Legal
Data processing agreement
1. Roles
The customer (the MGA or coverholder) is the data controller of policyholder personal data contained in uploaded files. NorthThread is the data processor, processing that data solely to provide the contracted service.
2. Scope of processing
Processing is limited to: parsing uploaded files, normalising and validating records, generating bordereau outputs, and reconciling carrier statements, all at the customer's initiation. NorthThread does not use policyholder data for any other purpose, including model training.
3. Sub-processors
Hosting (DigitalOcean), object storage (S3-compatible), transactional email, and error monitoring. Masked, truncated samples may be processed by an AI provider during one-time mapping setup; policyholder names and contact details are masked before transmission.
4. Security
Encryption in transit and at rest; mandatory two-factor authentication for all users; row-level tenant isolation; append-only audit logging of access and processing actions; automated backups with tested restores.
5. Retention and offboarding
Uploaded files and derived records are retained for the life of the subscription (insurance record-keeping). On termination, the customer receives a full export; all customer data is hard-deleted 30 days after termination, on request sooner where law permits.
6. Assistance
NorthThread assists the controller with data subject requests, breach notification within 72 hours of awareness, and reasonable audit requests.