Data Processing Addendum
Last Updated: June 26, 2026
Version: 1.0
Effective: June 26, 2026
Contents
Introduction
This Data Processing Addendum (“DPA”) is entered into between the agency or business entity that has accepted the AgencyStryde Terms of Service (“Customer” or “Controller”) and AgencyStryde (“AgencyStryde,” “we,” “us,” or “Processor”).
This DPA governs AgencyStryde's processing of personal data on behalf of the Customer in connection with the AgencyStryde platform and services. This DPA supplements and is incorporated into the AgencyStryde Terms of Service. In the event of any conflict between this DPA and the Terms of Service with respect to personal data processing, this DPA shall control.
AgencyStryde is a software-as-a-service platform designed for independent insurance agencies. In providing the platform, AgencyStryde processes personal data entered by agency customers relating to the agency's own clients. AgencyStryde processes this data exclusively as a data processor acting under the instructions of the Customer.
Definitions
As used in this DPA, the following terms have the meanings set out below:
Roles of the Parties
Customer (Agency)
Data Controller
- Determines what Personal Data is entered into the platform
- Controls the purposes for which Customer Data is collected
- Bears responsibility for the lawful basis for collecting client data
- Instructs AgencyStryde on how Customer Data should be processed
- Manages data subject rights requests from its own clients
AgencyStryde
Data Processor
- Processes Customer Data only under Customer instructions
- Does not determine the purposes or means of processing
- Provides the platform infrastructure and tooling
- Maintains security controls to protect Customer Data
- Engages Subprocessors to assist in delivering the platform
Types of Data Processed
In the course of providing the AgencyStryde platform, AgencyStryde may process the following categories of Personal Data submitted by the Customer:
First and last names of clients and contacts
Residential and business mailing addresses
Mobile, home, and business phone numbers
Personal and business email addresses
Insurance policy numbers, types, carriers, coverages, and premiums
Policy renewal dates, history, and renewal activity records
Household members, relationships, and associated contact records
Internal notes and activity records entered by agency staff
Policy documents, certificates, correspondence, and other uploaded files
Records of communications between the agency and its clients
Agency team member names, emails, and role assignments within the platform
The specific categories and volumes of Personal Data processed depend on how the Customer configures and uses the platform. The Customer is responsible for ensuring that its collection and submission of Personal Data to the platform complies with applicable data protection laws.
Purpose of Processing
AgencyStryde processes Customer Data solely for the purpose of providing the platform services to the Customer. Permitted processing purposes include:
Customer Instructions
AgencyStryde shall process Customer Data only in accordance with the documented instructions of the Customer as set out in this DPA and the Terms of Service. AgencyStryde's processing of Customer Data is limited to:
- Processing necessary to provide the platform services as described in the Terms of Service and this DPA
- Processing explicitly instructed by the Customer through its use of platform features and settings
- Processing required by applicable law, in which case AgencyStryde will notify the Customer prior to processing unless prohibited by law from doing so
If AgencyStryde believes any Customer instruction violates applicable law, AgencyStryde will promptly notify the Customer. AgencyStryde may suspend processing of the affected data until the Customer provides updated lawful instructions.
Confidentiality
AgencyStryde shall ensure that access to Customer Data is limited to personnel and Subprocessors who need access to perform their functions in connection with providing the platform services.
- Only authorized AgencyStryde personnel may access Customer Data, and only when necessary for support, security, maintenance, or legal compliance purposes
- All AgencyStryde personnel with access to Customer Data are subject to confidentiality obligations no less protective than those in this DPA
- AgencyStryde personnel are prohibited from accessing Customer Data for purposes unrelated to delivering the platform services
- Access to Customer Data by AgencyStryde personnel is subject to internal authorization controls and access logging
Security Measures
AgencyStryde implements and maintains appropriate technical and organizational security measures designed to protect Customer Data against unauthorized access, disclosure, alteration, or destruction.
TLS encryption for all data transmitted between users and AgencyStryde services
Industry-standard authentication with bcrypt password hashing and secure session management
Access to features and data scoped to assigned roles and permissions
Authentication and administrative activities are logged for security monitoring
Hosted on enterprise-grade cloud infrastructure with managed security and redundancy
Subprocessors are required to maintain appropriate security standards
Subprocessors
AgencyStryde engages the following Subprocessors to assist in delivering the platform services. All Subprocessors are required to maintain security and data protection standards appropriate to the data they process.
| Subprocessor | Role | Data Processed |
|---|---|---|
| Supabase | Database, authentication, file storage | Customer Data, authentication records, uploaded files |
| Vercel | Application hosting and delivery | Request/response data, application logs |
| Stripe | Payment processing and billing | Billing and subscription data (no full card numbers) |
| Anthropic | AI assistant (Ava) functionality | Queries submitted to Ava within agency workspace |
AgencyStryde may engage additional Subprocessors as needed to deliver or improve the platform services. AgencyStryde will update this DPA to reflect the addition of new Subprocessors. The current Subprocessor list will be maintained at this page. Continued use of the platform following an update to the Subprocessor list constitutes acceptance of the updated list.
AgencyStryde is responsible for ensuring that its Subprocessors comply with data protection obligations at least as protective as those set out in this DPA with respect to Customer Data.
International Transfers
AgencyStryde primarily operates through cloud service providers based in the United States. Customer Data may be processed in the United States and, in some cases, other locations where AgencyStryde's Subprocessors operate global infrastructure.
AgencyStryde relies on its Subprocessors to implement appropriate safeguards for any international transfers of Personal Data, including standard contractual clauses or other transfer mechanisms recognized under applicable law.
Customers who require specific transfer mechanism documentation should contact AgencyStryde at support@agencystryde.com.
Data Subject Requests
Where an individual (data subject) makes a request to AgencyStryde regarding Personal Data that is Customer Data — including requests for access, correction, deletion, or portability — AgencyStryde will:
- Notify the Customer promptly when AgencyStryde receives a data subject request that relates to Customer Data, where permitted by applicable law
- Provide reasonable assistance to the Customer in responding to data subject requests where technically feasible and within AgencyStryde's ability to assist
- Not respond directly to data subject requests relating to Customer Data without the Customer's authorization, unless required by applicable law
The Customer (as Data Controller) bears primary responsibility for responding to data subject requests relating to Customer Data. AgencyStryde provides technical capabilities to support Customer-initiated data exports and deletions within the platform.
Security Incident Notification
If AgencyStryde becomes aware of a confirmed Security Incident affecting Customer Data, AgencyStryde will:
- Investigate the Security Incident promptly upon becoming aware
- Take reasonable containment and remediation measures to address the Security Incident
- Notify affected Customers of a confirmed Security Incident without unreasonable delay
- Provide available information regarding the nature of the Security Incident, the data potentially affected, the likely consequences, and the measures taken or proposed to address it
- Cooperate with the Customer in its own assessment of and response to the Security Incident
Security incident notifications will be delivered to the email address associated with the Customer's account. Customers are responsible for maintaining accurate contact information in their account settings.
Data Retention
AgencyStryde retains Customer Data for the duration of the Customer's active subscription. Retention practices include:
- Customer Data is retained and accessible while a Customer account is active and subscription is in good standing
- Customers may export their Customer Data at any time during an active subscription by contacting support@agencystryde.com
- Following account cancellation, Customer Data will be retained for a limited grace period to allow for data export before deactivation
- AgencyStryde may retain limited records beyond the subscription period when required for legal obligations, financial recordkeeping, security investigations, or dispute resolution
- Retained records following termination are limited to the minimum necessary to satisfy the applicable legal or operational requirement
Data Return and Deletion
Upon termination of the Customer's subscription for any reason, the Customer may:
- Request a data export — AgencyStryde will provide a Customer Data export in a machine-readable format within a reasonable timeframe following a written request submitted prior to account deactivation
- Request data deletion — Following the applicable retention period or upon written request, AgencyStryde will delete Customer Data from active systems, subject to legal retention obligations
Customers are responsible for submitting data export requests before their account is deactivated. AgencyStryde will use commercially reasonable efforts to process data export and deletion requests within 30 days of receipt, subject to applicable legal obligations.
Data deletion requests may be submitted to support@agencystryde.com.
Audits and Security Information
AgencyStryde will make available to Customers reasonable information regarding its security practices and controls, including through:
- This DPA and the publicly available Security Overview page at agencystryde.com/security
- Responses to reasonable security questionnaires submitted by Customers in the context of enterprise procurement or compliance reviews
- Security incident notifications as described in this DPA
AgencyStryde is not required to disclose, and will not disclose, the following in response to audit or security information requests:
- Application source code or proprietary algorithms
- Internal security system configurations that could create security vulnerabilities if disclosed
- Information relating to other customers or their data
- Proprietary business or technical information
Enterprise customers with specific audit rights requirements should contact AgencyStryde Management at support@agencystryde.com to discuss reasonable accommodations.
Limitation of Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the AgencyStryde Terms of Service.
Nothing in this DPA shall exclude or limit either party's liability to the extent it cannot be excluded or limited under applicable law. The DPA does not create any additional liability beyond what is set out in the Terms of Service.
Updates to this DPA
AgencyStryde may update this DPA periodically to reflect changes in processing activities, legal requirements, or security practices. When material changes are made, AgencyStryde will communicate the changes through:
- A notice posted on the AgencyStryde platform or this page
- An update to the Last Updated date at the top of this DPA
- Email communication to the account administrator when changes are material
Continued use of the AgencyStryde platform following the effective date of an updated DPA constitutes acceptance of the updated terms. If a Customer does not agree to an updated DPA, the Customer must discontinue use of the platform and cancel their subscription before the updated DPA takes effect.
Prior versions of this DPA are available upon request by contacting support@agencystryde.com.
Contact Information
For questions about this DPA, data processing practices, or to submit a data subject request or data deletion request, please contact:
AgencyStryde
We aim to respond to data-related inquiries within 10 business days.