Legal

Data Processing Addendum

Last Updated: June 26, 2026

Version: 1.0

Effective: June 26, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between AgencyStryde and its customers and governs how AgencyStryde processes personal data on behalf of agencies using the platform. By using the AgencyStryde platform, you agree to the terms of this DPA.

Introduction

This Data Processing Addendum (“DPA”) is entered into between the agency or business entity that has accepted the AgencyStryde Terms of Service (“Customer” or “Controller”) and AgencyStryde (“AgencyStryde,” “we,” “us,” or “Processor”).

This DPA governs AgencyStryde's processing of personal data on behalf of the Customer in connection with the AgencyStryde platform and services. This DPA supplements and is incorporated into the AgencyStryde Terms of Service. In the event of any conflict between this DPA and the Terms of Service with respect to personal data processing, this DPA shall control.

AgencyStryde is a software-as-a-service platform designed for independent insurance agencies. In providing the platform, AgencyStryde processes personal data entered by agency customers relating to the agency's own clients. AgencyStryde processes this data exclusively as a data processor acting under the instructions of the Customer.

Definitions

As used in this DPA, the following terms have the meanings set out below:

CustomerThe independent insurance agency, brokerage, or other business entity that has subscribed to the AgencyStryde platform under the Terms of Service.
Customer DataAll data, records, files, and content submitted to or generated within the AgencyStryde platform by the Customer or its authorized users, including personal data relating to the Customer's clients.
Personal DataAny information relating to an identified or identifiable natural person, including names, contact information, policy records, financial information, and any other information that can reasonably be used to identify an individual.
ProcessingAny operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure, or destruction, whether or not by automated means.
ControllerThe party that determines the purposes and means of processing Personal Data. Under this DPA, the Customer is the Controller of Customer Data.
ProcessorThe party that processes Personal Data on behalf of the Controller under the Controller's instructions. Under this DPA, AgencyStryde is the Processor.
SubprocessorA third-party service provider engaged by AgencyStryde to assist in processing Customer Data in connection with delivering the platform services.
Security IncidentA confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by AgencyStryde on behalf of the Customer.

Roles of the Parties

Customer (Agency)

Data Controller

  • Determines what Personal Data is entered into the platform
  • Controls the purposes for which Customer Data is collected
  • Bears responsibility for the lawful basis for collecting client data
  • Instructs AgencyStryde on how Customer Data should be processed
  • Manages data subject rights requests from its own clients

AgencyStryde

Data Processor

  • Processes Customer Data only under Customer instructions
  • Does not determine the purposes or means of processing
  • Provides the platform infrastructure and tooling
  • Maintains security controls to protect Customer Data
  • Engages Subprocessors to assist in delivering the platform
AgencyStryde processes Customer Data only under the instructions of the Customer (Agency). AgencyStryde does not process Customer Data for its own independent purposes beyond what is necessary to deliver, maintain, and secure the platform.

Types of Data Processed

In the course of providing the AgencyStryde platform, AgencyStryde may process the following categories of Personal Data submitted by the Customer:

👤Names

First and last names of clients and contacts

🏠Addresses

Residential and business mailing addresses

📞Phone Numbers

Mobile, home, and business phone numbers

📧Email Addresses

Personal and business email addresses

📋Policy Information

Insurance policy numbers, types, carriers, coverages, and premiums

🔄Renewal Information

Policy renewal dates, history, and renewal activity records

👨‍👩‍👧Household Information

Household members, relationships, and associated contact records

📝Staff Notes

Internal notes and activity records entered by agency staff

📁Uploaded Documents

Policy documents, certificates, correspondence, and other uploaded files

💬Communications Records

Records of communications between the agency and its clients

🔐User Account Information

Agency team member names, emails, and role assignments within the platform

The specific categories and volumes of Personal Data processed depend on how the Customer configures and uses the platform. The Customer is responsible for ensuring that its collection and submission of Personal Data to the platform complies with applicable data protection laws.

Purpose of Processing

AgencyStryde processes Customer Data solely for the purpose of providing the platform services to the Customer. Permitted processing purposes include:

Providing core platform functionality including CRM, policy management, and renewals
Storing and organizing agency records and client information
Supporting renewal workflows, service requests, and sales pipelines
Enabling agency-to-client and internal team communications
Generating agency reports, dashboards, and analytics
Providing AI-assisted platform features through the Ava AI assistant
Delivering customer and technical support to the Customer
Maintaining platform security, integrity, and availability
Complying with applicable legal obligations
Fulfilling obligations under the Terms of Service and this DPA
AgencyStryde will not: sell Customer Data, use Customer Data for advertising or marketing, or share Customer Data with unrelated third parties for their own independent business purposes.

Customer Instructions

AgencyStryde shall process Customer Data only in accordance with the documented instructions of the Customer as set out in this DPA and the Terms of Service. AgencyStryde's processing of Customer Data is limited to:

  • Processing necessary to provide the platform services as described in the Terms of Service and this DPA
  • Processing explicitly instructed by the Customer through its use of platform features and settings
  • Processing required by applicable law, in which case AgencyStryde will notify the Customer prior to processing unless prohibited by law from doing so

If AgencyStryde believes any Customer instruction violates applicable law, AgencyStryde will promptly notify the Customer. AgencyStryde may suspend processing of the affected data until the Customer provides updated lawful instructions.

Confidentiality

AgencyStryde shall ensure that access to Customer Data is limited to personnel and Subprocessors who need access to perform their functions in connection with providing the platform services.

  • Only authorized AgencyStryde personnel may access Customer Data, and only when necessary for support, security, maintenance, or legal compliance purposes
  • All AgencyStryde personnel with access to Customer Data are subject to confidentiality obligations no less protective than those in this DPA
  • AgencyStryde personnel are prohibited from accessing Customer Data for purposes unrelated to delivering the platform services
  • Access to Customer Data by AgencyStryde personnel is subject to internal authorization controls and access logging

Security Measures

AgencyStryde implements and maintains appropriate technical and organizational security measures designed to protect Customer Data against unauthorized access, disclosure, alteration, or destruction.

🔒Encryption in Transit

TLS encryption for all data transmitted between users and AgencyStryde services

🔑Secure Authentication

Industry-standard authentication with bcrypt password hashing and secure session management

👥Role-Based Access Controls

Access to features and data scoped to assigned roles and permissions

📋Access Logging

Authentication and administrative activities are logged for security monitoring

🏗️Infrastructure Security

Hosted on enterprise-grade cloud infrastructure with managed security and redundancy

🤝Vendor Security Controls

Subprocessors are required to maintain appropriate security standards

AgencyStryde maintains a formal Information Security Policy and Incident Response Plan governing its security program and incident management procedures. Additional detail on security practices is available on the Security Overview page.

Subprocessors

AgencyStryde engages the following Subprocessors to assist in delivering the platform services. All Subprocessors are required to maintain security and data protection standards appropriate to the data they process.

SubprocessorRoleData Processed
SupabaseDatabase, authentication, file storageCustomer Data, authentication records, uploaded files
VercelApplication hosting and deliveryRequest/response data, application logs
StripePayment processing and billingBilling and subscription data (no full card numbers)
AnthropicAI assistant (Ava) functionalityQueries submitted to Ava within agency workspace

AgencyStryde may engage additional Subprocessors as needed to deliver or improve the platform services. AgencyStryde will update this DPA to reflect the addition of new Subprocessors. The current Subprocessor list will be maintained at this page. Continued use of the platform following an update to the Subprocessor list constitutes acceptance of the updated list.

AgencyStryde is responsible for ensuring that its Subprocessors comply with data protection obligations at least as protective as those set out in this DPA with respect to Customer Data.

International Transfers

AgencyStryde primarily operates through cloud service providers based in the United States. Customer Data may be processed in the United States and, in some cases, other locations where AgencyStryde's Subprocessors operate global infrastructure.

AgencyStryde relies on its Subprocessors to implement appropriate safeguards for any international transfers of Personal Data, including standard contractual clauses or other transfer mechanisms recognized under applicable law.

Customers who require specific transfer mechanism documentation should contact AgencyStryde at support@agencystryde.com.

Data Subject Requests

Where an individual (data subject) makes a request to AgencyStryde regarding Personal Data that is Customer Data — including requests for access, correction, deletion, or portability — AgencyStryde will:

  • Notify the Customer promptly when AgencyStryde receives a data subject request that relates to Customer Data, where permitted by applicable law
  • Provide reasonable assistance to the Customer in responding to data subject requests where technically feasible and within AgencyStryde's ability to assist
  • Not respond directly to data subject requests relating to Customer Data without the Customer's authorization, unless required by applicable law

The Customer (as Data Controller) bears primary responsibility for responding to data subject requests relating to Customer Data. AgencyStryde provides technical capabilities to support Customer-initiated data exports and deletions within the platform.

Security Incident Notification

If AgencyStryde becomes aware of a confirmed Security Incident affecting Customer Data, AgencyStryde will:

  • Investigate the Security Incident promptly upon becoming aware
  • Take reasonable containment and remediation measures to address the Security Incident
  • Notify affected Customers of a confirmed Security Incident without unreasonable delay
  • Provide available information regarding the nature of the Security Incident, the data potentially affected, the likely consequences, and the measures taken or proposed to address it
  • Cooperate with the Customer in its own assessment of and response to the Security Incident
Notification of a Security Incident does not constitute an admission of fault or liability by AgencyStryde. AgencyStryde's obligation to notify is limited to confirmed Security Incidents and does not extend to unsuccessful access attempts, false alarms, or security events that do not result in unauthorized access to Customer Data.

Security incident notifications will be delivered to the email address associated with the Customer's account. Customers are responsible for maintaining accurate contact information in their account settings.

Data Retention

AgencyStryde retains Customer Data for the duration of the Customer's active subscription. Retention practices include:

  • Customer Data is retained and accessible while a Customer account is active and subscription is in good standing
  • Customers may export their Customer Data at any time during an active subscription by contacting support@agencystryde.com
  • Following account cancellation, Customer Data will be retained for a limited grace period to allow for data export before deactivation
  • AgencyStryde may retain limited records beyond the subscription period when required for legal obligations, financial recordkeeping, security investigations, or dispute resolution
  • Retained records following termination are limited to the minimum necessary to satisfy the applicable legal or operational requirement

Data Return and Deletion

Upon termination of the Customer's subscription for any reason, the Customer may:

  • Request a data export — AgencyStryde will provide a Customer Data export in a machine-readable format within a reasonable timeframe following a written request submitted prior to account deactivation
  • Request data deletion — Following the applicable retention period or upon written request, AgencyStryde will delete Customer Data from active systems, subject to legal retention obligations

Customers are responsible for submitting data export requests before their account is deactivated. AgencyStryde will use commercially reasonable efforts to process data export and deletion requests within 30 days of receipt, subject to applicable legal obligations.

Data deletion requests may be submitted to support@agencystryde.com.

Audits and Security Information

AgencyStryde will make available to Customers reasonable information regarding its security practices and controls, including through:

  • This DPA and the publicly available Security Overview page at agencystryde.com/security
  • Responses to reasonable security questionnaires submitted by Customers in the context of enterprise procurement or compliance reviews
  • Security incident notifications as described in this DPA

AgencyStryde is not required to disclose, and will not disclose, the following in response to audit or security information requests:

  • Application source code or proprietary algorithms
  • Internal security system configurations that could create security vulnerabilities if disclosed
  • Information relating to other customers or their data
  • Proprietary business or technical information

Enterprise customers with specific audit rights requirements should contact AgencyStryde Management at support@agencystryde.com to discuss reasonable accommodations.

Limitation of Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the AgencyStryde Terms of Service.

Nothing in this DPA shall exclude or limit either party's liability to the extent it cannot be excluded or limited under applicable law. The DPA does not create any additional liability beyond what is set out in the Terms of Service.

Updates to this DPA

AgencyStryde may update this DPA periodically to reflect changes in processing activities, legal requirements, or security practices. When material changes are made, AgencyStryde will communicate the changes through:

  • A notice posted on the AgencyStryde platform or this page
  • An update to the Last Updated date at the top of this DPA
  • Email communication to the account administrator when changes are material

Continued use of the AgencyStryde platform following the effective date of an updated DPA constitutes acceptance of the updated terms. If a Customer does not agree to an updated DPA, the Customer must discontinue use of the platform and cancel their subscription before the updated DPA takes effect.

Prior versions of this DPA are available upon request by contacting support@agencystryde.com.

Contact Information

For questions about this DPA, data processing practices, or to submit a data subject request or data deletion request, please contact:

AgencyStryde

We aim to respond to data-related inquiries within 10 business days.