Privacy Policy

Metis Solutions LLC — Commercial Underwriting Intelligence
Version 1.0  •  Effective Date: June 8, 2026  •  Last Updated: June 8, 2026

This Privacy Policy explains how Metis Solutions LLC, together with its permitted successors and assigns ("Metis," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes Personal Data in connection with our websites, hosted software platform, applications, portals, APIs, reports, communications, events, and related products and services that link to this Privacy Policy (collectively, the "Services").

Metis provides commercial underwriting intelligence, business-verification, public-record research, and decision-support technology for workers' compensation insurance professionals and other authorized business users. Metis is not an insurer and does not make underwriting, pricing, coverage, eligibility, or claims decisions.

Please read this Privacy Policy together with our Terms of Service, applicable Order Form, Data Processing Agreement, and any other privacy or security notice presented when Personal Data is collected.

1. Scope of This Privacy Policy

1.1 Activities covered

This Privacy Policy applies when Metis processes Personal Data in connection with:

1.2 Customer-controlled data

Enterprise Customers may submit information to the Services or direct Metis to process information on their behalf. When Metis acts as a processor, service provider, or contractor for a Customer, the Customer generally determines why and how that information is processed. The applicable Customer's privacy notice and Metis's Data Processing Agreement govern that processing. Individuals should ordinarily direct requests concerning Customer-controlled data to the relevant Customer.

Metis may redirect a request to the applicable Customer or assist the Customer in responding, as required by contract and applicable law.

1.3 Activities not covered

This Privacy Policy does not apply to:

1.4 Organization-managed accounts

If an account is provided or administered by an employer or other organization, that organization may control the account, access or manage account information and Customer Data, configure permissions, and request account reassignment or deletion. Authorized Users should direct questions about organization-controlled data to the relevant administrator.

2. Our Privacy Roles

2.1 Metis as a business or controller

Metis generally acts as a business, controller, or equivalent responsible entity for Personal Data used to operate our website and business; manage accounts; provide sales, billing, support, security, and communications; maintain our business relationships; and comply with law.

Depending on the applicable law, source, license, and product configuration, Metis may also act as a business or controller for public-source or licensed information that Metis selects, organizes, indexes, matches, summarizes, or otherwise processes for inclusion in its commercial business-intelligence Services.

2.2 Metis as a processor or service provider

Metis generally acts as a processor, service provider, or contractor when processing Customer Data solely on documented instructions from an Enterprise Customer. The applicable Data Processing Agreement describes the parties' respective responsibilities.

2.3 Independent third parties

Government agencies, public-record custodians, websites, social-media platforms, commercial data providers, payment processors, and integration providers may independently determine their own processing purposes. Metis does not control their privacy practices.

3. Definitions

3.1 Customer Data

"Customer Data" means information submitted to, stored in, transmitted through, or generated from a Customer's authorized use of the Services, excluding Usage Data and information Metis processes as an independent business or controller.

3.2 Personal Data

"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an identified or identifiable natural person or household, and includes equivalent terms such as personal information under applicable law.

3.3 Process

"Process" or "processing" means any operation performed on Personal Data, including collecting, accessing, organizing, using, analyzing, storing, disclosing, transmitting, correcting, restricting, deleting, or destroying it.

3.4 Search Subject

"Search Subject" means a business, sole proprietor, owner, officer, registered agent, or other person or entity that is the subject of an authorized commercial research query or appears in a source result.

3.5 Sensitive Personal Data

"Sensitive Personal Data" includes information treated as sensitive under applicable law, such as government identifiers, account credentials, precise geolocation, biometric or genetic information, racial or ethnic origin, religious beliefs, union membership, citizenship or immigration status, health information, sexual orientation, and information concerning a known child.

4. Personal Data We Collect

4.1 Account, identity, and contact information

We may collect:

4.2 Subscription, transaction, and billing information

We may collect:

Metis does not ordinarily receive or store full payment-card numbers. Payment processors independently process payment information under their own terms and privacy notices.

4.3 Communications and support information

We may collect:

4.4 Device, network, and Usage Data

We may automatically collect:

4.5 Search inputs and Customer-submitted research information

Depending on Customer configuration, a Customer may submit:

Customers are responsible for limiting submitted information to what is lawful, relevant, and reasonably necessary for the authorized commercial purpose.

4.6 Public-source and licensed business-intelligence information

The Services may locate, access, receive, organize, or display information from government databases, public records, publicly accessible websites, commercial data providers, and Customer-authorized sources, including:

4.7 Information associated with natural persons

Business records may identify natural persons associated with a business, including owners, officers, members, managers, registered agents, professional licensees, or sole proprietors. Metis's standard Services are designed for entity-level commercial research. When individual-associated information is included, Metis seeks to limit it to information relevant to the person's business role, authority, ownership, or association.

Metis does not intend its standard Services to provide personal background reports or to evaluate a person's personal character, reputation, creditworthiness, lifestyle, health, or eligibility for personal insurance, employment, housing, credit, or government benefits.

4.8 Information from integrations and enterprise systems

When a Customer enables an integration, we may receive identifiers, configuration information, records, and authentication tokens necessary to operate the integration. The Customer determines which integrations to enable and is responsible for its relationship with the third-party provider.

4.9 Security, fraud, and compliance information

We may process:

4.10 Sensitive Personal Data

The standard Services are not intended for unnecessary Sensitive Personal Data. Customers must not submit Sensitive Personal Data unless the applicable Service, contract, and security controls expressly permit it.

Metis does not use or disclose Sensitive Personal Data to infer characteristics about an individual or for cross-context behavioral advertising. Metis does not sell Sensitive Personal Data.

5. Sources of Personal Data

We may obtain Personal Data:

6. How We Use Personal Data

Metis may process Personal Data to:

7. Commercial Underwriting Research and Source Data

7.1 Advisory and decision-support function

Metis uses Personal Data and business information to automate research and organize source-derived results. Metis does not approve or reject insurance applicants and does not determine pricing, classification, coverage, eligibility, or policy terms.

7.2 Verification and ambiguity

Public and licensed sources may be incomplete, outdated, incorrectly indexed, or associated with a different business or person. Metis may use names, addresses, registration numbers, telephone numbers, websites, ownership information, and other identifiers to evaluate whether a source result is associated with a Search Subject.

No matching process is infallible. Customers must review source attribution and available identifiers before using a result for a material decision. Metis does not treat a name-only match concerning a natural person as independently verified information.

7.3 Corrections and disputes

A Search Subject or other individual may report information believed to be inaccurate, incomplete, outdated, misidentified, or unlawfully processed by contacting Metis as described in Section 26. Metis may investigate, add a dispute notation, correct Metis-generated information, suppress a result, request documentation, or contact the underlying data source.

Metis may be unable to change information controlled by a government agency, website, or independent data provider. We may instead correct our association or presentation of the information and direct the requester to the source.

8. Automation, Machine Learning, and AI-Assisted Features

8.1 How automated tools may be used

Metis may use rules-based systems, statistical methods, machine learning, or artificial-intelligence-assisted tools to identify sources, match entities, remove duplicates, extract facts, classify results, generate summaries, detect anomalies, improve search quality, and support security.

8.2 Human review and customer responsibility

Automated results may be inaccurate or incomplete. Metis's outputs are research aids and are not final insurance decisions. Customers are responsible for qualified human review, independent verification, and compliance with applicable notice, explanation, dispute, and appeal requirements.

8.3 Model training and improvement

Metis may use Usage Data, feedback, de-identified data, and aggregated data to improve the Services. Metis will not use Customer Data to train a general-purpose model made available to other customers or third parties unless the applicable Customer has expressly agreed in writing.

Where Metis uses a third-party model or AI provider to process Customer Data, Metis will do so under applicable contractual, security, and data-processing restrictions.

9. How We Disclose Personal Data

Metis may disclose Personal Data to the following recipients:

9.1 Customer organizations and account administrators

An enterprise account administrator may access Authorized User information, account activity, permissions, reports, and Customer Data within the organization. Customers are responsible for their administrators and internal access decisions.

9.2 Service providers and subprocessors

We may engage cloud-hosting, security, identity, payment, billing, communications, customer-support, analytics, professional-services, document-processing, and AI technology providers. They may process Personal Data only for authorized purposes and subject to contractual obligations appropriate to their role.

9.3 Public-record and commercial data providers

We may transmit search identifiers to a government source, public website, licensed provider, or data integration to obtain an authorized result. The recipient may independently process the query under its own rules and privacy notice.

9.4 Customer-authorized integrations

We disclose information to an integration provider when a Customer enables or directs the integration.

9.5 Professional advisors

We may disclose information to attorneys, accountants, auditors, insurers, financial institutions, investors, and other professional advisors subject to appropriate confidentiality obligations.

9.6 Legal, safety, and compliance recipients

We may disclose information where reasonably necessary to comply with law or legal process; respond to regulators or governmental authorities; protect rights, safety, and security; prevent fraud or abuse; or enforce our agreements.

9.7 Corporate transactions

We may disclose or transfer information in connection with an actual or proposed financing, merger, conversion, reorganization, acquisition, sale of assets, bankruptcy, or similar transaction, subject to appropriate safeguards.

9.8 With direction or consent

We may disclose information for another purpose disclosed at collection or with the individual's direction or consent.

10. Sale, Sharing, Targeted Advertising, and Profiling

10.1 Account and Customer Data

Metis does not sell Customer Data, account credentials, payment information, or confidential Customer content for money. Metis does not disclose Customer Data to third parties for their own cross-context behavioral advertising.

10.2 Business-intelligence results

Customers pay for access to Metis's commercial research technology and authorized source results. The standard Services are designed to provide information about business entities. A source result may nevertheless contain limited information about a natural person in a business capacity, such as an owner, officer, registered agent, professional licensee, or sole proprietor.

Some privacy laws define "sale" broadly to include certain transfers of Personal Data for valuable consideration, even without a payment specifically allocated to the data. Where a Metis disclosure legally qualifies as a sale, sharing, targeted advertising, or profiling subject to an opt-out right, Metis will provide and honor the applicable right.

10.3 Advertising technology

As of the Effective Date, Metis does not use Personal Data for cross-context behavioral advertising. If our practices change, we will update this Privacy Policy, provide legally required notices and controls, and recognize applicable universal opt-out signals.

10.4 Sensitive Personal Data

Metis does not sell Sensitive Personal Data and does not use it for targeted advertising.

11. Cookies and Similar Technologies

11.1 Types of technologies

Metis and authorized providers may use cookies, local storage, pixels, tags, software-development kits, and similar technologies for authentication, security, preferences, functionality, performance, analytics, and legally permitted marketing.

11.2 Cookie categories

11.3 Controls

Users may manage cookies through browser settings and any cookie-preference tool Metis provides. Blocking necessary cookies may prevent parts of the Services from functioning.

11.4 Global Privacy Control and universal opt-out signals

Where required by law, Metis recognizes valid browser-based universal opt-out mechanisms, including Global Privacy Control, as a request to opt out of applicable sale, sharing, or targeted advertising for the browser or device from which the signal is sent.

12. Marketing and Communication Preferences

Metis may send transactional, security, billing, support, and service communications that are necessary to administer an account. These communications are not promotional and generally cannot be disabled while an account remains active.

Recipients may opt out of marketing emails by using the unsubscribe link or contacting us. We may retain limited suppression-list information to honor the opt-out.

13. Data Retention

Metis retains Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, maintain business and security records, comply with source licenses, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, and regulatory obligations.

Retention periods depend on factors such as:

When retention is no longer reasonably necessary, Metis will delete, anonymize, aggregate, or isolate the information, subject to backup cycles and lawful exceptions.

14. Data Security

Metis uses reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, acquisition, alteration, disclosure, destruction, or loss. Safeguards may include access controls, authentication, encryption, logging, monitoring, vulnerability management, incident-response procedures, vendor review, employee training, and secure development practices.

No system is completely secure. Individuals should use unique credentials, protect authentication factors, and promptly notify Metis through the contact or support method available at https://metisinsured.com of suspected account compromise or misuse.

15. International Data Transfers

Metis is based in the United States. Personal Data may be processed in the United States and other countries where Metis or its service providers operate. Those countries may have data-protection laws different from those in the individual's location.

Where applicable law requires a transfer mechanism, Metis may use standard contractual clauses, contractual safeguards, adequacy mechanisms, or another lawful transfer method described in an applicable Data Processing Agreement.

16. U.S. State Privacy Rights

16.1 Rights that may be available

Depending on residence, the applicable law, and relevant exemptions, an individual may have the right to:

16.2 Submitting a request

A privacy request may be submitted through the contact method available at https://metisinsured.com or by mail to Metis Solutions LLC, Attn: Privacy, 1106 S Redwood Rd, Unit 13, Salt Lake City, UT 84104, United States.

16.3 Verification

Metis will take reasonable steps to verify a request based on the nature of the request, the sensitivity of the information, and the risk of unauthorized disclosure or deletion. We may request information reasonably necessary to match the requester to relevant records. We will not require creation of an account solely to submit a request.

Where we cannot verify identity or authority, we may deny or limit the request and explain the reason, subject to applicable law.

16.4 Authorized agents

An authorized agent may submit a request where permitted. Metis may require proof of the agent's authority and may ask the individual to verify identity or confirm the authorization directly.

16.5 Appeals

Where applicable, an individual may appeal a denied request through the contact method available at https://metisinsured.com with the subject line "Privacy Request Appeal" within 45 days after the denial. Metis will respond within the period required by applicable law.

16.6 Requests concerning Customer Data

When Metis processes information solely on behalf of a Customer, we may direct the requester to that Customer. Metis will support the Customer as required by the Data Processing Agreement and applicable law.

16.7 Search Subject requests

A person identified in a commercial source result may request review of a potential misidentification, inaccurate association, outdated Metis-generated summary, or other alleged error. Metis may request documentation sufficient to distinguish the correct business or person and protect against fraudulent alteration requests.

17. California Privacy Notice

17.1 Applicability

This Section supplements the Privacy Policy for California residents where the California Consumer Privacy Act, as amended, applies to Metis's processing and no exemption controls.

17.2 Categories of Personal Information

During the preceding twelve months, Metis may have collected the following categories of Personal Information, depending on whether the applicable feature was operational and used:

Metis does not intentionally collect protected-classification information for underwriting decisions and does not use Sensitive Personal Information to infer characteristics.

17.3 Sources, purposes, and recipients

The sources of these categories are described in Section 5; the business and commercial purposes are described in Sections 6 through 8; and the categories of recipients are described in Section 9.

17.4 Sale and sharing

Metis does not sell account credentials, payment information, confidential Customer Data, or Sensitive Personal Information. Metis does not share Personal Information for cross-context behavioral advertising as of the Effective Date.

Metis may provide authorized commercial source results to Customers as part of a paid Service. If a particular transfer of information about a natural person constitutes a sale under California law, Metis will provide the legally required opt-out mechanism and honor applicable requests and browser signals.

17.5 California rights

Subject to verification, exemptions, and legal limitations, California residents may request access to categories and specific pieces of Personal Information, correction, deletion, information about sales or disclosures, opt-out of sale or sharing, and limitation of certain uses of Sensitive Personal Information. Metis will not unlawfully discriminate against an individual for exercising these rights.

17.6 Notice at Collection

Appendix A provides a concise Notice at Collection. Metis may also present a context-specific notice at or before collection.

17.7 Data-broker obligations

Where Metis is legally classified as a data broker, Metis will comply with applicable registration, disclosure, deletion, and centralized-request obligations.

18. Colorado and Other U.S. State Supplement

Where applicable state law provides rights to access, correct, delete, obtain portable data, opt out of sale or targeted advertising, opt out of specified profiling, or appeal a decision, Metis will honor those rights subject to verification and applicable exemptions.

Where required, Metis recognizes valid universal opt-out mechanisms. If a request is denied, the response will include instructions for appeal and, where required, information about contacting the applicable state attorney general.

19. European Economic Area, United Kingdom, and Switzerland

19.1 Applicability and legal bases

Where European data-protection law applies and Metis acts as controller, Metis processes Personal Data based on one or more of the following legal bases:

19.2 European rights

Subject to applicable conditions and exceptions, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a competent supervisory authority.

19.3 Automated decision-making

Metis does not use its standard Services to make solely automated decisions that produce legal or similarly significant effects on Search Subjects. Customers are prohibited from treating Metis outputs as a substitute for required human review.

19.4 Contact

Requests may be submitted using Section 16. Metis does not currently designate a European representative or Data Protection Officer because those appointments are not presently required for the Services as offered. Metis will update this section if that changes.

20. Children's Privacy

The Services are designed for business professionals and are not directed to children under thirteen or the higher minimum age required by applicable law. Metis does not knowingly collect Personal Data directly from children through account registration.

Customers may not use the standard Services to research children or submit information about children unless expressly authorized under a separate written agreement and permitted by law. Contact Metis through the method available at https://metisinsured.com if you believe a child has provided Personal Data directly to Metis.

21. Do Not Track

Some browsers offer a Do Not Track setting. Because no uniform industry standard governs all Do Not Track signals, Metis does not respond to legacy Do Not Track signals unless required by law. Metis does recognize legally valid universal opt-out mechanisms as described in Section 11.4.

22. Third-Party Links and Sources

The Services may link to government websites, social-media platforms, public databases, commercial sources, or other third-party services. Metis is not responsible for their content, availability, accuracy, security, or privacy practices. Individuals should review the third party's applicable notices.

23. De-Identified and Aggregated Information

Metis may create and use information that has been aggregated or de-identified so that it cannot reasonably be linked to an identified individual. Metis may use such information for analytics, benchmarking, security, research, product development, and other lawful purposes.

Where required by law, Metis will maintain de-identified information in de-identified form and will not attempt to re-identify it except to test whether de-identification processes are effective or as otherwise legally permitted.

24. Changes to This Privacy Policy

Metis may update this Privacy Policy to reflect changes in the Services, data practices, legal requirements, or business operations. The revised policy will identify the updated date. Where required, Metis will provide additional notice or obtain consent before a material change applies. Metis will not materially reduce the protections applicable to Customer Personal Data during a current paid Subscription Period except as required by law, permitted by the governing agreement, or accepted by the Customer.

25. Entity Conversion, Reorganization, and Successors

Metis Solutions LLC may convert, reorganize, or transfer its business to a corporation, Affiliate, or successor entity. Personal Data may be transferred as part of that transaction subject to this Privacy Policy, applicable law, and any additional notice or choice legally required.

26. Contact Metis

Questions, complaints, privacy requests, correction requests, and appeals may be submitted through the contact method available at https://metisinsured.com or mailed to:

Metis Solutions LLC
Attn: Privacy
1106 S Redwood Rd, Unit 13, Salt Lake City, UT 84104, United States
Website: https://metisinsured.com

Appendix A — Notice at Collection

This Notice at Collection summarizes the categories of Personal Data Metis may collect, the purposes for which it is used, applicable retention considerations, and available privacy rights. Context-specific notices may also be presented at signup, through cookies, in forms, in integrations, or within search workflows.

Categories collected

Metis may collect the following categories of Personal Data:

Purposes

Metis uses these categories to:

Retention

Metis retains each category only for as long as reasonably necessary for the purposes described above, subject to contractual, security, source-license, legal, tax, accounting, audit, dispute, and backup requirements.

Sale, sharing, and sensitive data

Metis does not sell account credentials, payment information, confidential Customer Data, or Sensitive Personal Data, and does not share Personal Data for cross-context behavioral advertising as of the Effective Date. If an authorized commercial-source transfer legally qualifies as a sale, Metis will provide and honor the applicable opt-out right.

Rights and full notice

The complete Privacy Policy explains available rights and how to submit a request through the contact method available at https://metisinsured.com.

Appendix B — Search Subject Correction and Privacy Request Process

B.1 Purpose

This process is intended for an owner, officer, registered agent, sole proprietor, professional licensee, or other natural person who believes that Metis has associated, summarized, displayed, or disclosed inaccurate or inappropriate information concerning that person.

B.2 Information to provide

A requester should provide only the information reasonably necessary to evaluate the request, such as:

B.3 Review

Metis may verify identity and authority, review internal matching information, inspect the underlying source, consult a data provider, request additional documentation, preserve information needed to prevent fraud, and determine whether an exception applies.

B.4 Potential outcomes

Depending on the facts and applicable law, Metis may:

B.5 No retaliation

Metis will not unlawfully discriminate or retaliate against an individual for submitting a good-faith privacy, correction, or dispute request.