Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how WordingsAI (“WordingsAI”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you access or use our websites, applications, APIs, AI tools, document analysis tools, policy wording tools, support services, and related services (together, the “Service”).
WordingsAI provides software that may assist with insurance, reinsurance, contract, clause, policy wording, document review, comparison, drafting, analysis, and workflow tasks.
This Privacy Policy applies to personal data we process as a controller. Where we process personal data on behalf of a customer under a data processing agreement, we act as processor and process that personal data in accordance with the customer’s instructions and the applicable agreement.
1. Information We Collect
We may collect and process the following categories of information.
1.1 Account and registration information
When you create an account, subscribe to the Service, request a demo, contact us, or communicate with us, we may collect:
- name;
- business email address;
- telephone number;
- job title;
- company or organisation name;
- username and account credentials;
- billing, subscription, and payment-related information;
- communication preferences; and
- any information you choose to provide in messages, forms, surveys, support tickets, or emails.
1.2 Content and documents you provide
When you use WordingsAI, you may upload, input, submit, paste, generate, or otherwise provide content to the Service, including:
- insurance and reinsurance documents;
- policy wordings, clauses, endorsements, schedules, slips, treaties, binders, certificates, contracts, and related materials;
- prompts, instructions, queries, comments, notes, annotations, and review requests;
- files, spreadsheets, PDFs, Word documents, emails, and other business documents;
- document metadata;
- generated outputs, comparisons, summaries, checklists, risk flags, and analyses; and
- any personal data contained in the materials you or your users provide.
You are responsible for ensuring that you have the right to upload and process any documents, business information, confidential information, personal data, or third-party materials through the Service.
1.3 Usage and device information
When you use the Service, we may automatically collect:
- IP address;
- browser type and version;
- device type, operating system, and device identifiers;
- time zone and approximate location derived from IP address;
- referring pages and URLs;
- pages viewed and features used;
- dates, times, and duration of visits;
- clicks, navigation paths, and interaction data;
- log files, diagnostic data, crash reports, and performance data;
- authentication and security logs;
- API usage, request metadata, and rate-limit information; and
- cookies and similar tracking technologies installed on your device.
1.4 Payment information
If you purchase paid services, payment may be processed by a third-party payment provider. We may receive limited payment-related information, such as billing contact details, transaction status, invoice details, subscription plan, payment method type, and the last four digits of a payment card. We do not usually store full payment card numbers.
1.5 Information from third parties and integrations
If you connect WordingsAI to third-party services or integrations, we may receive information from those services as authorised by you, such as:
- account identifiers;
- files, folders, documents, messages, or metadata selected by you;
- permissions and access tokens;
- workspace, team, or organisation information; and
- content necessary to provide the requested integration functionality.
Third-party services may process your data under their own terms and privacy policies.
1.6 Special category or sensitive data
The Service is not designed for unnecessary special category data or sensitive personal data. You should not upload special category data, health data, biometric data, criminal offence data, children’s data, or similarly sensitive data unless it is necessary, lawful, and permitted under your agreement with WordingsAI.
If documents you upload contain sensitive data, you are responsible for ensuring that there is a lawful basis and appropriate safeguards for that processing.
2. How We Use Data
We use personal data to provide, maintain, secure, improve, and administer the Service. In particular, we may use information to:
- create, authenticate, and manage user accounts;
- provide access to the Service and its features;
- process documents, prompts, instructions, and other inputs;
- generate outputs, summaries, comparisons, analyses, and workflow results;
- personalise your experience and present relevant product features;
- provide customer support and respond to requests;
- manage subscriptions, billing, payments, renewals, and invoices;
- send service notices, security alerts, administrative messages, and product updates;
- monitor usage, performance, reliability, availability, and errors;
- debug, maintain, test, and improve the Service;
- protect against fraud, abuse, unauthorised access, security threats, and misuse;
- enforce our Terms of Service and other agreements;
- comply with legal, regulatory, tax, accounting, sanctions, and compliance obligations;
- maintain records and audit logs;
- conduct internal analytics and business planning; and
- develop and improve products, features, models, prompts, workflows, and user experience, subject to the AI training commitments below.
3. AI Processing, Training, and Model Improvement
WordingsAI may use artificial intelligence, machine learning, retrieval, document parsing, embedding, classification, and automated processing technologies to provide the Service.
3.1 Use of your inputs and outputs to provide the Service
We process the content you provide, including prompts, documents, files, and related materials, to provide requested functionality. This may include extracting text, analysing clauses, comparing documents, identifying issues, generating summaries, producing draft wording, and creating outputs.
3.2 No training on private customer content without consent
We do not use your private personal data, confidential business documents, customer inputs, or customer outputs to train global or generally available AI models without your explicit consent or a separate written agreement permitting that use.
3.3 Limited operational use
We may use inputs, outputs, logs, metadata, and derived information where necessary to:
- provide and operate the Service;
- secure, monitor, troubleshoot, and debug the Service;
- prevent abuse, fraud, and misuse;
- comply with law;
- enforce our agreements;
- maintain quality and reliability;
- respond to support requests; and
- improve the Service using aggregated, anonymised, de-identified, or non-confidential information where appropriate.
3.4 Human review
We may review customer content where necessary to provide support, investigate bugs, prevent abuse, comply with law, enforce agreements, or with your consent. Access is limited to personnel or service providers with a need to know and subject to confidentiality obligations.
4. Legal Bases for Processing
Where UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:
- Contract: to provide the Service, manage your account, process subscriptions, and perform our agreement with you.
- Legitimate interests: to operate, improve, secure, and promote the Service, prevent fraud and misuse, support users, analyse usage, and protect our rights, provided those interests are not overridden by your rights and freedoms.
- Consent: where required for certain cookies, marketing communications, optional AI training, or other processing that requires consent.
- Legal obligation: to comply with applicable laws, court orders, regulatory obligations, tax, accounting, sanctions, and compliance requirements.
- Vital interests or public task: where applicable in exceptional circumstances.
If you provide personal data about other individuals, you are responsible for ensuring that you have a lawful basis to do so and that any required notices have been provided.
5. Cookies and Similar Technologies
We may use cookies, pixels, local storage, SDKs, and similar technologies to:
- keep you signed in;
- remember preferences;
- secure the Service;
- understand how users interact with the Service;
- measure performance and errors;
- improve functionality; and
- support analytics and marketing, where permitted.
Some cookies are necessary for the Service to function. Others may be optional and used only with consent where required by law.
You can control cookies through your browser settings and, where available, through our cookie preference tools. Blocking some cookies may affect Service functionality.
6. How We Share Information
We may share personal data with the following categories of recipients.
6.1 Service providers
We may share data with vendors and service providers that support our business and the Service, including:
- cloud hosting and infrastructure providers;
- AI model, API, and processing providers;
- database, storage, and security providers;
- analytics and monitoring providers;
- payment processors;
- customer support and communication tools;
- email and notification providers;
- professional advisers;
- auditors, insurers, and legal advisers; and
- other providers necessary to operate the Service.
These providers are authorised to process personal data only as needed to provide services to us and are subject to contractual safeguards.
6.2 Customer administrators and organisations
If your account is provided by an organisation, employer, or customer, that organisation may be able to access information about your account and use of the Service, including user details, activity logs, documents, outputs, and administrative information, depending on the configuration and agreement.
6.3 Integrations
If you enable integrations with third-party services, we may share information with those services as necessary to provide the integration and as authorised by you.
6.4 Legal and compliance disclosures
We may disclose information where we reasonably believe it is necessary to:
- comply with applicable law, regulation, court order, or legal process;
- respond to lawful requests from regulators, law enforcement, or public authorities;
- enforce our Terms of Service and other agreements;
- protect the rights, property, security, or safety of WordingsAI, users, customers, or others;
- detect, prevent, or address fraud, abuse, security incidents, or technical issues; or
- establish, exercise, or defend legal claims.
6.5 Business transfers
If WordingsAI is involved in a merger, acquisition, investment, financing, reorganisation, sale of assets, insolvency, or similar transaction, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
6.6 Aggregated or de-identified data
We may use and share aggregated, anonymised, or de-identified information that does not reasonably identify you for analytics, product improvement, research, reporting, and business purposes.
7. International Transfers
WordingsAI and its service providers may process personal data in countries other than the country where you are located. These countries may have data protection laws that differ from those in your jurisdiction.
Where required, we use appropriate safeguards for international transfers, such as:
- adequacy regulations or decisions;
- standard contractual clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- contractual, technical, and organisational safeguards; and
- other lawful transfer mechanisms.
8. Data Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.
These measures may include:
- encryption in transit;
- access controls;
- authentication controls;
- logging and monitoring;
- vulnerability management;
- backup and recovery processes;
- vendor security review;
- confidentiality obligations; and
- internal security policies and procedures.
However, no system is completely secure. We cannot guarantee absolute security of any information transmitted to or processed by the Service. You are responsible for keeping your login credentials secure and for using appropriate access controls within your organisation.
9. Data Retention
We retain personal data for as long as reasonably necessary to provide the Service, fulfil the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs.
Retention periods may vary depending on:
- the type of data;
- the sensitivity of the data;
- the nature of your account or subscription;
- contractual requirements;
- legal, tax, accounting, or regulatory requirements;
- security and audit needs; and
- whether deletion has been requested.
When personal data is no longer required, we will delete, anonymise, or de-identify it in accordance with our retention practices, unless we are required or permitted to retain it by law or contract.
10. Your Rights
Depending on your location and applicable law, you may have rights to:
- access your personal data;
- receive a copy of your personal data;
- correct inaccurate or incomplete personal data;
- delete personal data;
- restrict processing;
- object to processing;
- withdraw consent where processing is based on consent;
- request data portability;
- opt out of marketing communications;
- complain to a data protection authority; and
- challenge certain automated decisions where applicable.
To exercise your rights, contact us using the details in the “Contact” section. We may need to verify your identity before responding.
Some rights may be limited by law, contractual obligations, confidentiality obligations, legal privilege, security requirements, or the rights of others.
11. Marketing Communications
We may send you marketing communications about WordingsAI products, services, events, updates, and resources where permitted by law.
You can opt out of marketing emails at any time by using the unsubscribe link in the email or contacting us.
Even if you opt out of marketing, we may still send you non-marketing messages, such as account, security, legal, billing, and service-related notices.
12. Children
The Service is not intended for children and must not be used by individuals under 18.
We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so that we can take appropriate steps.
13. Automated Decision-Making
WordingsAI may use automated systems to provide outputs, analysis, classification, recommendations, or workflow assistance. These outputs are designed to support human review and decision-making.
The Service is not intended to make legally significant or similarly significant decisions about individuals without appropriate human involvement. You are responsible for ensuring that any use of the Service involving individuals complies with applicable law and includes required human review, notices, safeguards, and rights.
14. Confidential Business Information
The Service may process confidential business information, including insurance, reinsurance, policy, claims, underwriting, contract, and commercial information.
We use such information to provide the Service and otherwise in accordance with this Privacy Policy and any applicable agreement. You should ensure that any confidential information uploaded to the Service is authorised for processing and subject to appropriate contractual and internal controls.
15. Third-Party Links and Services
The Service may contain links to third-party websites or may integrate with third-party services. We are not responsible for the privacy practices, security, content, or policies of third parties.
You should review the privacy policies and terms of any third-party services you use.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify you, such as by posting the updated policy, sending an email, or providing an in-product notice.
Your continued use of the Service after the updated Privacy Policy becomes effective indicates that you have read the updated policy.
17. Contact
For questions about this Privacy Policy or to exercise your privacy rights, contact WordingsAI using the contact details provided on our website or in your applicable agreement.
If you are in the UK or EEA, you may also have the right to complain to your local data protection authority. In the UK, this is the Information Commissioner’s Office.