Legal
Privacy Policy
Last updated 24 June 2026
This Privacy Policy explains how iqava ("iqava", "we", "us") collects, uses, shares and protects personal data in connection with our website, the iqava platform, and related services (together, the "Service"). It applies to visitors, the people who use the Service on behalf of a customer organization, and individuals whose data is processed within the Service.
Controller vs processor
For our website and our own business operations (e.g. account administration, billing, support), iqava is the data controller. When we process data that a customer organization puts into the platform (their users, clients, policies, claims, finance records, etc.), that organization is the controller and iqava acts as a processor on its documented instructions under our customer agreement / Data Processing Agreement (DPA). If you are an employee or customer of one of our customers, please direct privacy requests to that organization in the first instance.
Information we collect
- Account & profile data — name, work email, organization, job role and workspace settings.
- Authentication data — passwords (salted and hashed, never stored in clear), MFA enrolment, password-reset/verification tokens, and SSO identifiers returned by your identity provider.
- Directory data — where an administrator connects directory sync (Microsoft Entra / Google Workspace), we read user profiles (display name, email/UPN, account-enabled status) and group memberships to provision accounts and map roles. See "Microsoft / directory integrations" below.
- Customer & business data — records entered into the platform (clients, contacts, policies, claims, treaties, cessions, finance, documents). This is controlled by the customer organization.
- Marketplace & consumer data — where you use the public marketplace or customer portal, the contact details and request information you submit (name, email, phone, message).
- Billing data — for paid plans, the order, plan and billing-contact details needed to invoice you (card data, if any, is handled by our payment processor, not stored by us).
- Usage, log & device data — IP address (and a hashed IP for abuse-tracing on public forms), timestamps, actions taken, and basic telemetry needed to operate, secure and improve the Service.
- Communications — messages you send us (e.g. via the contact form or support email).
Microsoft / directory integrations
When an administrator of your organization authorizes the directory integration, iqava uses read-only, least-privilege permissions (e.g. User.Read.All and GroupMember.Read.All on Microsoft Graph) solelyto: read user profiles and group memberships, provision or update the corresponding iqava accounts, and map directory groups to iqava roles. We do not use directory data for advertising or any purpose unrelated to operating the Service, and we do not write back to your directory. Authorization is granted by your tenant administrator via Microsoft's admin-consent screen and can be revoked at any time from your identity provider or by disabling the connection in iqava.
How we use personal data
- To provide, operate, maintain and secure the Service and authenticate users.
- To enforce access control (roles, permissions and tenant isolation) and keep an audit trail.
- To provision and synchronize accounts from a connected directory.
- To process marketplace and portal requests and route them to the relevant provider.
- To bill for paid plans, provide support, and send service and security communications.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To improve the Service and develop new features, and to comply with legal obligations.
Legal bases (where GDPR / similar laws apply)
We rely on: performance of a contract (to provide the Service to you/your organization); legitimate interests (to secure, support and improve the Service, prevent abuse, and run our business) balanced against your rights; consent (e.g. optional cookies and certain communications), which you can withdraw at any time; and legal obligation (e.g. tax, accounting and lawful requests).
AI features
Some features use AI models to assist you (e.g. claims triage, reconciliation suggestions, form generation and assistants). Content you submit to these features may be processed by our AI provider(s) to return a result. We do not use your customer data to train third-party foundation models, and AI outputs are decision-support only — they are not used to make decisions with legal or similarly significant effects about an individual without human review.
Sharing & sub-processors
We share personal data only as needed to run the Service: with vetted sub-processors (e.g. cloud hosting, email delivery, AI providers, and identity providers you connect), strictly under contract; with your chosen integrations at your direction; and where required by law or to protect rights and safety. We do not sell personal data and do not share it for cross-context behavioural advertising. Enterprise customers can request our current sub-processor list and a DPA.
Security
We encrypt data in transit (TLS) and encrypt sensitive secrets at rest (AES-GCM); passwords are salted and hashed. The platform enforces role-based access control and database-level tenant isolation (row-level security), records changes in an audit trail, throttles authentication, and checks new passwords against known-breach datasets. No system is perfectly secure, but we work to protect your data and to notify affected customers of incidents as required by law. See our security overview.
Data retention
We retain personal data for as long as your account is active and as needed to provide the Service and meet legal obligations, then delete or anonymize it. Customer data is retained and deleted on the controlling organization's instructions. Administrators can configure an automated retention window for their audit trail; substantive business records (e.g. policies and claims) are kept in line with the controller's legal/regulatory obligations and are never automatically deleted by us.
International transfers
We may process data in countries other than your own. Where we do, we rely on appropriate safeguards (such as Standard Contractual Clauses or an adequacy decision). Self-hosted deployments keep data within your own environment and region.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing, and withdraw consent where processing is consent-based. Signed-in users can export their own data at any time from Account → Privacy & data, and workspace administrators can fulfil access and erasure requests on a member's behalf. For data your organization controls, contact that organization's administrator. To exercise rights against iqava as a controller, email [email protected]. You also have the right to complain to your local data-protection authority.
Children
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children.
Cookies
We use strictly-necessary cookies for authentication, security and session management, and do not use advertising cookies. Optional (analytics/marketing) cookies are set only with your consent, which you can give or withdraw at any time. See our Cookie Policy.
Changes
We may update this policy from time to time; material changes will be reflected by the date above and, where appropriate, communicated to you.
Contact
Questions or requests about privacy? [email protected] or contact us.
This document is provided for transparency and should be reviewed by qualified legal counsel before you rely on it for compliance in your jurisdiction.