Privacy Policy
ClearCOI ("ClearCOI," "we," "our," or "us") operates getclearcoi.com and provides manual vendor insurance certificate compliance reviews. This policy explains what information we collect, why we collect it, how long we keep it, and what you can ask us to do with it.
This policy applies to visitors to our website and to businesses that request or receive a compliance check. Our clients are businesses in the United States. ClearCOI itself is operated from Lithuania, so both US state privacy laws and the EU General Data Protection Regulation are relevant — sections 7 and 8 address each in turn. We do not offer our services to individuals for personal, family, or household purposes.
1. Information we collect
We collect only what you send us. We do not buy contact data, and we do not build profiles from third-party sources.
- Contact information. Your name, work email address, and company name, submitted through the form on our site.
- Materials you send for review. Any message, file-sharing link, or Certificate of Insurance (COI) document you provide so we can perform the compliance check.
- Correspondence. Emails you send us and our replies.
We do not use advertising cookies, analytics pixels, session recording, fingerprinting, or any other tracking technology on this website. There is no tracking to opt out of, because there is none running.
Our web host may generate standard server logs, including IP addresses, as a normal function of serving the site. We do not use those logs for marketing, analytics, or profiling.
2. Certificates and third-party information
This section matters more than most of this policy, so it is stated plainly.
COI documents typically contain information about people and businesses other than you — vendors, contractors, insurance agents and brokers, named insureds, policy numbers, and coverage details. When you send us those documents, we handle that information solely on your behalf and solely to produce your report.
- We act as a service provider with respect to information contained in the materials you send. We process it only on your instructions and only for the compliance review you requested.
- We do not use, retain, or disclose that information for any purpose other than performing the review — including no marketing to your vendors, no contacting them, and no combining it with information from any other client.
- By sending us COI documents, you confirm that you have the right to share them with a service provider for this purpose.
- If one of your vendors contacts us directly about information contained in a certificate you supplied, we will refer them to you rather than acting unilaterally.
3. How we use information
We use what you send us for these purposes only:
- To perform the compliance review you requested.
- To prepare and deliver your report.
- To answer your questions about the report or the service.
- To discuss ongoing work, if you ask us to.
- To meet legal, tax, or recordkeeping obligations.
We do not use your information for automated decision-making or profiling.
4. How we share information
We do not sell your information. We do not share it for cross-context behavioral advertising. We have not done either in the preceding twelve months, and we have no plans to.
Information is disclosed only in these limited circumstances:
- Form delivery. Submissions from our website are transmitted through FormSubmit, which routes them to our email inbox. Your submission passes through and is briefly handled by that service. See FormSubmit's privacy policy.
- Email and hosting. Our email provider and web host necessarily handle messages and files in the course of delivering them to us.
- Legal requirements. If we are required to disclose information by law, subpoena, or valid request from a public authority.
- Protection of rights. Where disclosure is necessary to establish, exercise, or defend a legal claim.
5. How long we keep information
We keep information only as long as we need it:
- COI documents and materials you send for review: deleted within 30 days of delivering your report. The short window exists so we can answer follow-up questions about the report; after that, the files are removed from our working storage.
- Contact information (name, work email, company): kept for up to 12 months from our last substantive communication with you, then deleted.
- The report itself and basic records of the engagement: retained where necessary to meet tax, accounting, or legal obligations, and deleted when that obligation ends.
You can ask us to delete your information sooner. See sections 7 and 8.
6. Security
We take reasonable measures to protect information in our possession, including limiting access to it and deleting documents on the schedule above. We are a small operation and we describe our practices honestly rather than claiming more than we do.
Reports and correspondence are delivered by ordinary email, which is not encrypted end to end. If you require a more secure delivery method for your documents or report, tell us before you send anything and we will arrange one.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your California privacy rights
The California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies to information about California residents — including business contact information such as work email and company name. If you are a California resident, you have the right to:
- Know what personal information we have collected about you, the categories of sources, the purposes, and the categories of third parties to whom it was disclosed.
- Access a copy of the specific pieces of personal information we hold about you.
- Correct inaccurate personal information.
- Delete personal information we have collected from you, subject to legal exceptions.
- Opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of — but the right exists and we state it.
- Limit use of sensitive personal information. We do not collect sensitive personal information as that term is defined by the CCPA.
- Non-discrimination. We will not deny you service, charge you a different price, or provide a lesser quality of service because you exercised any of these rights.
Categories of personal information we collect. Under the CCPA's categories, we collect identifiers (name, email address), commercial information (records of services requested), and professional or employment-related information (company name, job context). We collect these directly from you.
How to make a request. Email saulius@getclearcoi.com with the subject line "Privacy Request." So that we do not disclose information to the wrong person, we will verify your request by replying to the email address we hold on file and may ask you to confirm details of your prior contact with us. We will acknowledge your request within 10 business days and respond substantively within 45 days, extendable by a further 45 days where reasonably necessary, in which case we will tell you.
Authorized agents. You may use an authorized agent to submit a request. We will ask for written proof of authorization and may ask you to verify your identity directly.
Residents of other US states with comparable privacy laws may have similar rights. We apply the process above to all such requests rather than distinguishing by state.
8. European data protection (GDPR)
ClearCOI is operated from Lithuania. Because we are established in the European Union, the General Data Protection Regulation (GDPR) applies to our processing of personal data, including personal data relating to individuals outside the EU. This section sets out how that works.
Controller. ClearCOI is the controller for personal data you submit to us directly — your name, work email address, company name, and any correspondence.
Processor. For personal data contained in the certificates and materials you send us for review — vendor contacts, insurance agents, named insureds — you are the controller and we act as processor, processing only on your instructions and only to produce your report, as described in section 2.
Legal bases for processing.
- Performing the compliance check and delivering your report: necessary to take steps at your request prior to entering a contract, or to perform a contract with you (Article 6(1)(b)).
- Responding to your enquiries and follow-up correspondence: our legitimate interest in communicating with business contacts who have approached us (Article 6(1)(f)).
- Meeting tax, accounting, and recordkeeping obligations: compliance with a legal obligation (Article 6(1)(c)).
Your rights. Where GDPR applies to our processing, you have the right to request access to your personal data; correction of inaccurate data; erasure; restriction of processing; portability of data you provided to us; and to object to processing carried out on the basis of legitimate interests. Where processing is based on consent, you may withdraw that consent at any time without affecting processing carried out before withdrawal.
How to exercise them. Email saulius@getclearcoi.com with the subject line "Data Protection Request." We will respond within one month of receiving your request, extendable by two further months where the request is complex, in which case we will tell you within the first month and explain why.
Right to complain. If you believe we have handled your personal data unlawfully, you may lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos g. 17, 10312 Vilnius, Lithuania — vdai.lrv.lt. You may also complain to the supervisory authority of your habitual residence.
Transfers outside the EU. Form submissions from this website are transmitted through FormSubmit, a service operated outside the European Economic Area, before reaching our inbox. Our email is hosted within the EU. We keep the personal data passing through the form to the minimum needed to contact you — name, work email, company name, and anything you choose to write in the message field. Do not send certificate documents through the web form; send them by email once we have replied.
Automated decision-making. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
9. Children
Our service is offered to businesses. We do not knowingly collect personal information from anyone under 16. If you believe a minor has provided us information, contact us and we will delete it.
10. Changes to this policy
If we change this policy, we will update the "last updated" date above. Where a change is material, we will note what changed at the top of this page for at least 30 days. Continued use of our service after a change means you accept the updated policy.
11. Contact
Questions about this policy, or requests under it, go to saulius@getclearcoi.com. A person reads that inbox — you will not get a ticket number.
ClearCOI is operated from Lithuania and provides services to business clients in the United States. Information you send us is therefore processed outside the United States. We apply the practices described in this policy regardless of where information is processed.