Privacy Policy
· Last updated 2026-09-20Privacy Policy
This Privacy Policy explains how Webbmi AB (trading as Claimance) handles your personal data when you use our website and services. It is written for users in AU.
1. Who we are
The controller of your personal data is Webbmi AB, a company incorporated in Sweden (Webbmi AB, Tors Gata 8, 242 35 Hörby, Sweden). Contact: info@claimance.ai.
2. Which law applies to you
Because you are accessing Claimance from AU, the following framework applies:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles (APPs)
- Notifiable Data Breaches scheme
We comply with the 13 Australian Privacy Principles. You can request access to and correction of your personal information at any time at no charge.
Personal information may be stored on servers located in the European Union; we take reasonable steps to ensure overseas recipients handle data consistent with the APPs.
Eligible data breaches are notified to the OAIC and affected individuals as required by the Notifiable Data Breaches scheme.
3. What personal data we process and why
| Purpose | Legal basis | Data categories | Retention |
|---|---|---|---|
| Operating your account and providing the Claimance service | Performance of a contract (GDPR Art. 6(1)(b)) | Account details, Profile, Authentication data | For the lifetime of your account, then 30 days for backups. |
| Drafting, sending and tracking insurance correspondence on your behalf | Performance of a contract (GDPR Art. 6(1)(b)) | Claim details, Insurer messages, Identity & signature (encrypted) | While the claim is active and for 7 years after resolution to support audits and disputes. |
| AI-assisted classification, drafting, and summarization | Legitimate interests (GDPR Art. 6(1)(f)) — providing the AI features you signed up for | Claim content, Messages | Prompts and outputs are processed by our AI sub-processor (Lovable AI Gateway) and not retained for model training. Logs auto-expire after 30 days. |
| Security, fraud prevention and abuse detection | Legitimate interests (GDPR Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) | IP address, Login timestamps, Audit logs | 12 months. |
| Service emails (claim updates, security alerts) | Performance of a contract (GDPR Art. 6(1)(b)) | Email address | Until you delete your account or unsubscribe from non-essential notices. |
| Product analytics & service improvement (aggregated) | Consent (GDPR Art. 6(1)(a)) — withdrawable via Cookie settings | Anonymous usage events | 13 months. |
4. AI processing
We use AI to classify insurer messages, draft replies, score claim completeness, and summarize correspondence. AI suggestions are always reviewable by you before anything is sent on your behalf — we do not make legally significant decisions about you by automated means alone. Prompts are processed by our AI sub-processor (Lovable AI Gateway, routing to OpenAI and Google) under contractual terms that prohibit using your data to train their models.
5. Identity vault & encryption
Sensitive identity fields (legal name, address, phone, national ID, signature) are stored encrypted at rest using authenticated encryption. We log every access to your identity vault and surface it to you in the audit trail. Insurer attachments are stored in a private bucket scoped to your user ID.
6. Who we share data with
We share personal data only with the following categories of recipients:
- Sub-processors listed below — strictly bound by data processing agreements.
- Your insurer and its agents — only when you instruct us to send correspondence on your behalf.
- Regulators, ombudsmen and courts — when you escalate a dispute, and only with the documents you choose to package.
- Authorities — where we are legally required to disclose information.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase (managed Postgres, Auth, Storage) | Application database & file storage | EU (Frankfurt) |
| Cloudflare | CDN, DDoS protection, edge runtime | Global edge; EU origin |
| Lovable AI Gateway | Routing prompts to AI providers (OpenAI, Google) — no training on your data | EU/US |
| Postmark (ActiveCampaign) | Transactional email delivery & inbound parsing | US (DPF-certified) |
| Stripe / Paddle | Payment processing (only if you subscribe) | EU/US |
7. International transfers
Our primary infrastructure is hosted in the European Union. Where data is transferred outside the EU/EEA (for example to our US-based email or AI providers), we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
8. Your rights
Subject to the applicable law in your country, you have the following rights:
- Access. Request access to the personal information we hold about you (APP 12).
- Correction. Have your personal information corrected if it is inaccurate or out of date (APP 13).
- Anonymity / pseudonymity. Where lawful and practicable, transact with us without identifying yourself (APP 2).
- Complaint to the OAIC. Complain to the OAIC if you believe we've breached the APPs.
- Notifiable data breaches. Be notified of an eligible data breach that is likely to result in serious harm.
You can exercise most rights directly from Settings → Privacy & data inside the app (download my data, delete my account). For anything else, email info@claimance.ai. We respond within 30 days (extendable to 90 for complex requests).
9. Complaints
If you believe we have mishandled your personal data, please contact us first so we can put it right. You also have the right to lodge a complaint with your supervisory authority: Office of the Australian Information Commissioner (OAIC).
10. Children
Claimance is not intended for users under 16. We do not knowingly collect personal data from children.
11. Changes
We'll notify you in-app and by email at least 30 days before any material change to this Policy. The "Last updated" date at the top always reflects the current version.
12. Contact
Webbmi AB
Webbmi AB, Tors Gata 8, 242 35 Hörby, Sweden
Privacy: info@claimance.ai
Legal: info@claimance.ai