← Back to IntelligenceClaim

Privacy Policy

Version 1.0 · Effective July 1, 2026 · Last updated July 1, 2026

Notice. By accessing or using any IntelligenceClaim service, application, or platform, you confirm that you have read, understood, and agreed to this Privacy Policy in full. If you do not agree, you must immediately cease all use of our Services.

1. About this policy and who we are

IntelligenceClaim is operated by MH Consulting Group AB, a Swedish limited liability company (“IntelligenceClaim,” “we,” “us,” or “our”). We develop and operate a cloud based, AI powered software platform and suite of associated tools designed to assist professionals in the property restoration and insurance claim industry (“Platform” or “Services”). This Privacy Policy (“Policy”) is a binding legal document that explains in comprehensive detail how we collect, receive, process, use, store, share, transfer, protect, and delete information relating to you, your organization, and the data you interact with when using our Services.

This Policy applies to all services, interfaces, features, websites, mobile applications, browser extensions, integrations, APIs, automated agents, and any other mechanisms through which you interact with IntelligenceClaim. It applies to:

  • Business entities and organizations that subscribe to or access the Platform in any capacity (“Clients” or “Organizations”);
  • Individual employees, contractors, representatives, or agents authorized by an Organization to use the Platform (“Authorized Users” or “Users”);
  • Visitors to our website, marketing pages, or any IntelligenceClaim operated web property;
  • Any person whose data is processed, stored, or analyzed in connection with our Services, whether or not they have a direct relationship with IntelligenceClaim.

This Policy does not govern the privacy practices of third party services, APIs, or platforms that IntelligenceClaim may integrate with, connect to, or reference. Those services operate under their own privacy policies, and you should review them independently.

If you have entered into a separate, written Data Processing Agreement or Master Services Agreement with IntelligenceClaim, the terms of that agreement supplement and may, where expressly stated, supersede portions of this Policy.

2. Definitions

The following definitions apply throughout this Policy:

  • “Aggregated Data” means data that has been combined with data from other sources and stripped of all identifying attributes such that it cannot reasonably be used to identify any individual, Organization, claim, or property.
  • “Anonymized Data” means data that has been irreversibly processed such that re identification of any individual, Organization, or specific claim is not technically feasible.
  • “Carrier Intelligence Database” means IntelligenceClaim's proprietary cross tenant database of anonymized, aggregated carrier response patterns, claim outcomes, denial patterns, and related analytical data collected from all Organizations using the Platform.
  • “Organization Data” means all content, documents, information, and data uploaded, submitted, or otherwise provided to the Platform by or on behalf of an Organization.
  • “Personal Information” means information that identifies or could reasonably identify a specific individual.
  • “Processing” means any operation performed on data, including collection, recording, storage, use, analysis, disclosure, transmission, or deletion.
  • “Services” means the IntelligenceClaim Platform, all associated web applications, browser extensions, APIs, automated agents, integrations, email communications, and any other service provided by IntelligenceClaim.

3. Information we collect

We collect information from multiple sources and in multiple forms in order to provide, operate, secure, improve, and promote our Services.

3.1 Information you provide directly

When an Organization or User registers for, configures, or uses the Services, we collect information actively provided to us:

3.1.1 Organizational information

  • Business name, trade name, or operating name;
  • Business address, registered address, and correspondence address;
  • Business registration numbers, tax identification numbers, and other legally required business identifiers;
  • Subscription tier, billing contact, and payment details;
  • Organization logo, brand assets, and color preferences submitted for white label configuration;
  • Custom pricing lists and line item databases.

3.1.2 User account information

  • Full name, email address, and job title;
  • Role and permission level within the Organization;
  • Login credentials (passwords stored only in cryptographically hashed form, we never store plaintext passwords);
  • Profile preferences and notification settings.

3.1.3 Claim and project data

  • Insurance claim numbers, project identifiers, and file references;
  • Carrier names, adjuster names, and insurance policy details;
  • Project manager names, field technician assignments, and contractor information;
  • Property addresses, damage descriptions, and loss event details;
  • Encircle field notes, photo metadata, and site survey data.

3.1.4 Uploaded documents and media

  • PDF documents of any type, including adjuster reports, scopes of work, invoices, moisture logs, certificates, and correspondence;
  • Photographs and images in standard digital formats;
  • Insurance carrier response letters, denial notices, and claim correspondence;
  • Field notes, inspection reports, and any other documents uploaded for analysis or storage;
  • PDF reports attached to your projects, including Xactimate estimates, mitigation, equipment and photo reports.

3.1.5 Communications

  • Support requests and tickets submitted through any channel;
  • Feedback, survey responses, and testimonials;
  • Emails, chat messages, and other direct communications with IntelligenceClaim personnel.

3.2 Information collected automatically

We automatically collect technical and usage information when you access or use the Services:

  • Network and device identifiers including IP addresses and device fingerprints;
  • Browser type, version, operating system, and device characteristics;
  • Referring URLs, pages viewed, click paths, timestamps, and session durations;
  • Features accessed, actions performed, and workflow interactions within the Platform;
  • Analysis requests submitted, documents uploaded, findings reviewed, and outputs generated;
  • System performance metrics, error events, and application health data;
  • Authentication events including login times, session tokens, and access attempts;
  • Cookie and session data described further in Section 8.

3.3 AI analysis and processing data

When you submit documents or data for AI powered analysis, we collect and process:

  • Full document content extracted from uploaded PDFs, images, and files;
  • AI model inputs including structured prompts, rule sets, and contextual data;
  • AI model outputs including findings, deductions, recommendations, rebuttal drafts, and narrative outputs;
  • Confidence scores, reasoning traces, and evidence references generated by the AI;
  • User interactions with AI outputs, including approvals, rejections, edits, and overrides;
  • Computational resource consumption, token usage, and processing costs associated with each analysis;
  • Prompt versions and model versions used for each analysis, retained for reproducibility and audit purposes.

3.4 Anonymized and aggregated intelligence data, important disclosure

Consent to anonymized data collection. By using the Services, each Organization expressly consents to IntelligenceClaim collecting, processing, and retaining anonymized, non attributable analysis outcomes for inclusion in the Carrier Intelligence Database and for AI model development. This is a core function of the platform and a condition of Service access. See below for full details.

IntelligenceClaim collects and maintains a proprietary cross tenant Carrier Intelligence Database for the purpose of improving analytical accuracy, training AI models, and providing industry wide intelligence to all Platform users. This database is built from anonymized data contributed by all Organizations using the Platform. Specifically, we collect and retain:

  • Anonymized patterns of insurance carrier responses to specific claim line items, stripped of all identifying information;
  • Aggregated statistical outcomes, claim approvals, denials, and partial payments, aggregated across all Organizations, with no individual Organization identifier, User identifier, claim number, property address, or claimant name retained;
  • Aggregated finding types, deduction categories, denial reason codes, and associated success and failure rates;
  • Normalized documentation quality benchmarks, capture rates, and recovery rates by damage type and geographic region (state level or broader only);
  • Statistical model performance data used to evaluate and improve the accuracy of our AI analysis engine.

The anonymization and aggregation process is irreversible. Once data has been incorporated into the Carrier Intelligence Database or used for model training, it is not attributable to any specific Organization, User, claim, claimant, contractor, or property. IntelligenceClaim represents that the Carrier Intelligence Database does not and will not contain any of the following: Organization names or identifiers, user names or email addresses, claim numbers, property addresses, claimant names, contractor names, or any other information that could reasonably be used to identify a specific Organization or claim.

If an Organization wishes to opt out of contributing anonymized data to the Carrier Intelligence Database on a prospective basis, it must submit a written opt out request prior to or at the time of contract execution. Opt out requests received mid subscription will be honored prospectively from the date of receipt. Data already anonymized, aggregated, and incorporated into the database prior to the opt out request cannot be removed, as it is no longer attributable to any Organization.

3.5 Integration and third party data

When you authorize integrations with third party services, we receive data from those services as permitted by your credentials and the applicable integration scope. We use this data solely to provide the Services. The nature of data received depends on the integration authorized, and we encourage you to review the privacy policies of any third party services you connect to the Platform.

3.6 Data from other sources

  • Information provided by Organization administrators when creating accounts for other Users;
  • Information received through referral programs or partnership arrangements;
  • Publicly available business information used to verify account details.

4. How we use your information

We process information collected about you and your Organization for the following purposes, all of which are necessary to operate, improve, secure, and grow the Services.

Lawful basis for processing (GDPR Article 6)

For data subjects whose information is protected by the GDPR, UK GDPR, or equivalent laws, IntelligenceClaim relies on the following lawful bases:

  • Article 6(1)(b), Performance of a contract: processing necessary to deliver the Services to the Organization under the Terms of Service, including user account management, document storage, AI analysis, and billing.
  • Article 6(1)(f), Legitimate interests: security monitoring and fraud prevention; product analytics and improvement using anonymized data; sub processor management; internal record keeping; customer relationship management. Our legitimate interests have been balanced against the rights and freedoms of data subjects; you may object at any time as described in Section 9.
  • Article 6(1)(c), Legal obligation: retention of billing records, tax compliance, response to lawful authority requests, and obligations under data protection law (including breach notification).
  • Article 6(1)(a), Consent: for marketing communications to EU/EEA recipients (which are opt in rather than opt out), for participation in attributed case studies, and for the optional CompanyCam integration when the Organization connects it. You may withdraw consent at any time without affecting prior processing.
  • Article 9(2)(a), Explicit consent: not relied upon by default. The Organization shall not upload special categories of personal data (Article 9 GDPR) without entering a separate written addendum with IntelligenceClaim.

4.1 Providing and operating the Services

  • Processing document uploads and executing AI powered analyses;
  • Generating findings, recommendations, rebuttal letter drafts, narrative reports, and data exports;
  • Managing user authentication, session management, and access controls;
  • Synchronizing data with authorized third party integrations;
  • Storing and retrieving claim records, analysis histories, and uploaded documents;
  • Delivering notifications, analysis results, and operational communications;
  • Processing subscription fees and managing billing.

4.2 Improving and developing the Services

  • Analyzing anonymized, aggregated usage patterns to improve Platform features and user experience;
  • Developing, testing, and refining AI models using anonymized outputs and outcomes;
  • Improving the accuracy and relevance of analysis outputs through model training and evaluation;
  • Expanding and improving the Carrier Intelligence Database;
  • Conducting research and development on new features, capabilities, and product improvements;
  • Evaluating and optimizing AI prompt strategies, rule engines, and analytical frameworks.

4.3 Marketing and communications, including use of your brand assets

Marketing rights. By accepting these Terms and using the Services, you grant IntelligenceClaim the rights described in this Section 4.3, including the right to reference your organization name and logo as a customer. See details below.

IntelligenceClaim uses the following information for marketing, promotion, and business development purposes:

  • We may identify your Organization as an IntelligenceClaim customer and reference your Organization's name in our marketing materials, on our website, in investor presentations, in press releases, in partner communications, and in sales materials, unless you submit a written opt out request to us. This right is non exclusive and limited to factual identification as a customer.
  • We may display your Organization's logo alongside your name in customer lists, testimonial sections, case study pages, product marketing materials, and partner showcases. We will use only logo versions and brand assets you have submitted to the Platform or made publicly available. We will not alter your logo in a way that distorts its appearance or meaning.
  • We may use masked, anonymized, and aggregated data derived from your Platform usage, such as percentage improvements in claim capture rates, average savings identified per analysis, or documentation quality improvements, in case studies, product marketing, research publications, and investor materials. Masked data used in this way will never identify your Organization by name unless you have provided separate written consent for an attributed case study.
  • If you agree to participate in an attributed case study, press release, testimonial, or co marketing activity, we will prepare and share the content with you for review and approval before publication.
  • You grant IntelligenceClaim a limited, non exclusive, worldwide, royalty free license to use and display your Organization's name and logo solely for the purposes described in this Section during the subscription term and for a period of 24 months after termination, after which we will remove your brand assets from active marketing materials unless you have provided extended consent.
  • We may use testimonials, quotes, or success stories you have voluntarily submitted to IntelligenceClaim in marketing materials, with attribution to you or your Organization as applicable, subject to your approval of the specific use.
  • Sending transactional emails including account setup, analysis results, monthly ROI reports, product updates, and service announcements;
  • Sending marketing communications about IntelligenceClaim products and features; you may opt out of marketing communications at any time by using the unsubscribe link in any email or contacting us at the email address below.

4.4 Security and fraud prevention

  • Monitoring access patterns for signs of unauthorized use, security threats, or abuse;
  • Enforcing access controls, tenant isolation, and permission boundaries;
  • Detecting and investigating potential fraud, policy violations, or illegal activity;
  • Maintaining comprehensive audit records of all access and modification events;
  • Executing automated security monitoring and anomaly detection routines.

4.5 Legal and compliance

  • Complying with applicable laws, regulations, and legal processes;
  • Enforcing our Terms of Service and other agreements;
  • Protecting the rights, property, and safety of IntelligenceClaim, our customers, and the public;
  • Responding to valid legal requests from government authorities or courts.

5. Information sharing and disclosure

5.1 No sale of personal information

IntelligenceClaim does not sell, rent, trade, or otherwise transfer personally identifiable information or individually identifiable Organization Data to third parties for their own commercial or marketing purposes. We do not participate in data broker networks. We do not permit third party advertising networks to collect data about our users through the Platform.

5.2 Service providers and technology partners

We engage carefully selected third party service providers who process data on our behalf and under our instruction solely to deliver the Services. These providers are contractually bound to implement appropriate security measures, to process data only as directed by IntelligenceClaim, and not to use your data for their own purposes. Our current categories of service providers include:

  • Cloud infrastructure and database hosting providers;
  • AI model providers that process document content to generate analysis outputs;
  • Email delivery services for transactional and operational communications;
  • Payment processing services for subscription fee collection;
  • Application performance monitoring and error tracking services;
  • Content delivery and web application performance services.

A current list of sub processors is published at /legal/subprocessors and includes each sub processor's purpose, location, and the categories of data accessed. We will notify customers at least thirty (30) days in advance of any new or replacement sub processor by updating that page.

5.3 AI model providers

To deliver AI analysis capabilities, documents and data you submit for analysis are processed by third party AI model providers. IntelligenceClaim may use AI models and services from multiple providers, which may include but are not limited to large language model providers and multimodal AI model providers. Data submitted for AI processing is processed in accordance with the applicable AI provider's API usage policies and our agreements with those providers. We implement appropriate safeguards and data handling requirements in our agreements with AI model providers. IntelligenceClaim does not permit AI model providers to use your data to train their general purpose models for use by other customers.

5.4 Anonymized aggregated data sharing

IntelligenceClaim may share or publish anonymized, aggregated statistical data derived from the Carrier Intelligence Database and Platform usage in the following contexts:

  • Industry research reports, white papers, and publications;
  • Product marketing materials and case studies;
  • Investor communications and financial disclosures;
  • Partnership and business development materials;
  • Academic or industry conference presentations.

Any data shared in these contexts is aggregated and anonymized and will not contain information that could identify any Organization, User, claimant, or specific claim.

5.5 Marketing use of organization names and logos

As described in Section 4.3, IntelligenceClaim may use your Organization's name and logo for customer identification purposes in marketing materials. This use is limited to factual identification as a customer and does not imply endorsement of any specific IntelligenceClaim claim, result, or product feature beyond your general status as a customer.

5.6 Legal disclosures

We may disclose information when we have a good faith belief that disclosure is required or permitted by applicable law, including in response to:

  • A valid subpoena, court order, or legal process;
  • A lawful request by a governmental, regulatory, or law enforcement authority;
  • An emergency where disclosure is necessary to protect the safety of any person;
  • A legal claim or proceeding in which IntelligenceClaim is a party and disclosure is relevant.

Where legally permissible, we will provide advance notice of legal disclosures to the relevant Organization.

5.7 Business transactions

If IntelligenceClaim is involved in a merger, acquisition, asset sale, financing transaction, bankruptcy proceeding, or similar corporate event, your information may be disclosed to or transferred to the counterparty or acquirer as part of that transaction. We will provide notice of any such transfer that materially affects the treatment of your data.

5.8 Consent based disclosure

We may share your information in other circumstances with your express written consent or at your explicit direction.

5.9 Aggregated, de identified, or non personal information

We may share aggregated, de identified, or non personal information, information that cannot reasonably be used to identify you or your Organization, without restriction for any lawful purpose, including research, marketing, analysis, and product development.

6. Data retention

We retain data for the periods described below. Retention periods are determined by the nature of the data, our legitimate business needs, legal obligations, and applicable regulatory requirements in the insurance and construction industries.

  • Active account and User data is retained throughout the active subscription period.
  • Claim records, analysis outputs, and associated findings are retained for seven (7) years from the date of creation, consistent with standard record keeping expectations for insurance related documentation.
  • Uploaded documents and media files are retained for the duration of the active subscription plus ninety (90) days following termination, after which they are permanently deleted unless the Organization requests earlier deletion or an extended retention period is agreed in writing.
  • Billing records, invoices, and payment history are retained for seven (7) years for financial compliance purposes.
  • Security and access audit records are retained for three (3) years.
  • Communications and support records are retained for three (3) years from the date of last interaction.
  • Anonymized, aggregated Carrier Intelligence Database data is retained indefinitely as it contains no personal or organizational identifiers and is not attributable to any specific party.

Upon subscription termination, the Organization may submit a written data export request within thirty (30) days, and IntelligenceClaim will provide a structured export of the Organization's claim records and analysis data within thirty (30) business days of the request. Following the 90 day post termination window, IntelligenceClaim will permanently delete all individually identifiable Organization and User data from active systems, subject to the retention obligations above and any active legal hold. Deletion from backup systems may take an additional sixty (60) days.

7. Data security

IntelligenceClaim takes the security of your data seriously and implements a multi layered security architecture to protect against unauthorized access, disclosure, alteration, or destruction. We maintain technical, administrative, and organizational security measures including:

  • All data stored within our systems is encrypted at rest using industry standard encryption algorithms;
  • All data transmitted between your browser or application and our servers is encrypted in transit using current industry standard protocols;
  • API keys, integration credentials, and secret tokens are stored in dedicated secure credential management systems with hardware level protection and are never stored in plaintext;
  • Database layer access controls ensure that each Organization can only access its own data, it is technically impossible for one Organization's users to read or modify another Organization's records through the Platform;
  • All user actions, data modifications, and administrative events are recorded in comprehensive, tamper resistant audit logs;
  • Administrator impersonation sessions, where IntelligenceClaim support staff access an Organization's environment for troubleshooting, are time limited, require a documented reason, and are fully logged and auditable;
  • Automated security monitoring routines continuously scan for anomalous access patterns and potential cross tenant access violations;
  • All code changes deployed to the production environment are subject to mandatory peer review before release;
  • We conduct regular security assessments and maintain a responsible disclosure policy for security researchers.

Despite these measures, no system connected to the internet can guarantee absolute security. IntelligenceClaim cannot warrant or guarantee that unauthorized access, data breaches, or security incidents will never occur.

Breach notification. In the event of a personal data breach affecting Customer Personal Data, IntelligenceClaim will notify the affected Organization without undue delay and in any event within seventy two (72) hours of becoming aware of the breach, in accordance with GDPR Article 33. The notification will include the nature of the breach, categories and approximate number of data subjects and records affected (insofar as known), likely consequences, measures taken or proposed to address the breach, and contact details for further information. Where required by law, we will also notify the competent supervisory authority and, where required, affected data subjects directly. Notifications under US state breach notification laws (including California Civ. Code § 1798.82) will be issued on the timelines required by those laws.

8. Cookies and tracking technologies

IntelligenceClaim uses cookies and similar tracking technologies within the Platform for operational, functional, and analytics purposes. We do not use third party advertising trackers or cross site behavioral tracking technologies.

8.1 Strictly necessary technologies

These are technologies that are essential for the Platform to function. They include session authentication tokens, security tokens, load balancing cookies, and similar mechanisms. These technologies cannot be disabled without preventing you from using the Services.

8.2 Functional technologies

These technologies remember your preferences, settings, and interactions to provide a more personalized and efficient experience. Examples include remembered filter settings, display preferences, and session state. Disabling these technologies may degrade your experience but will not prevent access.

8.3 Analytics technologies

We use aggregated, anonymized analytics to understand how the Platform is used, which features are most valuable, and where performance can be improved. We do not use individual level behavioral tracking for advertising purposes. Analytics data is processed in aggregate and does not identify specific individuals.

8.4 Your choices

You may configure your browser to reject certain cookies. Strictly necessary cookies cannot be rejected without losing access to the Services. You may opt out of analytics collection by contacting us, though aggregate, anonymized analytics do not identify you personally.

9. Your rights and choices

9.1 Access and correction

Authorized Users may access and update their personal account information, including name, email address, and notification preferences, directly within the Platform. Organizations may request a summary of data held about them by contacting us.

9.2 Data export

Organizations have the right to request a complete structured export of their claim data, analysis outputs, and associated records. Export requests should be submitted in writing and will be fulfilled within thirty (30) business days.

9.3 Deletion

You may request deletion of your personal data. We will delete or anonymize personal data within sixty (60) days of a verified request, subject to: (a) legal and regulatory retention obligations; (b) active contractual obligations; (c) the technical impossibility of removing data from anonymized aggregated datasets where re identification is not feasible.

9.4 Opt out of marketing communications

You may opt out of marketing emails at any time using the unsubscribe link in any marketing email or by contacting us at the address in Section 14. Transactional and operational communications cannot be opted out of while you maintain an active account.

9.5 Opt out of brand usage in marketing

Organizations that wish to opt out of having their name or logo used in IntelligenceClaim marketing materials as described in Section 4.3 must submit a written request to us. We will remove your brand assets from active marketing materials within sixty (60) days of receiving the request. Previously published materials featuring your name or logo may take longer to update across all distribution channels.

9.6 Opt out of anonymized data contribution

As described in Section 3.4, Organizations may opt out of prospective contribution of anonymized data to the Carrier Intelligence Database by submitting a written request. Retroactive removal of already anonymized and incorporated data is not technically feasible.

9.7 Rights under GDPR / UK GDPR

IntelligenceClaim is operated from Sweden and is subject to the EU General Data Protection Regulation (GDPR). If you are an individual in the EU/EEA, the UK, or Switzerland, you have the following rights with respect to your Personal Information:

  • Right to be informed (Articles 13–14): to receive the information set out in this Policy about how your data is processed.
  • Right of access (Article 15): to obtain confirmation of whether we process your Personal Data and to receive a copy of it.
  • Right to rectification (Article 16): to have inaccurate or incomplete Personal Data corrected.
  • Right to erasure / “right to be forgotten” (Article 17): to have your Personal Data deleted in the circumstances described in the Article.
  • Right to restriction of processing (Article 18): to have processing restricted while we verify the basis for processing or while you contest accuracy.
  • Right to data portability (Article 20): to receive your Personal Data in a structured, commonly used, machine readable format and to transmit it to another controller.
  • Right to object (Article 21): to object to processing carried out on the basis of legitimate interests, including profiling, on grounds relating to your particular situation. To object to direct marketing, see Section 9.4.
  • Right not to be subject to automated decision making (Article 22): the Platform does not engage in automated individual decision making that produces legal effects or similarly significant effects without human intervention. Every AI output is reviewed by a qualified human before any business action is taken.
  • Right to withdraw consent (Article 7(3)): where processing is based on your consent, you may withdraw that consent at any time without affecting prior processing.
  • Right to lodge a complaint (Article 77): with a competent supervisory authority. EU/EEA residents may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the data protection authority in their country of residence. UK residents may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, contact us at the email address in Section 14. We will respond without undue delay and in any event within one (1) month of receipt of the request, extendable by up to two (2) further months where necessary, taking into account the complexity and number of requests, in accordance with GDPR Article 12(3).

9.8 California residents, CCPA / CPRA rights

If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following specific rights with respect to your Personal Information:

  • Right to know: request disclosure of the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to delete: request deletion of Personal Information we have collected from you, subject to legal exemptions.
  • Right to correct: request correction of inaccurate Personal Information we hold about you.
  • Right to opt out of sale or sharing: IntelligenceClaim does not “sell” or “share” Personal Information as those terms are defined under the CCPA / CPRA. You are nonetheless entitled to direct us not to sell or share Personal Information about you.
  • Right to limit use of sensitive Personal Information: we do not collect or process “sensitive Personal Information” for purposes that would trigger this right, but you may direct us to limit use to what is necessary to provide the Services if such collection occurs.
  • Right to non discrimination: we will not deny services, charge different prices, or provide different levels of quality because you exercised a CCPA / CPRA right.
  • Right to portability: request that we transmit your Personal Information to you or to a third party in a structured, commonly used, machine readable format.
  • Right to opt out of automated decision making: the Platform does not engage in automated decision making affecting California residents. Every AI output is reviewed by a qualified human before any business action is taken.

To exercise any of these rights, contact us at the email address in Section 14. We will respond to verifiable requests within forty five (45) days, extendable by an additional forty five (45) days where reasonably necessary, as permitted under the CCPA / CPRA. You may also designate an authorized agent to make a request on your behalf.

Notice at collection: The categories of Personal Information we collect are listed in Section 3 of this Policy. The business purposes for which we collect each category are listed in Section 4. We retain Personal Information for the periods listed in Section 6.

Do Not Sell or Share My Personal Information: We do not sell or share Personal Information for cross context behavioral advertising or for monetary consideration. No opt out mechanism is required because no sale or sharing occurs.

9.9 Other US state privacy laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other US states with enacted consumer privacy laws have similar rights to access, delete, correct, and opt out of certain processing. To exercise these rights, contact us at the email address in Section 14. We process such requests under the framework most protective of your rights regardless of your state of residence.

9.10 Verification

We will take reasonable steps to verify your identity before responding to rights requests to protect against fraudulent or unauthorized requests.

10. International data transfers

IntelligenceClaim is based in Sweden, with primary infrastructure operated by trusted cloud providers in the European Union and the United States. Some processing, including AI analysis carried out by our third party AI providers, necessarily takes place outside the European Economic Area (EEA), primarily in the United States. A current sub processor list with location and purpose is published at /legal/subprocessors.

Transfer mechanism. Where Personal Data is transferred outside the EEA, the UK, or Switzerland to a country not covered by a European Commission adequacy decision (including the United States), we rely on the European Commission's Standard Contractual Clauses (SCCs), Decision (EU) 2021/914, and, for UK GDPR transfers, the UK International Data Transfer Addendum issued by the ICO. The IntelligenceClaim Data Processing Agreement at /legal/dpa incorporates the SCCs (Module 2: Controller to Processor) by reference.

Schrems II transfer impact assessment. Consistent with the Court of Justice of the European Union's ruling in Case C-311/18 (Schrems II), we have conducted a transfer impact assessment (TIA) for our US based sub processors. The TIA considers the laws and practices of the recipient country (including FISA 702 and EO 12333), the type of data transferred, and the nature of processing. Based on this assessment, we have determined that the following supplementary measures, combined with the SCCs, provide an essentially equivalent level of protection:

  • Encryption in transit and at rest using current industry standard algorithms across all transferred data;
  • Sub processor contractual restrictions prohibiting use of Customer Personal Data for any purpose other than provision of the Services on documented instructions, and specifically prohibiting AI model providers from using Customer Personal Data to train their general purpose models;
  • Strict tenant isolation enforced at the database layer so that one Customer's data cannot be read by another Customer or by a US government request directed at another Customer;
  • Tamper resistant audit logging enabling Customers to verify access to their data;
  • Government access request review: IntelligenceClaim will review any government request for Customer Personal Data for validity under applicable law and will challenge requests that we believe are unlawful or overbroad. Where legally permitted, we will notify the affected Organization of any such request.

By using the Services, you acknowledge and consent to these cross border transfers subject to the safeguards described above. A copy of the TIA summary is available to Customers on written request to the email address in Section 14.

11. Children's privacy

The IntelligenceClaim Services are intended exclusively for business use by professionals and are not directed at, marketed to, or intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a person under 18 without verifiable parental or guardian consent, we will take steps to delete that information promptly. If you believe we have collected information from a minor, please contact us immediately.

12. Third party links and integrations

The Services may contain links to, or integrations with, third party websites, applications, and services. IntelligenceClaim does not control and is not responsible for the privacy practices of third party services. Links to third party sites are provided for your convenience and do not constitute endorsement of those services or their privacy practices. We strongly encourage you to review the privacy policies of any third party services you interact with through or alongside the Platform.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. For material changes, meaning changes that materially affect your rights or the way we use your data, we will provide at least thirty (30) days' notice by email to the Organization's primary contact and by prominent notice within the Platform prior to the changes taking effect. For non material clarifications or corrections, updated versions will be published with a revised “Last Updated” date. Continued use of the Services after the effective date of any updated Policy constitutes acceptance of the changes. If you disagree with material changes, you may terminate your subscription before they take effect.

14. Contact information

For any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact:

IntelligenceClaim, Privacy Team
MH Consulting Group AB
admin@intelligenceclaim.com

We will acknowledge receipt of your inquiry promptly and respond to verifiable requests within thirty (30) business days.


IntelligenceClaim, a service of MH Consulting Group AB
© 2026 MH Consulting Group AB. All Rights Reserved.