Data Processing Terms
Effective July 23, 2026
1. Roles and Instructions
The agency is the controller or business that determines the purposes and means of processing Customer Personal Data. OneagencyOS is the processor or service provider and will process Customer Personal Data only to provide, secure, support, and improve the contracted service; follow the agency's documented instructions; prevent fraud or abuse; and comply with law. OneagencyOS will notify the agency if an instruction appears unlawful, unless prohibited by law.
2. Scope of Processing
Processing may include collection, recording, organization, extraction, analysis, transmission, storage, retrieval, display, synchronization, restriction, deletion, and other operations needed for agency-management workflows. Data subjects may include prospects, applicants, insureds, household members, agency personnel, producers, service providers, and other contacts. Data may include identity, contact, property, vehicle, policy, coverage, claim, payment-status, communication, document, signature, device, authentication, and activity information. Processing continues for the subscription term and the limited retention periods described in the Retention and Deletion Policy.
3. Service Provider Restrictions
OneagencyOS will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the business purposes specified by the agreement, or combine it with personal information received from another source except as permitted by applicable law and needed to provide the service. OneagencyOS will not use Customer Personal Data to train generalized or non-personalized AI models without the agency's express written permission.
4. Confidentiality and Personnel
OneagencyOS will limit access to personnel and contractors who need the information to perform authorized duties and who are subject to confidentiality obligations. Personnel with elevated access will receive security and privacy guidance appropriate to their responsibilities. Access will be reviewed and removed when no longer needed.
5. Security Measures
OneagencyOS will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of the processing. Measures include role-based access, tenant isolation, authentication controls, transport encryption, server-side handling of privileged credentials, logging, vulnerability and dependency management, backup practices, incident response, and vendor oversight. Agencies are responsible for user access, endpoint security, permissions, lawful instructions, and use of available security controls.
6. Subprocessors
The agency authorizes OneagencyOS to use subprocessors for hosting, databases, authentication, communications, payments, AI, document processing, storage, monitoring, and support. OneagencyOS will impose written data-protection duties appropriate to each subprocessor's work and remains responsible for its obligations under these terms. OneagencyOS will provide reasonable notice of a material new subprocessor and consider a good-faith objection based on documented data-protection concerns. If the parties cannot resolve the concern, the agency may discontinue the affected feature or terminate that affected service.
7. Individual Rights Requests
Taking into account the nature of processing, OneagencyOS will reasonably assist the agency with verified requests for access, correction, deletion, portability, restriction, or objection. If OneagencyOS receives a request relating to agency-controlled data, it will direct the requester to the agency when appropriate and will not independently respond except as instructed or legally required.
8. Security Incidents
OneagencyOS will notify the agency without undue delay after confirming unauthorized acquisition, access, use, or disclosure of Customer Personal Data that compromises its security, confidentiality, or integrity ("Security Incident"). The notice will include available information about the nature, affected data and individuals, likely consequences, containment, and recommended steps. OneagencyOS will investigate, contain, remediate, preserve relevant evidence, and reasonably cooperate. Unsuccessful attempts, blocked attacks, and events that do not compromise Customer Personal Data are not Security Incidents.
9. Return and Deletion
During the subscription, the agency may export supported Customer Data. After termination or a verified deletion instruction, OneagencyOS will return or delete Customer Personal Data according to the agreement and Retention and Deletion Policy, unless retention is required by law, legal hold, dispute, or documented security purpose. Protected backup copies may remain until overwritten in the ordinary backup cycle and will not be restored except for disaster recovery.
10. Compliance Information and Audits
OneagencyOS will make information reasonably necessary to demonstrate compliance available to the agency, including relevant policies, summaries, and responses to security questionnaires. No more than once annually, unless required after a material incident or by a regulator, the agency may request a reasonable remote audit at its expense, subject to confidentiality, security, and non-disruption requirements. Third-party reports may satisfy the request when appropriate.
11. Government Requests and Legal Process
OneagencyOS will notify the agency of legally compelled disclosure of Customer Personal Data when permitted, evaluate the request, and disclose only information reasonably required. The agency is responsible for lawful preservation and production instructions for records under its control.
12. International Processing
Unless agreed otherwise, the service is intended for U.S. agencies and U.S. processing. If Customer Personal Data is transferred from a jurisdiction that requires a transfer mechanism, the parties will cooperate in good faith to implement an appropriate addendum before the transfer.
13. Contact
Privacy and data-processing questions may be sent to hello@oneagencyos.com.