Stere, Inc. — Privacy Policy

Privacy Policy

What we do with information about you — on our website, across our platform, and through our APIs.

Effective date: May 10, 2026 Version 2.0 Stere, Inc. SOC 2 Type II · ISO/IEC 27001:2022

Covers stere.io and every Stere subdomain, the Stere platform and its portals, the Stere APIs, and Stere’s dealings with business contacts and personnel worldwide.

At a glance

  • Stere builds infrastructure for insurance businesses. Ours is not a consumer product, and we make no money from anyone’s personal information.
  • Our obligations depend on which hat we are wearing. Running our own website and company, we decide what happens to the information and answer for it. Running an insurance program for a Client, the Client decides and we act on their written instructions.
  • Nothing that belongs to a Client or flows through a Client’s program is used to train general-purpose or third-party AI models.
  • Independent auditors examine our controls annually against SOC 2 Type II and ISO/IEC 27001:2022. Encryption applies in transit and at rest, permissions follow role, and multi-factor authentication is mandatory.
  • Whichever country you are in, you can ask what we hold, have it corrected, have it erased, or take a copy elsewhere. The address is security@stere.io.

This overview is a convenience, not a substitute for the sections that follow.

1

About this policy

Stere, Inc., together with its affiliates and subsidiaries (“Stere”, “we”, “us”), operates an API- and AI-enabled insurance Platform-as-a-Service. Carriers, managing general agents, MGA aggregators, mutuals and distribution platforms — our “Clients” — use it to design, underwrite, distribute and administer insurance products.

This policy sets out what happens to personal information in four settings:

  • our marketing site at stere.io and any Stere subdomain (the “Site”);
  • the Stere platform, the Underwriting Workbench, the agent and client portals, and our REST and GraphQL endpoints (together, the “Platform”);
  • everything that surrounds selling and supporting the product — enquiries, demonstrations, events, support tickets, invoicing; and
  • our relationships with the people who work here, past, present and prospective.

The Site and the Platform together are the “Services”.

The Stere Site Terms of Use and the Stere Master Agreement each incorporate this policy by reference, and definitions in those documents carry over here. Client agreements take precedence over this policy for the data they cover: where an executed Order, Statement of Work or Data Processing Addendum says something different about a particular Client’s data, that document governs.

Third-party sites reached from the Services fall outside this policy, as do the privacy practices our Clients apply to their own insurance programs.

2

The two roles Stere plays

Almost every question about Stere and personal data resolves to a single distinction: is Stere deciding, or is Stere executing? The answer determines who you should write to and who owes you an answer.

Setting What Stere is Who answers to you
Our website, marketing, sales, events, support and business relationships The deciding party (controller) Stere. Write to security@stere.io.
Our own workforce — employees, contractors, candidates The deciding party (controller) Stere. Write to security@stere.io.
Anything inside a Client’s insurance program — submissions, quotes, policies, endorsements, claims, and the people named in them (“Program Data”) The executing party (processor or service provider) The Client. Send your request to them; if it reaches us first we will route it and help them answer.
Aggregated, de-identified measurements drawn from Platform usage The deciding party (controller) Stere. This material no longer identifies anyone.

Program Data ordinarily reaches us from the Client and nowhere else, and we rarely have any dealings with the individuals it describes. We open it only where the Client’s written instructions call for it and only to run the Services. It stays confidential, and it is put to no purpose beyond delivering the Services except where the Client instructs and the law allows.

Should someone approach us directly about Program Data, we take only enough contact detail to work out which Client is responsible, pass the request across, and reply — after which that contact detail is removed or stripped of identifiers.

3

What we collect

3.1 Information you give us

  • When you get in touch. Your name, work email, telephone number, employer, job title, country and whatever you write in the message — whether that arrives through a demonstration request, a contact form, a support ticket or a subscription to our updates.
  • When an account is set up. Sign-in credentials, profile fields, authentication factors, the roles and permissions assigned to you, and any single sign-on identifier your organisation uses.
  • When money changes hands. Billing contact, business address, purchase order references, invoice records and the commercial terms captured in an Order or Statement of Work. Card and bank particulars go to our payment processor; Stere does not hold them.
  • When you attend something. Registration details, contact preferences, and any dietary or accessibility requirement you choose to tell us about.
  • When you give feedback. Whatever you volunteer in a survey or research conversation. Taking part is always your choice.

3.2 Information generated as you use the Services

Some information arises simply from the act of using a networked product. On the Site and the Platform this includes your IP address, cookie and device identifiers, browser and operating system details, language setting, a city- or region-level location inferred from your IP address (never precise geolocation), the pages and features you moved through, the links you followed, referring and exit addresses, and the timing, duration and status of each request. Where you call our APIs we also record the endpoint reached, response latency and any error returned.

Inside the Platform we keep audit and access records showing which authenticated account performed which action, and when. These serve security and regulatory purposes and are kept for the periods in section 10.

3.3 Program Data handled for Clients

When a Client configures an insurance program on the Platform, the information passing through it can describe brokers, agents, applicants, insureds, policyholders and claimants. Typically that means names and contact details, business and occupancy particulars, exposure and risk data, coverage and policy records, premium and payment history, claims files, and documents attached to a submission.

Depending on what the Client has built, Program Data may extend to categories the law treats as sensitive — health information in an accident or medical program, for instance, or a government identifier used for verification or sanctions screening. Stere handles such categories only on the Client’s written instructions and under the additional protections described in section 11.

3.4 Information reaching us from elsewhere

  • Business and firmographic records from professional data providers, used to check what you have told us and to make our communications more relevant.
  • Confirmation from a Client that you are an authorised contact or Platform administrator.
  • Enrichment feeds called during an underwriting workflow at a Client’s instruction — industry classification, property characteristics, sanctions and watchlist results.
  • Publicly accessible sources and professional networks, to the extent you have chosen to make the information public.

3.5 Information about our own people

We hold personal information about current, former and prospective employees and contractors, their emergency contacts, and beneficiaries under any insurance arrangement. It is used for employment purposes and no others: personnel administration and internal communication; payroll, benefits and compensation; hiring, performance and development; absence and workplace safety; IT provisioning and support; regulatory compliance and audit; the assessment, pursuit or defence of legal claims; and the handling of expenses. Any other intended use will be notified to the individual, with an opportunity to object.

4

What we do with it

  • Running the Services. Provisioning accounts and permissions, operating the Platform and its APIs, answering support requests, hosting Client configurations, and registering you for events.
  • Running the company. Confirming who we are dealing with, raising invoices and collecting payment, keeping proper records, and sending service and account notices — the latter being operational rather than promotional, and not something you can switch off while you hold an account.
  • Keeping the Services safe. Spotting, investigating and heading off unauthorised access, fraud, abuse and denial-of-service activity; maintaining audit trails; and discharging our own security commitments.
  • Making the product better. Working out which features earn their place, diagnosing faults, measuring performance and designing what comes next — relying on aggregated and de-identified material wherever it will do the job.
  • Telling you about our work. Sending information about products, services and events likely to be of interest, by email or telephone, within the limits of applicable law and subject to section 13.
  • Meeting obligations imposed on us. Tax, accounting, insurance record-keeping, sanctions screening and anti-money-laundering requirements; responses to lawful requests; and the establishment, exercise or defence of legal claims.

We take no payment or other consideration in exchange for personal information. We do not hand it to third parties so they can market their own products, and we take no part in cross-context behavioural advertising.

5

Why we are permitted to process it (Europe, United Kingdom, Switzerland)

If you are in the European Economic Area, the United Kingdom or Switzerland, each activity below rests on a stated lawful ground. Where that ground is a legitimate interest of ours, we have weighed it against your rights and set out the interest openly.

Activity Ground relied on The interest, where that is the ground
Replying to an enquiry or a demonstration request Legitimate interests; pre-contractual steps Answering people who approach us about our product
Delivering the Platform under an Order or SOW Necessary for a contract
Account security, audit trails, fraud and abuse prevention Legitimate interests; legal obligation Protecting our Clients’ data and our own systems
Product measurement and improvement Legitimate interests Learning how the product is used so it can be improved
Marketing email Consent where required; otherwise legitimate interests Making our work known to business contacts in our industry
Cookies and similar technologies beyond the strictly necessary Consent
Tax, accounting, sanctions screening, insurance records Legal obligation
Bringing or defending legal claims Legitimate interests Protecting our position at law
Program Data inside a Client’s program The Client’s ground as controller; Stere follows written instructions

You may object to anything resting on legitimate interests, and we will stop unless we can demonstrate compelling grounds that override your rights — an objection to marketing is absolute and needs no reason. Where consent is the ground, you may take it back whenever you wish; doing so leaves earlier processing lawful but ends it going forward.

6

Agentic AI and automated processing

Stere ships AI capabilities that read submissions, extract and enrich data, and score and route risk. Because they operate on insurance information, we would rather be explicit about their limits than leave them to inference.

  • Your data does not become anyone’s training set. Client Data and Program Data are not used to train, fine-tune or otherwise improve any general-purpose or third-party foundation model, and are not released to a model provider for that purpose.
  • Output stays inside the tenant that produced it. Where a Client enables an AI capability, processing serves that Client’s program alone. Results are not pooled, compared or surfaced across Clients.
  • The Client decides, not Stere. Stere holds no insurance licence and acts as no insurer, agent, broker or intermediary. Our AI applies the rules, thresholds and routing the Client has configured. Whether a given step proceeds without a person reviewing it is the Client’s configuration decision and the Client’s responsibility as controller.
  • Recourse against automated decisions. Where a decision produces legal or similarly significant effects and is reached with no human involvement, the law may entitle you to human review, to put your case, and to challenge the outcome. Because the program belongs to the Client, address that request to them; we will support them in meeting it.
  • Everything is recorded. AI-assisted steps are written to the audit trail, so a Client can reconstruct exactly how a submission was handled and on what basis.
7

Cookies, tags and browser storage

The Site uses cookies, pixels, web beacons, local storage and comparable technologies, some of them operated by third parties on our behalf. Those that are strictly necessary are set the moment you arrive, because without them the Site will not work. Everything else waits for your consent, given through the banner shown on your first visit and adjustable afterwards through the “Cookie settings” link in the footer of every page.

Purpose What it does Needs consent Usual lifespan
Strictly necessary Holds your session together, balances load, guards against fraud and abuse, and remembers the choices you make about cookies. No Session to 12 months
Measurement Counts visits, records which pages and features are reached, and surfaces errors so they can be fixed. Yes Up to 13 months
Convenience Remembers preferences such as language and region, and supports embedded elements including the scheduling tool. Yes Up to 12 months
Campaign attribution Shows which channels brought visitors to the Site and whether a campaign was worth running. Yes Up to 13 months

A current list naming every cookie in use, the party that sets it and what it does is published alongside this policy and kept up to date.

The Platform is a different matter: it runs strictly necessary cookies and nothing else. No advertising technology and no behavioural tracking operates inside the Platform or within a Client portal.

7.1 Browser-level signals

“Do Not Track” never settled into an agreed technical standard and browsers implement it inconsistently, so we do not act on it. The Global Privacy Control is different: where applicable law gives it effect, we treat a Global Privacy Control signal as a valid instruction not to sell or share personal information and not to process it for targeted advertising.

8

Who else sees your information

Personal information is never traded, and nobody buys access to it. It is disclosed in the following circumstances and no others.

  • Suppliers acting for us. Vendors that help operate the Services, under written contracts confining them to our instructions and binding them to confidentiality and security standards at least as demanding as our own.
  • Companies in our group. Stere affiliates, for internal business purposes, subject to written confidentiality and security commitments.
  • The Client whose program you are in. Where you deal with a program one of our Clients operates, the information belonging to that program is available to the Client, who is answerable for it.
  • Professional advisers. Auditors, lawyers, insurers and accountants, each bound by professional duties of confidence.
  • Authorities and legal process. Where required or appropriate to satisfy law, regulation or legal process; to respond to a lawful request from a public authority; to enforce our agreements; to recover sums owed; or to protect the rights, property or safety of Stere, our Clients or others.
  • A change of ownership. In a merger, acquisition, financing, reorganisation, insolvency or sale of assets — on terms requiring the recipient to continue honouring this policy.

8.1 Subprocessors

We maintain a published register of the suppliers that process personal information on our behalf, naming each one, its function and where it operates. Clients receive advance notice of any addition and may object as their agreement provides. The register covers these functions:

Function What it supports
Cloud infrastructure and hostingThe Platform itself, its databases and its backups
AI and model providersSubmission parsing, extraction, and risk scoring
Messaging and email deliveryTransactional messages and system notifications
Support and ticketingThe support desk and incident tracking
Product telemetry and analyticsMeasurement of Site and Platform usage
Payment processingCollection of subscription fees
Data enrichment and screeningIndustry classification, property data, sanctions and watchlist checks
Identity and access managementAuthentication and single sign-on
9

Where your information travels

Stere operates internationally, with offices in New York, São Paulo and Singapore. Personal information may accordingly be stored and processed in the United States and in other countries where we or our suppliers work.

Sending personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy finding requires a recognised safeguard, and we put one in place: the European Commission’s Standard Contractual Clauses, the United Kingdom’s International Data Transfer Addendum, or the Swiss addendum recognised by the Federal Data Protection and Information Commissioner — reinforced by technical and organisational measures including encryption in transit and at rest and tightly scoped access. Transfers out of Brazil rely on the mechanisms available under the Lei Geral de Proteção de Dados. Copies of the relevant instruments are available on request from security@stere.io.

Where a Client requires data to remain within a defined region, regional hosting may be arranged under the applicable Order.

10

How long we keep it

Nothing is kept indefinitely by default. Each category is held for as long as the purpose behind it survives, or for as long as the law requires — which in insurance can be considerably longer than commercial need alone would suggest.

Category Retained for Reason
Enquiry and demonstration request records24 months from our last contact with youLegitimate interests; length of the sales cycle
Marketing contact recordsUntil you unsubscribe, after which a suppression entry is kept indefinitelySo that your opt-out continues to be honoured
Platform account and profile recordsThe life of the Client agreement, then 24 months, unless required longer by lawPerformance of the contract
Audit and access logs12 months, extended where a Client’s regulator requires itSecurity; legal obligation
Program Data within a Client programAs the Client instructs; available for export for 60 days after termination, then destroyedMaster Agreement, Consequences upon Termination
Billing, tax and accounting records7 yearsLegal obligation
Workforce records24 months, unless local law requires longerLegal obligation
BackupsA rolling 24 months, unless required longer by law, after which deleted material is overwrittenBusiness continuity

Once the need has passed, information is deleted or stripped of identifiers. Where immediate deletion is impossible — material sitting in a backup archive, for instance — it is put beyond further use until the archive itself expires.

11

Security and resilience

11.1 Independent assurance

Our information security management system is certified to ISO/IEC 27001:2022 and re-examined annually. We also undergo SOC 2 Type II examination across the security, availability and confidentiality criteria. Current reports go to Clients and prospective Clients under non-disclosure agreement, on request to security@stere.io.

11.2 Encryption

Traffic is protected in transit with TLS. Data at rest, including database backups, is encrypted using current industry algorithms, and the keys are held separately from the material they protect.

11.3 Access governance

Permissions are granted on the narrowest basis that allows the work to be done, and reviewed on a regular cycle. Multi-factor authentication is compulsory on every privileged system and account. Administrative routes into production are secured and logged. Access ends immediately on departure or a change of role.

11.4 Testing and vulnerability management

Our systems are scanned continuously for known weaknesses and tested periodically by independent specialists. Findings are triaged by severity and tracked through to closure rather than closed on discovery.

11.5 Our people

Employees and contractors are screened before joining where the law permits, sign confidentiality undertakings, and complete security and privacy training on arrival and at least annually afterwards.

11.6 If something goes wrong

We maintain a documented incident response plan and rehearse it. On confirming a personal data breach affecting Client Data, we notify the affected Client without undue delay and supply what they reasonably need to discharge their own notification duties. Where Stere is itself the controller and a breach is likely to put your rights and freedoms at risk, we notify the competent supervisory authority within 72 hours of becoming aware, and notify affected individuals where the law requires it.

Live Platform availability and incident history are published at stere.statuspage.io. Suspected vulnerabilities and security concerns should go to security@stere.io, where they will be acknowledged and investigated.

No system is impregnable, and we do not claim otherwise. What we can say is that the controls above are audited by people who do not work for us.

12

What you can ask us to do

12.1 Wherever you are

Regardless of where you live, you may ask us to confirm whether we hold anything about you, send you a copy, put right anything inaccurate, or erase it. You may leave our mailing list at any moment. Exercising any of this costs you nothing and changes nothing about how we treat you.

12.2 Europe, the United Kingdom and Switzerland

Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection you may:

  • obtain a copy of the personal data we hold about you, together with confirmation of how it is being processed;
  • have it corrected or completed where it is wrong or missing something material;
  • have it erased in the circumstances the legislation provides for;
  • have processing paused while a dispute about accuracy or lawfulness is worked out;
  • take it elsewhere — receiving what you gave us in a common machine-readable form, and having it sent directly to another organisation where that is technically possible;
  • object to anything grounded in legitimate interests, and to direct marketing at any time and without qualification;
  • withdraw consent wherever consent was the ground, without unpicking what was already lawful;
  • insist on human involvement where a decision producing legal or similarly significant effects was reached by automated means alone — see section 6; and
  • complain to your national supervisory authority. We would welcome the chance to resolve the matter first, but that is your choice, not a precondition.

12.3 The United States

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy statutes may ask what we have collected, obtain a copy, correct it, delete it, and take it elsewhere — and may opt out of sale, sharing, targeted advertising and certain profiling. As it happens there is nothing to opt out of: Stere neither sells nor shares personal information as those terms are defined, runs no targeted advertising, and performs no profiling in support of decisions producing legal or similarly significant effects about a consumer.

Set out below are the categories collected over the preceding twelve months and what each is for.

What we hold Statutory category Why Who receives it
Business contact and enquiry recordsIdentifiers; commercial informationSales, support, marketingSuppliers; affiliates
Account and sign-in recordsIdentifiers; online identifiersOperations; securitySuppliers
Commercial and billing recordsCommercial information; financial informationOperations; legal obligationPayment processor; advisers
Device and usage recordsInternet or network activity; online identifiersOperations; measurement; securitySuppliers
Correspondence with usIdentifiers; commercial informationSupport; operationsSuppliers
Workforce and candidate recordsIdentifiers; professional or employment informationPersonnel administrationSuppliers; advisers
Program Data in a Client programVaries by program; may include sensitive personal informationHandled as processor on the Client’s instructionsThe Client; subprocessors

Sensitive personal information is collected only where a Client’s program requires it, and is used for nothing beyond delivering the Services. Requests go to security@stere.io, and an authorised agent may make one on your behalf. We verify identity before acting. A refusal can be appealed by replying to our decision, and we will answer the appeal within the period your state’s law allows.

Residents of Nevada may separately direct us not to sell personal information within the meaning of Nevada Revised Statutes Chapter 603A. We do not sell it in any event, but the instruction will be recorded on request.

12.4 Brazil

The Lei Geral de Proteção de Dados (Law No. 13.709/2018) entitles you to confirmation that processing is taking place, access to the data, correction, anonymisation or deletion of anything unnecessary or excessive, portability, disclosure of the parties with whom we have shared it, an explanation of what refusing consent would mean, withdrawal of consent, and review of a decision taken purely by automated means. Write to security@stere.io. You may also take the matter to the Autoridade Nacional de Proteção de Dados.

12.5 Singapore

The Personal Data Protection Act entitles you to access and correct the personal data we hold about you and to withdraw consent to its collection, use or disclosure. Requests should be sent to security@stere.io.

12.6 Making a request

Send your request to security@stere.io with your full name, the email address tied to your account or enquiry, and a description of what you want. We will confirm your identity before acting, and reply within the statutory period — generally one month in Europe and the United Kingdom, and 45 days in the United States — extending it only where the law permits and telling you why.

If your data sits inside a Client’s insurance program, the Client is the controller and the request belongs with them. Send it to us anyway if that is easier and we will pass it on.

Occasionally we cannot give full access: where the material is legally privileged, where disclosure would compromise someone else’s rights, or where it is commercially proprietary. In those cases we will say so, explain the reason, and give you somewhere to take it further.

13

Staying in touch

Every marketing message we send carries an unsubscribe link, and it works. You can also write to security@stere.io. Once you have opted out we keep a suppression record — not to contact you, but to make certain nothing does.

Service and account messages are a separate matter: notices about your account, changes to our terms or to this policy, and operational alerts continue for as long as you hold an account, because you need them. We maintain do-not-call and do-not-mail lists where the law requires.

14

Age limits

The Services are built for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, a parent or guardian should write to security@stere.io and it will be removed.

15

Sites and services we do not control

The Services link out to places we have no hand in. We are not answerable for their content or their privacy practices, and a link implies no endorsement. It is worth reading the privacy policy of anywhere you land.

Our marketing pages may embed features from professional networks such as LinkedIn. If you already use those networks, their cookies may be set on your device subject to the choices you make in our consent banner, and your dealings with those features are governed by the network’s own policy.

16

Revisions to this policy

Law, technology and our own business all move, and this policy moves with them. The effective date on the first page always shows when it last changed, and earlier versions are kept and available on request.

Material changes — a genuinely different use of personal information, for example — are notified to Clients at least 30 days before they take effect. Continuing to use the Services after the effective date signifies acceptance. If a revision does not sit well with you, the remedy is to stop using the Services and to tell us why.

17

Reaching us

What you need Where to write
Privacy and individual rights requests, copies of transfer safeguards, security questions, vulnerability reports, SOC 2 and ISO documentationsecurity@stere.io
General enquirieshello@stere.io
Platform supportsupport@stere.io
Registered entityStere, Inc., 8 The Green, Ste B, Dover, DE 19901, United States

We would rather hear a complaint directly than read about it elsewhere, and we treat privacy questions as questions about whether the product is trustworthy — because that is what they are.

Privacy questions

For data requests, security questions, or a copy of our transfer safeguards, contact our team.