PRIVACY
Litmus Privacy Statement
This statement applies across Litmus websites, software platforms, applications, accounts, communications, and related services that link to or reference it, including the Litmus Insurance Solutions client portal powered by Litmus Risk.
Last updated July 31, 2026PRIVACY AT A GLANCE
Litmus Holdings, Inc. provides insurance brokerage, claims-support, risk-management, advisory, and technology services in the United States. This Statement applies across Litmus websites, software platforms, applications, accounts, communications, and services.
We collect and use information to operate Litmus websites, the institutional Litmus Risk platform, and the Litmus Insurance Solutions client portal; provide requested services; support insurance transactions and claims; maintain security; and meet legal and regulatory obligations.
The institutional Litmus Risk software product is offered to financial-advisory firms and licensed insurance agencies or brokerages, not directly to consumers. Litmus Insurance Solutions may separately provide consumers with a client portal powered by Litmus Risk technology as part of its brokerage and client services.
Litmus does not sell personal information or share it for cross-context behavioral advertising. Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your information and to appeal certain privacy decisions.
This summary highlights key points. The complete Privacy Statement below controls.
1. Who We Are and Scope of This Statement
Litmus Holdings, Inc. and its affiliated entities (collectively, "Litmus," "we," "us," or "our") provide insurance brokerage, insurance advisory, claims-support, risk-management, and technology services. Our services may include:
- Selling, placing, and servicing personal and commercial property and casualty insurance through a Litmus-affiliated licensed insurance agency;
- Providing insurance-policy analysis, coverage guidance, and risk-assessment services;
- Providing claims coaching, advocacy, and related support; and
- Offering software-as-a-service solutions to financial-advisory firms and their authorized representatives, and to licensed insurance agencies or brokerages and their authorized producers, agents, and representatives.
Litmus Risk software subscriptions are offered to those professional organizations and their authorized representatives—not to consumers as a standalone retail software product. Clients, consumers, employees, service providers, or other authorized users may access parts of the Litmus Risk platform when invited, supported, or administered by a subscribing organization, but they are not customers of the institutional Litmus Risk software product.
Litmus Insurance Solutions may separately provide consumers with a client portal powered by Litmus Risk technology. That portal is made available as part of Litmus Insurance Solutions' consumer-facing services; it is not a direct-to-consumer subscription to the institutional Litmus Risk platform.
Insurance brokerage services available through a Litmus website, a Litmus Insurance Solutions client portal, or in connection with the Litmus Risk platform may be provided by a Litmus-affiliated licensed insurance agency or by an unaffiliated third-party insurance agency. When an unaffiliated agency provides brokerage services, that agency—not Litmus—is responsible for selling, placing, and servicing the applicable insurance policies and may process personal information under its own privacy notice. Litmus is not an insurance company and does not underwrite insurance.
In California, insurance brokerage services are provided by Litmus Holdings, Inc., doing business as Litmus Insurance Solutions, Inc., under California Property and Casualty License #6017185. Claims Coaching and related claims-support services may be provided under California Adjuster License #2N60154, as applicable.
This Privacy Statement ("Statement") explains how Litmus collects, uses, discloses, retains, and protects personal information in connection with our websites, software platforms, applications, authenticated accounts, insurance and advisory services, claims-support services, communications, and other online or offline interactions that link to or reference this Statement (collectively, the "Services"). This Statement applies across the Litmus Services and digital properties that link to or reference it.
The Services covered by this Statement include, without limitation, the public websites at litmusrisk.com and litmusinsurance.com, the institutional Litmus Risk platform, and authenticated experiences available through app.litmusrisk.com, including a Litmus Insurance Solutions client portal powered by Litmus Risk technology. Information submitted through a public website form is not treated as authenticated account data unless you separately create or use an account or direct that the information be added to or used with an authenticated Service.
Litmus is based in the United States, and the Services are offered and intended for use in the United States. This Statement is designed to address applicable United States federal and state privacy requirements. The Services are not directed to individuals outside the United States.
This Statement does not govern an unaffiliated insurance agency's independent processing of personal information or a third-party website, product, or service that is governed by its own privacy notice. Additional notices, engagement terms, carrier notices, or legally required financial-privacy notices may apply to particular products, services, jurisdictions, or relationships. This Statement does not replace any notice of insurance information practices, Gramm-Leach-Bliley Act or other financial-privacy notice, consumer-report disclosure or authorization, adverse-action notice, carrier notice, or other notice or consent required for an insurance transaction. If a service-specific privacy notice conflicts with this Statement, the service-specific notice controls for that service. Certain information regulated by federal or state insurance or financial-privacy laws may be exempt from some provisions of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA").
When Litmus provides the Litmus Risk platform to a financial-advisory firm or licensed insurance agency or brokerage, Litmus may process personal information on that organization's behalf and under its instructions. In that context, the subscribing organization's privacy notice governs its independent collection and use of personal information, and privacy requests concerning that processing should generally be directed to that organization. Litmus may also process limited information for its own legitimate business purposes as described in this Statement and permitted by applicable law.
Depending on the context, Litmus may act as a business or controller that determines the purposes and means of processing personal information, or as a service provider or processor acting for a subscribing organization. When Litmus acts as a service provider or processor, the subscribing organization remains responsible for its instructions, legal basis, notices, and responses to privacy requests, and Litmus will assist as required by applicable law and its agreement with that organization.
1.1 Individuals Covered by This Statement
This Statement may apply to insurance applicants, policyholders, insureds, prospective insureds, claimants, beneficiaries, household members, business owners, employees or representatives of commercial insureds, financial advisors and their personnel, insurance agents, producers, brokers and agency personnel, authorized representatives, business contacts, service providers, visitors to our websites, users of the Litmus Risk platform or a Litmus Insurance Solutions client portal, and other individuals whose personal information is processed in connection with the Services.
2. Personal Information We Collect
The information we collect depends on how you interact with the Services and which services you or an organization on your behalf requests or uses.
2.1 Information You Provide
- Contact and identity information, such as your name, email address, telephone number, postal address, ZIP code, state, date of birth, and similar identifiers.
- Account and profile information, such as login credentials, account preferences, user role, organization, and authentication information.
- Inquiry and communications information, such as the services or coverage in which you are interested, form responses, messages, recordings where permitted, support requests, and other information you provide when corresponding with Litmus.
- Insurance and risk information, such as policy documents, coverage, limits, premiums, deductibles, claims history, property and asset information, household or business information, driver and vehicle information, loss exposures, risk-assessment responses, and information needed to analyze, quote, place, service, or support insurance.
- Claims information, such as the nature and circumstances of a loss, claim status, communications, photographs, supporting documents, and other information provided for claims coaching, advocacy, or related support.
- Beneficiary and relationship information, such as household members, dependents, additional insureds, beneficiaries, ownership interests, and the nature of an individual's relationship to an applicant, policyholder, insured, claimant, business, trust, or other entity.
- Professional and organizational information, such as employer, occupation, job title, professional role, agency or advisory-firm affiliation, licenses, and information about the clients or accounts you are authorized to manage.
- Verification, compliance, and screening information, such as identity-verification results, insurance-fraud indicators, sanctions-screening results, driving or criminal-history information, consumer-report information, credit or insurance-score information, and professional disciplinary or licensing information, when relevant to a requested Service and permitted by applicable law.
- Transaction and commercial information, such as products or services considered, requested, or received; subscription and billing details; and records of transactions. Payment-card information may be collected directly by a payment processor rather than Litmus.
- Content and documents you upload, connect, create, or direct another party to provide through the Services.
Please do not submit Social Security numbers, payment-card information, medical records, passwords, or other highly sensitive information through a general contact form or other channel not designated for that information.
2.2 Information Collected Automatically
When you use the Services, Litmus and our hosting, security, analytics, and technical service providers may automatically collect technical and usage information, including:
- Internet Protocol address
- Browser and device type
- Operating system
- Pages, screens, features, and content viewed or used, and the referring webpage
- Date and time of access
- General location inferred from an Internet Protocol address
- Security, error, audit, and diagnostic logs
- Account and platform activity, such as login events, feature interactions, uploads, downloads, actions taken, and records of user instructions
- Cookie, software-development-kit, and similar technology data as described in Section 8
2.3 Sources of Personal Information
We collect information directly from you; from your employer, financial advisor, insurance professional, agency, broker, authorized representative, or another organization through which you access the Services; automatically from your browser, device, and interactions with the Services; from connected accounts and data sources you authorize; from service providers; from Litmus personnel and affiliates; from insurers, wholesalers, managing general agents, insurance data providers, claims professionals, and other insurance-market participants; and from public records or commercially available sources where permitted by law.
If you provide personal information about another person, you represent that you are authorized to do so and, where required, have provided appropriate notice or obtained appropriate consent.
2.4 Third-Party Data Integrations
With your authorization, we may collect insurance-policy information through third-party integration services that connect to your insurance-carrier accounts or other approved insurance systems. These integrations may allow policy information to be retrieved without manual document upload. We and insurance agencies providing brokerage services through the Litmus Risk platform or a Litmus Insurance Solutions client portal may also use agency-management systems, carrier portals, comparative-rating tools, market-access systems, and approved document or communication tools to collect, receive, submit, store, or process information.
2.5 Insurance Brokerage Data and Authorization
"Insurance Brokerage Data" means personal information, insurance information, application information, policy information, communications, documents, and related records collected, created, received, submitted, or retained in connection with insurance brokerage services. It may include information used for quoting, underwriting submissions, binding, policy issuance, servicing, renewals, endorsements, commissions, accounting, carrier communications, fraud prevention, dispute handling, regulatory compliance, and legal recordkeeping.
Information collected for policy analysis, risk assessment, or other Litmus Risk platform services will not be used by a Litmus-affiliated licensed insurance agency for insurance solicitation, quoting, carrier submission, placement, binding, or brokerage servicing unless the applicable channel rules below permit that use and you request or authorize those services.
For clients participating through a financial-advisory firm, the client may continue with an existing insurance professional or separately request services from Litmus Insurance Solutions. Information is provided to Litmus Insurance Solutions for solicitation, quoting, placement, binding, or brokerage servicing only when the client requests or authorizes those services.
For clients participating through a partner insurance agency or brokerage, the partner agency remains responsible for the client relationship, insurance advice, policy support, quoting, shopping, placement, claims assistance, claims coaching, and ongoing servicing. Client information processed for that partner is not provided to Litmus Insurance Solutions for independent sales, marketing, cross-selling, solicitation, quoting, placement, policy support, claims assistance, or claims coaching. This restriction does not prevent processing reasonably necessary to operate or secure the Litmus Risk platform, comply with law, or follow the partner agency's documented instructions.
If, through a Litmus Insurance Solutions client portal or otherwise, you request brokerage services from a Litmus-affiliated licensed insurance agency, you authorize the agency to use relevant information to evaluate insurance needs, prepare applications, request and present quotes, submit information to carriers and market partners, request binding, support policy issuance, service policies, manage renewals, provide claims-related support, maintain commission and accounting records, prevent fraud, resolve disputes, and comply with legal, carrier, and regulatory obligations.
You may withdraw a brokerage authorization prospectively by contacting us. Prior submissions, quotes, communications, binders, policies, servicing records, and related records may remain with Litmus, carriers, market partners, service providers, or other recipients where retention is required or permitted for legal, regulatory, carrier, accounting, commission, fraud-prevention, dispute-resolution, or insurance-recordkeeping purposes.
When brokerage services are provided by an unaffiliated insurance agency using the Litmus Risk platform, that agency is responsible for obtaining any authorization required for its brokerage activities and for describing its independent use of personal information in its own privacy notice.
2.6 Underwriting Reports and Carrier Information
Insurance carriers or market partners may obtain motor-vehicle reports, claims or loss-history reports, insurance scores, credit-based insurance scores, property data, or other underwriting information through their own processes and subject to applicable notices and authorizations. Litmus or the insurance agency providing brokerage services may receive resulting quote, eligibility, underwriting-referral, pricing, declination, non-renewal, binding, policy, renewal, billing-status, servicing, claims-status, commission, or carrier-correspondence information rather than the underlying consumer report itself.
3. California Notice at Collection
This Section 3 provides notice at or before collection for California residents. It describes the categories of personal information we may collect through the Services, the purposes for which we use them, and our retention approach. The examples below do not mean that we collect every example of information included in a CCPA category from every person.
3.1 Categories Collected and Purposes
- Identifiers. Examples include name, email address, telephone number, postal address or ZIP code, date of birth, account name, Internet Protocol address, and similar contact or online identifiers. We use identifiers to create and administer accounts, authenticate users, respond to requests, communicate with you, route inquiries, provide requested services, secure and operate the Services, maintain records, and comply with law.
- Customer-record information. Examples include contact details, signature, policy and claim information, property and asset information, financial information used for insurance or billing, and other information described in California Civil Code section 1798.80(e). We use this information to understand and fulfill requests, provide or support brokerage, advisory, claims-support, risk-management, and technology services, maintain records, and comply with legal, licensing, and regulatory obligations.
- Commercial information. Examples include insurance products, subscriptions, or services considered, requested, purchased, or received, along with transaction and service history. We use this information to respond to inquiries, provide and improve the Services, support brokerage and claims-support activities, process transactions, and maintain business records.
- Internet or other electronic-network activity. Examples include pages and features used, referring webpage, browser and device information, account and platform activity, access dates and times, and security, error, audit, or diagnostic logs. We use this information to deliver, personalize, secure, troubleshoot, measure, and improve the Services and to detect or prevent fraud, abuse, or security incidents.
- Geolocation data. We may derive an approximate city, region, or state from an Internet Protocol address, and we may collect location information you provide. We use this information to operate and secure the Services and to determine licensing, service availability, risk characteristics, and appropriate routing. We do not intentionally collect precise geolocation unless a feature clearly requests it and applicable notice or consent is provided.
- Professional or employment-related information. Examples include employer, business role, company, occupation, licenses, and agency or advisory-firm affiliation. We use this information to administer professional accounts, verify authority, provide business-related Services, and respond to commercial-coverage or other professional requests.
- Audio, electronic, visual, or similar information. Examples may include call or meeting recordings where permitted, photographs, videos, claim documentation, and files uploaded to the Services. We use this information to provide support, document instructions or losses, maintain quality and security, and provide requested Services.
- Inferences. We may derive insights concerning coverage needs, gaps, overlaps, risks, service interests, or likely preferences from information available to us. We use these inferences to provide analysis, recommendations, support, and requested Services. We do not use this information to create profiles for cross-context behavioral advertising.
3.2 Sensitive Personal Information
Depending on the Service, we may collect sensitive personal information as defined by the CCPA, such as account login credentials, precise geolocation when a feature clearly requests it, Social Security or driver's-license information needed for an authorized insurance transaction, or health information relevant to a claim or insurance request. We collect sensitive personal information only when reasonably necessary for the disclosed and permitted purposes. Please do not submit sensitive personal information through a general contact form or another channel not designated for it.
We use and disclose sensitive personal information only as reasonably necessary to provide requested Services, process or support insurance transactions or claims, authenticate users, maintain security, prevent fraud, comply with law, or for another purpose permitted by the CCPA. We do not use or disclose sensitive personal information to infer characteristics about you in a manner that triggers the CCPA right to limit.
Where applicable law requires consent or authorization before sensitive personal information is collected or processed, or before it is used for a materially different purpose, we will request the required consent or authorization. Where applicable, you may withdraw consent prospectively through the relevant Service or by contacting us, subject to legal, contractual, insurance, fraud-prevention, and recordkeeping requirements.
3.3 Retention at Collection
We retain each category described above only for as long as reasonably necessary and proportionate for the disclosed purposes. Relevant criteria include the nature of the inquiry; whether you become a client; the duration of our relationship; applicable insurance, licensing, legal, tax, fraud-prevention, and recordkeeping requirements; the need to resolve disputes or enforce agreements; and security considerations.
Inquiry and communication records may be retained for the period reasonably needed to respond, document our handling of the request, and satisfy applicable obligations. Account, platform, insurance, claims-support, transaction, and professional-service records may be retained for the duration of the relationship and the period needed afterward to satisfy contractual, legal, insurance, licensing, tax, fraud-prevention, dispute-resolution, and recordkeeping requirements. Technical and security logs are generally retained for shorter operational and security periods unless needed to investigate an incident or comply with law.
4. How We Use Personal Information
We may use personal information to:
- Respond to your questions and contact requests
- Route your inquiry to the appropriate Litmus professional
- Create, authenticate, administer, and support accounts
- Provide, personalize, analyze, and improve the Services
- Analyze policies, coverage, assets, exposures, risks, and claims-related information
- Discuss, evaluate, quote, place, service, or support insurance brokerage, advisory, risk-management, or claims-support services you request
- Communicate with you about your inquiry or relationship with Litmus
- Process subscriptions, payments, and business transactions
- Verify identity, authority, licensing, eligibility, and account access, and conduct due-diligence, fraud-prevention, sanctions, credit, consumer-report, or regulatory screening when relevant and permitted by law
- Operate, maintain, secure, troubleshoot, measure, and improve our websites, applications, platforms, and business
- Detect or prevent fraud, abuse, security incidents, or unlawful activity
- Comply with legal, licensing, regulatory, recordkeeping, and insurance-industry obligations
- Establish, exercise, or defend legal rights
- Create aggregated or deidentified information, where permitted by law
4.1 Artificial Intelligence Features
The Services may use artificial intelligence and machine-learning features provided by Litmus or third-party providers for policy-document ingestion, coverage analysis, automated recommendations, risk assessment, gap analysis, and interactive queries or responses.
AI-generated information may be inaccurate or incomplete and should be reviewed and validated before it is used to make insurance or risk-management decisions. AI features support informational and advisory functions and do not replace professional judgment or an insurance carrier's underwriting, pricing, eligibility, billing, policy-issuance, or claims determinations.
Litmus may use aggregated or deidentified information to monitor and improve platform performance, AI tools, and functionality. Customer personal data and Insurance Brokerage Data are not used to train AI models. Authorized AI workflows may process personal information to provide document processing, analysis, and other requested features subject to the applicable agreement and professional review.
AI features may analyze personal information and generate inferences, scores, summaries, recommendations, or other outputs concerning coverage, risk, or service needs. Litmus does not use AI features by themselves to make final insurance underwriting, pricing, eligibility, binding, policy-issuance, or claims decisions. Where applicable law requires a pre-use notice, explanation, access right, human review, consent, or ability to opt out of profiling or automated decisionmaking, Litmus or the organization responsible for the applicable decision will provide the required notice or choice.
5. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients:
- Litmus personnel and affiliates. We may provide information to team members who need it to respond to or service your inquiry, subject to the purpose limitations and channel separation described in this Statement.
- Service providers and contractors. We use providers that support cloud and website hosting, platform operation, security, identity verification, email delivery, communications, data storage, analytics, document processing, payment processing, customer support, and professional services. They may process information for the services they provide to us and subject to appropriate obligations.
- Litmus-affiliated and unaffiliated insurance agencies. We may provide information to Litmus Insurance Solutions when you use its client portal or separately request or authorize its brokerage services. At your direction or as part of the service arrangement through which you use the Litmus Risk platform, we may provide information to an unaffiliated insurance agency. An unaffiliated agency may use the information as an independent business under its own privacy notice when it provides brokerage services or manages its client relationship.
- Partner-agency channel separation. Client information processed for a partner insurance agency or brokerage is not provided to Litmus Insurance Solutions for independent sales, marketing, cross-selling, solicitation, quoting, or placement. The partner agency remains responsible for its client relationship and brokerage activities.
- Financial advisors, employers, and sponsoring organizations. If you access the Services through a financial advisor, employer, benefit program, or other sponsoring organization, we may disclose information to that organization consistent with your instructions, its arrangement with Litmus, and applicable law. Depending on the arrangement, this may include enrollment or engagement status, selected policy or protection summaries, service activity, and advisor-facing insights needed to support the relationship or administer an enterprise account. These organizations generally will not receive Social Security numbers, driver's-license numbers, detailed brokerage applications or quote submissions, carrier underwriting notes, or consumer-report information unless you authorize the disclosure, the organization has a defined role requiring the information, or disclosure is otherwise permitted by law. The organization may process information under its own privacy notice.
- Insurance-market participants. When brokerage, advisory, risk-management, or claims-support services are requested, we may provide relevant information to insurers, wholesalers, managing general agents, premium-finance providers, inspection companies, claims professionals, adjusters, and other insurance-service providers. Additional notices and authorizations may apply.
- Legal and regulatory recipients. We may disclose information when reasonably necessary to comply with law, a subpoena, court order, regulatory request, licensing obligation, or other legal process; to protect rights, safety, and security; or to investigate fraud or unlawful activity.
- Business-transaction participants. Information may be disclosed to professional advisors, counterparties, and others in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to applicable law.
Recipients you direct. We may disclose information when you direct us to do so or otherwise provide authorization.
6. California Disclosure for the Preceding 12 Months
During the 12 months preceding the Last Updated date, we may have collected the following CCPA categories described in Section 3: identifiers; customer-record information; commercial information; Internet or other electronic-network activity; geolocation data; professional or employment-related information; audio, electronic, visual, or similar information; inferences; and sensitive personal information.
We collected those categories from the sources described in Section 2.3 and used them for the business and commercial purposes described in Sections 3 and 4.
During that period, we may have disclosed the following categories for business purposes: identifiers; customer-record information; commercial information; Internet or other electronic-network activity; geolocation data; professional or employment-related information; audio, electronic, visual, or similar information; inferences; and sensitive personal information.
Depending on the information and purpose, and subject to the partner-agency channel separation described in Section 5, those categories may have been disclosed to the recipients described in Section 5, including Litmus personnel and affiliates; service providers and contractors; Litmus-affiliated or unaffiliated insurance agencies; financial advisors, employers, or sponsoring organizations; insurance-market participants; legal or regulatory recipients; business-transaction participants; and recipients you directed.
During the preceding 12 months, Litmus has not sold personal information for monetary or other valuable consideration and has not shared personal information for cross-context behavioral advertising as those terms are defined by the CCPA.
Litmus does not knowingly sell or share the personal information of consumers under 16 years of age.
7. Sale, Sharing, and Targeted Advertising
Litmus does not sell personal information for money or other valuable consideration.
Litmus does not share personal information for cross-context behavioral advertising as those terms are defined under California privacy law.
Because we do not currently sell or share personal information in those ways, we do not provide a "Do Not Sell or Share My Personal Information" link. If our practices change, we will update this Statement and provide any legally required choices before engaging in those activities.
8. Cookies, Similar Technologies, and Browser Signals
Our websites, applications, and platforms and their service providers may use cookies, software-development kits, local storage, pixels, and similar technologies needed to provide features, maintain sessions, remember preferences, protect forms and accounts, maintain security, prevent abuse, understand performance and usage, and support operation of the Services.
The Services do not currently use advertising technologies to build profiles for cross-context behavioral advertising.
You may configure your browser or device to limit cookies or similar technologies, although doing so may affect certain Service functions.
Some browsers transmit "Do Not Track," Global Privacy Control, or other universal opt-out preference signals. Because we do not currently sell personal information or share it for cross-context behavioral advertising, such signals generally do not change our current practices. Where applicable law requires recognition of a browser- or device-based opt-out preference signal, we will process a recognized signal as a request to opt out of the applicable sale, sharing, or targeted-advertising activity for the browser or device from which the signal is received and, where required and reasonably identifiable, for the associated account. We will not require you to create an account to submit such a signal.
9. Retention
We retain personal information only for as long as reasonably necessary and proportionate to provide the Services, administer the relevant relationship, maintain appropriate business and insurance records, comply with legal or regulatory requirements, resolve disputes, enforce agreements, and protect against fraud or security incidents.
Retention periods vary depending on the type of information, the Service and relationship involved, account status, and applicable contractual, legal, insurance-industry, tax, licensing, and security requirements. Additional category-specific retention information appears in Section 3.3.
When personal information is no longer reasonably necessary for an applicable purpose and no legal, contractual, insurance, security, dispute, or recordkeeping requirement supports continued retention, we may securely delete it or convert it to aggregated or deidentified information. We may retain and use aggregated or deidentified information as permitted by law and will not attempt to reidentify it except as permitted to test whether deidentification processes comply with applicable law.
Insurance Brokerage Data may be retained longer than advisory-platform or general account data and may not be deleted immediately after account cancellation or a deletion request. Relevant retention events may include policy expiration or cancellation, final servicing activity, final commission or accounting activity, and final resolution of a related claim, complaint, dispute, audit, investigation, or regulatory inquiry. Information may be retained longer when required or permitted by applicable law, carrier requirements, litigation hold, fraud prevention, dispute resolution, or insurance-recordkeeping obligations.
Deleting an uploaded file from an account or dashboard may not delete copies that have become part of brokerage, carrier, claims, compliance, security, backup, or legal records.
If personal information is processed by Litmus on behalf of a subscribing financial-advisory firm or insurance agency or brokerage, closing a Litmus account or asking Litmus to delete information may not delete information controlled by that organization. Requests concerning information controlled by a subscribing organization should generally be directed to that organization, and Litmus will assist the organization as required by applicable law and the applicable agreement.
10. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. These safeguards may include access controls, secure transmission, service-provider controls, monitoring, and employee practices appropriate to the nature of the information.
No website, application, transmission, or storage system can be guaranteed completely secure. Please use care when deciding what information to submit and use only channels designated for sensitive information.
If you receive or create account credentials, you are responsible for maintaining their confidentiality, using reasonable safeguards, and promptly notifying Litmus or the subscribing organization if you believe an account or credential has been compromised. Do not share credentials with unauthorized persons.
10.1 Service-Provider Processing Outside the United States
Litmus operates in the United States. Personal information may be processed in the United States or, where Litmus uses a service provider that operates in another country, in that country. Where applicable law requires safeguards for such processing, the party responsible for the transfer will use an approved transfer mechanism or other legally recognized safeguard.
11. California Privacy Rights
To the extent the CCPA applies to Litmus and the personal information involved, California residents may have the following rights:
- Right to know and access. You may request the categories and specific pieces of personal information we have collected about you; the categories of sources; our business or commercial purposes; the categories of third parties to whom we disclose information; and information concerning sale, sharing, or disclosure for a business purpose.
- Right to delete. You may request deletion of personal information we collected from you, subject to legal exceptions.
- Right to correct. You may request correction of inaccurate personal information we maintain about you.
- Right to portability. You may request a copy of eligible personal information in a portable and, where technically feasible, readily usable format.
- Right to opt out of sale or sharing. You may opt out of the sale of personal information or sharing for cross-context behavioral advertising. As explained above, Litmus does not currently engage in those activities.
- Right to limit use and disclosure of sensitive personal information. Where applicable, you may direct a business to limit certain uses or disclosures of sensitive personal information. Litmus does not use or disclose sensitive personal information for purposes that currently trigger this limitation right.
- Right to non-discrimination. We will not unlawfully discriminate or retaliate against you for exercising a privacy right. We will not deny services, charge a different price, provide a different level or quality of service, or suggest that you will receive different treatment because you exercised a CCPA right, except as permitted by law.
11.1 How to Submit a Request
You may submit a request by:
- Emailing privacy@litmusrisk.com with "California Privacy Request" in the subject line
- Writing to the Privacy Officer at the address in Section 17
- Calling our toll-free privacy request number at (833) 548-8677 during our published business hours
Please identify the right you wish to exercise and provide enough information for us to reasonably locate relevant records. Do not send Social Security numbers, passwords, complete policy documents, or other highly sensitive information with an initial request.
11.2 Verification and Response
We will confirm receipt and respond within the periods required by applicable law. The CCPA generally requires a substantive response to a verifiable request to know, delete, or correct within 45 days, subject to a permitted extension of up to an additional 45 days when reasonably necessary and when notice is provided.
We may verify your identity by matching information you provide with information already maintained by Litmus or by requesting additional information appropriate to the sensitivity of the request. We will use verification information only for verification, fraud prevention, and compliance. We will not require you to create an account solely to submit a request.
We may deny or limit a request where permitted by law, including when we cannot verify identity, the request is manifestly unfounded or excessive, or an exemption applies. If we deny a request, we will explain the basis to the extent required by law.
11.3 Authorized Agents
You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide written permission signed by you or evidence of a valid power of attorney. We may also contact you directly to verify your identity and confirm that you authorized the request, unless applicable law provides otherwise.
11.4 Request Frequency and Fees
We generally do not charge a fee to process a verifiable consumer request. We may charge a reasonable fee or decline to act on requests that are manifestly unfounded or excessive, particularly because of their repetitive character, as permitted by law. The CCPA does not require a business to provide access information to the same consumer more than twice in a 12-month period.
Certain information may be exempt from a request, including information subject to insurance, financial-privacy, fraud-prevention, legal, privilege, security, or recordkeeping requirements. The rights described in this Section do not apply to all information in every circumstance.
12. Privacy Rights Outside California
Depending on where you live and the law that applies, you may have additional rights concerning your personal information, including rights to access, correct, delete, obtain a portable copy, opt out of certain processing, limit certain uses of sensitive personal information, appeal a privacy-request decision, and receive equal service.
To submit a request, use one of the methods in Section 11.1. We will evaluate the request under the law applicable to you.
12.1 Appeals
If we decline to take action on a privacy request and applicable law provides a right to appeal, you may appeal by replying to our decision or by emailing privacy@litmusrisk.com with "Privacy Request Appeal" in the subject line. Please identify the request being appealed and explain why you believe our decision should be reconsidered. We will review and respond to the appeal within the period required by applicable law. If we deny an appeal, we will provide information about how to contact the appropriate state attorney general or other regulator where required.
13. Marketing Communications
Subject to applicable law and your choices, Litmus may communicate about its products, services, events, or educational materials by email, telephone, text message, postal mail, or similar channels. Where consent is required for a communication channel, we will request it before sending the applicable marketing communication. Client information processed for a partner insurance agency or brokerage is not used by Litmus Insurance Solutions for independent marketing, cross-selling, or solicitation.
You may opt out of promotional email by using the unsubscribe method included in the message or by contacting us. You may opt out of marketing text messages by following the instructions in the message, such as replying STOP. You may request that we not make marketing calls or send postal marketing by contacting us. Even after an opt-out, we may continue sending non-promotional communications concerning an inquiry, transaction, service, security matter, legal notice, or existing relationship.
13.1 Call and Meeting Recordings
Calls, virtual meetings, or conversations with Litmus representatives may be recorded or transcribed for quality assurance, training, service and product improvement, documentation, security, and operational purposes. We will provide notice or obtain consent where required by applicable law.
14. Children's Privacy
The Services are intended for adults and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through the Services. Information about a child may be included in insurance, household, claim, or risk-management records provided by a parent, guardian, authorized professional, insurer, or agency when permitted by law and reasonably necessary to provide the requested Services. We do not knowingly sell or share the personal information of consumers under 16. If you believe a child has submitted personal information without appropriate authorization, contact us so we can review and address the request.
15. Third-Party Services and Organizations
The Services may link to or integrate with insurers, insurance agencies, financial advisors, data providers, service providers, social media, and other third-party services or organizations. A third party's independent collection and use of personal information is governed by its own privacy notice, not this Statement.
If you use the Litmus Risk platform through an unaffiliated insurance agency, financial advisor, employer, or other organization, Litmus may process personal information to provide the platform and related services, while that organization may separately process the same or related information for its own purposes. Questions about that organization's practices should be directed to the organization.
16. Changes to This Statement
We may update this Statement as our Services, business relationships, or legal obligations change. We will post the revised Statement and update the "Last Updated" date. We review the California disclosures in this Statement at least once every 12 months. If required by law, we will provide additional notice before a material change takes effect.
17. Contact Us
Questions or requests concerning this Privacy Statement may be directed to:
Litmus Holdings, Inc. Privacy Officer 1230 Rosecrans Ave., Suite 300 Manhattan Beach, CA 90266
privacy@litmusrisk.com
(833) 548-8677 (toll-free)
For legal inquiries: legal@litmusrisk.com
