Privacy & Data Protection Notice
1. What we collect
We may collect your name, email address, phone number, assessment details, insurance quotations and policy documents, communications, account information and technical information necessary to operate the service.
2. Sensitive and health information
Insurance documents may contain sensitive information, including health information. Only provide information that is reasonably necessary for the requested review. Where possible, remove information that is not relevant to the assessment.
Where applicable, sensitive information is collected only with the consent required by law. The upload workflow separately asks the person submitting the information to acknowledge the collection and handling described in this notice. This does not replace any legal requirement that may apply to the provider.
3. Collection notice and why we use your information
At or before collection, we aim to tell you what is being collected, why it is needed, how it will be held, and the relevant rights and choices. We ask for only information reasonably necessary for the requested review.
- To receive and assess your insurance-review request.
- To determine the scope and complexity of the work.
- To analyse policy terms, quotations, limits, exclusions, conditions and material differences.
- To communicate with you and provide the requested report.
- To maintain security, prevent misuse and comply with legal obligations.
4. AI-assisted processing
Documents may be processed by automated and AI-assisted technology used to extract text and support structured insurance analysis. The service is configured to use AI as an analysis engine; a human reviewer remains responsible for the final output. Your documents are not used for advertising or published by Insurance Reviewer.
5. Third-party and overseas providers
The website and its document-processing workflow may rely on hosting, storage, authentication and AI technology providers. Some providers or infrastructure may be located outside Australia. Before commercial launch, the provider will maintain a current vendor register identifying relevant recipients, processing locations and contractual safeguards, and this notice will be updated where practicable to identify likely overseas recipient countries.
Where Australian privacy requirements apply, cross-border handling will be assessed against the applicable requirements, including APP 8 where relevant.
6. Security
Private case records and uploaded documents are access-controlled. Documents are stored under private case-specific storage keys rather than public document URLs. Reasonable technical and organisational safeguards are used to reduce risks of unauthorised access, modification, loss or disclosure.
7. Retention and deletion
Information is retained only for as long as reasonably necessary for the purpose for which it was collected, service administration, security, dispute handling and applicable legal obligations. A documented retention schedule will be maintained before paid commercial launch. When information is no longer required and no lawful retention obligation applies, it will be securely deleted or de-identified as appropriate.
8. Access and correction
Subject to applicable law and any relevant exceptions, you may request access to or correction of personal information held about you. Requests should be made through the contact details provided for the service.
9. Data breaches
If a security incident occurs, the service provider will assess it and take steps required by applicable law, including any applicable notification obligations.
10. Complaints and contact
Privacy questions, access or correction requests, and complaints should be directed to the service provider through the contact details published by Insurance Reviewer. Before commercial launch, the final version of this notice will identify the legal provider, privacy contact, contact address and applicable external complaint pathway, including any relevant OAIC pathway where applicable.
11. Changes
This notice may be updated as the service, technology providers or legal requirements change. The applicable version will be shown when consent or acknowledgement is requested.
Read the Client Confidentiality & Document Handling Agreement →