This Privacy Policy explains how Metis Solutions LLC, together with its permitted successors and assigns ("Metis," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes Personal Data in connection with our websites, hosted software platform, applications, portals, APIs, reports, communications, events, and related products and services that link to this Privacy Policy (collectively, the "Services").
Metis provides commercial underwriting intelligence, business-verification, public-record research, and decision-support technology for workers' compensation insurance professionals and other authorized business users. Metis is not an insurer and does not make underwriting, pricing, coverage, eligibility, or claims decisions.
Please read this Privacy Policy together with our Terms of Service, applicable Order Form, Data Processing Agreement, and any other privacy or security notice presented when Personal Data is collected.
This Privacy Policy applies when Metis processes Personal Data in connection with:
Enterprise Customers may submit information to the Services or direct Metis to process information on their behalf. When Metis acts as a processor, service provider, or contractor for a Customer, the Customer generally determines why and how that information is processed. The applicable Customer's privacy notice and Metis's Data Processing Agreement govern that processing. Individuals should ordinarily direct requests concerning Customer-controlled data to the relevant Customer.
Metis may redirect a request to the applicable Customer or assist the Customer in responding, as required by contract and applicable law.
This Privacy Policy does not apply to:
If an account is provided or administered by an employer or other organization, that organization may control the account, access or manage account information and Customer Data, configure permissions, and request account reassignment or deletion. Authorized Users should direct questions about organization-controlled data to the relevant administrator.
Metis generally acts as a business, controller, or equivalent responsible entity for Personal Data used to operate our website and business; manage accounts; provide sales, billing, support, security, and communications; maintain our business relationships; and comply with law.
Depending on the applicable law, source, license, and product configuration, Metis may also act as a business or controller for public-source or licensed information that Metis selects, organizes, indexes, matches, summarizes, or otherwise processes for inclusion in its commercial business-intelligence Services.
Metis generally acts as a processor, service provider, or contractor when processing Customer Data solely on documented instructions from an Enterprise Customer. The applicable Data Processing Agreement describes the parties' respective responsibilities.
Government agencies, public-record custodians, websites, social-media platforms, commercial data providers, payment processors, and integration providers may independently determine their own processing purposes. Metis does not control their privacy practices.
"Customer Data" means information submitted to, stored in, transmitted through, or generated from a Customer's authorized use of the Services, excluding Usage Data and information Metis processes as an independent business or controller.
"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an identified or identifiable natural person or household, and includes equivalent terms such as personal information under applicable law.
"Process" or "processing" means any operation performed on Personal Data, including collecting, accessing, organizing, using, analyzing, storing, disclosing, transmitting, correcting, restricting, deleting, or destroying it.
"Search Subject" means a business, sole proprietor, owner, officer, registered agent, or other person or entity that is the subject of an authorized commercial research query or appears in a source result.
"Sensitive Personal Data" includes information treated as sensitive under applicable law, such as government identifiers, account credentials, precise geolocation, biometric or genetic information, racial or ethnic origin, religious beliefs, union membership, citizenship or immigration status, health information, sexual orientation, and information concerning a known child.
We may collect:
We may collect:
Metis does not ordinarily receive or store full payment-card numbers. Payment processors independently process payment information under their own terms and privacy notices.
We may collect:
We may automatically collect:
Depending on Customer configuration, a Customer may submit:
Customers are responsible for limiting submitted information to what is lawful, relevant, and reasonably necessary for the authorized commercial purpose.
The Services may locate, access, receive, organize, or display information from government databases, public records, publicly accessible websites, commercial data providers, and Customer-authorized sources, including:
Business records may identify natural persons associated with a business, including owners, officers, members, managers, registered agents, professional licensees, or sole proprietors. Metis's standard Services are designed for entity-level commercial research. When individual-associated information is included, Metis seeks to limit it to information relevant to the person's business role, authority, ownership, or association.
Metis does not intend its standard Services to provide personal background reports or to evaluate a person's personal character, reputation, creditworthiness, lifestyle, health, or eligibility for personal insurance, employment, housing, credit, or government benefits.
When a Customer enables an integration, we may receive identifiers, configuration information, records, and authentication tokens necessary to operate the integration. The Customer determines which integrations to enable and is responsible for its relationship with the third-party provider.
We may process:
The standard Services are not intended for unnecessary Sensitive Personal Data. Customers must not submit Sensitive Personal Data unless the applicable Service, contract, and security controls expressly permit it.
Metis does not use or disclose Sensitive Personal Data to infer characteristics about an individual or for cross-context behavioral advertising. Metis does not sell Sensitive Personal Data.
We may obtain Personal Data:
Metis may process Personal Data to:
Metis uses Personal Data and business information to automate research and organize source-derived results. Metis does not approve or reject insurance applicants and does not determine pricing, classification, coverage, eligibility, or policy terms.
Public and licensed sources may be incomplete, outdated, incorrectly indexed, or associated with a different business or person. Metis may use names, addresses, registration numbers, telephone numbers, websites, ownership information, and other identifiers to evaluate whether a source result is associated with a Search Subject.
No matching process is infallible. Customers must review source attribution and available identifiers before using a result for a material decision. Metis does not treat a name-only match concerning a natural person as independently verified information.
A Search Subject or other individual may report information believed to be inaccurate, incomplete, outdated, misidentified, or unlawfully processed by contacting Metis as described in Section 26. Metis may investigate, add a dispute notation, correct Metis-generated information, suppress a result, request documentation, or contact the underlying data source.
Metis may be unable to change information controlled by a government agency, website, or independent data provider. We may instead correct our association or presentation of the information and direct the requester to the source.
Metis may use rules-based systems, statistical methods, machine learning, or artificial-intelligence-assisted tools to identify sources, match entities, remove duplicates, extract facts, classify results, generate summaries, detect anomalies, improve search quality, and support security.
Automated results may be inaccurate or incomplete. Metis's outputs are research aids and are not final insurance decisions. Customers are responsible for qualified human review, independent verification, and compliance with applicable notice, explanation, dispute, and appeal requirements.
Metis may use Usage Data, feedback, de-identified data, and aggregated data to improve the Services. Metis will not use Customer Data to train a general-purpose model made available to other customers or third parties unless the applicable Customer has expressly agreed in writing.
Where Metis uses a third-party model or AI provider to process Customer Data, Metis will do so under applicable contractual, security, and data-processing restrictions.
Metis may disclose Personal Data to the following recipients:
An enterprise account administrator may access Authorized User information, account activity, permissions, reports, and Customer Data within the organization. Customers are responsible for their administrators and internal access decisions.
We may engage cloud-hosting, security, identity, payment, billing, communications, customer-support, analytics, professional-services, document-processing, and AI technology providers. They may process Personal Data only for authorized purposes and subject to contractual obligations appropriate to their role.
We may transmit search identifiers to a government source, public website, licensed provider, or data integration to obtain an authorized result. The recipient may independently process the query under its own rules and privacy notice.
We disclose information to an integration provider when a Customer enables or directs the integration.
We may disclose information to attorneys, accountants, auditors, insurers, financial institutions, investors, and other professional advisors subject to appropriate confidentiality obligations.
We may disclose information where reasonably necessary to comply with law or legal process; respond to regulators or governmental authorities; protect rights, safety, and security; prevent fraud or abuse; or enforce our agreements.
We may disclose or transfer information in connection with an actual or proposed financing, merger, conversion, reorganization, acquisition, sale of assets, bankruptcy, or similar transaction, subject to appropriate safeguards.
We may disclose information for another purpose disclosed at collection or with the individual's direction or consent.
Metis does not sell Customer Data, account credentials, payment information, or confidential Customer content for money. Metis does not disclose Customer Data to third parties for their own cross-context behavioral advertising.
Customers pay for access to Metis's commercial research technology and authorized source results. The standard Services are designed to provide information about business entities. A source result may nevertheless contain limited information about a natural person in a business capacity, such as an owner, officer, registered agent, professional licensee, or sole proprietor.
Some privacy laws define "sale" broadly to include certain transfers of Personal Data for valuable consideration, even without a payment specifically allocated to the data. Where a Metis disclosure legally qualifies as a sale, sharing, targeted advertising, or profiling subject to an opt-out right, Metis will provide and honor the applicable right.
As of the Effective Date, Metis does not use Personal Data for cross-context behavioral advertising. If our practices change, we will update this Privacy Policy, provide legally required notices and controls, and recognize applicable universal opt-out signals.
Metis does not sell Sensitive Personal Data and does not use it for targeted advertising.
Metis and authorized providers may use cookies, local storage, pixels, tags, software-development kits, and similar technologies for authentication, security, preferences, functionality, performance, analytics, and legally permitted marketing.
Users may manage cookies through browser settings and any cookie-preference tool Metis provides. Blocking necessary cookies may prevent parts of the Services from functioning.
Where required by law, Metis recognizes valid browser-based universal opt-out mechanisms, including Global Privacy Control, as a request to opt out of applicable sale, sharing, or targeted advertising for the browser or device from which the signal is sent.
Metis may send transactional, security, billing, support, and service communications that are necessary to administer an account. These communications are not promotional and generally cannot be disabled while an account remains active.
Recipients may opt out of marketing emails by using the unsubscribe link or contacting us. We may retain limited suppression-list information to honor the opt-out.
Metis retains Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide Services, maintain business and security records, comply with source licenses, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, and regulatory obligations.
Retention periods depend on factors such as:
When retention is no longer reasonably necessary, Metis will delete, anonymize, aggregate, or isolate the information, subject to backup cycles and lawful exceptions.
Metis uses reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, acquisition, alteration, disclosure, destruction, or loss. Safeguards may include access controls, authentication, encryption, logging, monitoring, vulnerability management, incident-response procedures, vendor review, employee training, and secure development practices.
No system is completely secure. Individuals should use unique credentials, protect authentication factors, and promptly notify Metis through the contact or support method available at https://metisinsured.com of suspected account compromise or misuse.
Metis is based in the United States. Personal Data may be processed in the United States and other countries where Metis or its service providers operate. Those countries may have data-protection laws different from those in the individual's location.
Where applicable law requires a transfer mechanism, Metis may use standard contractual clauses, contractual safeguards, adequacy mechanisms, or another lawful transfer method described in an applicable Data Processing Agreement.
Depending on residence, the applicable law, and relevant exemptions, an individual may have the right to:
A privacy request may be submitted through the contact method available at https://metisinsured.com or by mail to Metis Solutions LLC, Attn: Privacy, 1106 S Redwood Rd, Unit 13, Salt Lake City, UT 84104, United States.
Metis will take reasonable steps to verify a request based on the nature of the request, the sensitivity of the information, and the risk of unauthorized disclosure or deletion. We may request information reasonably necessary to match the requester to relevant records. We will not require creation of an account solely to submit a request.
Where we cannot verify identity or authority, we may deny or limit the request and explain the reason, subject to applicable law.
An authorized agent may submit a request where permitted. Metis may require proof of the agent's authority and may ask the individual to verify identity or confirm the authorization directly.
Where applicable, an individual may appeal a denied request through the contact method available at https://metisinsured.com with the subject line "Privacy Request Appeal" within 45 days after the denial. Metis will respond within the period required by applicable law.
When Metis processes information solely on behalf of a Customer, we may direct the requester to that Customer. Metis will support the Customer as required by the Data Processing Agreement and applicable law.
A person identified in a commercial source result may request review of a potential misidentification, inaccurate association, outdated Metis-generated summary, or other alleged error. Metis may request documentation sufficient to distinguish the correct business or person and protect against fraudulent alteration requests.
This Section supplements the Privacy Policy for California residents where the California Consumer Privacy Act, as amended, applies to Metis's processing and no exemption controls.
During the preceding twelve months, Metis may have collected the following categories of Personal Information, depending on whether the applicable feature was operational and used:
Metis does not intentionally collect protected-classification information for underwriting decisions and does not use Sensitive Personal Information to infer characteristics.
The sources of these categories are described in Section 5; the business and commercial purposes are described in Sections 6 through 8; and the categories of recipients are described in Section 9.
Metis does not sell account credentials, payment information, confidential Customer Data, or Sensitive Personal Information. Metis does not share Personal Information for cross-context behavioral advertising as of the Effective Date.
Metis may provide authorized commercial source results to Customers as part of a paid Service. If a particular transfer of information about a natural person constitutes a sale under California law, Metis will provide the legally required opt-out mechanism and honor applicable requests and browser signals.
Subject to verification, exemptions, and legal limitations, California residents may request access to categories and specific pieces of Personal Information, correction, deletion, information about sales or disclosures, opt-out of sale or sharing, and limitation of certain uses of Sensitive Personal Information. Metis will not unlawfully discriminate against an individual for exercising these rights.
Appendix A provides a concise Notice at Collection. Metis may also present a context-specific notice at or before collection.
Where Metis is legally classified as a data broker, Metis will comply with applicable registration, disclosure, deletion, and centralized-request obligations.
Where applicable state law provides rights to access, correct, delete, obtain portable data, opt out of sale or targeted advertising, opt out of specified profiling, or appeal a decision, Metis will honor those rights subject to verification and applicable exemptions.
Where required, Metis recognizes valid universal opt-out mechanisms. If a request is denied, the response will include instructions for appeal and, where required, information about contacting the applicable state attorney general.
Where European data-protection law applies and Metis acts as controller, Metis processes Personal Data based on one or more of the following legal bases:
Subject to applicable conditions and exceptions, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a competent supervisory authority.
Metis does not use its standard Services to make solely automated decisions that produce legal or similarly significant effects on Search Subjects. Customers are prohibited from treating Metis outputs as a substitute for required human review.
Requests may be submitted using Section 16. Metis does not currently designate a European representative or Data Protection Officer because those appointments are not presently required for the Services as offered. Metis will update this section if that changes.
The Services are designed for business professionals and are not directed to children under thirteen or the higher minimum age required by applicable law. Metis does not knowingly collect Personal Data directly from children through account registration.
Customers may not use the standard Services to research children or submit information about children unless expressly authorized under a separate written agreement and permitted by law. Contact Metis through the method available at https://metisinsured.com if you believe a child has provided Personal Data directly to Metis.
Some browsers offer a Do Not Track setting. Because no uniform industry standard governs all Do Not Track signals, Metis does not respond to legacy Do Not Track signals unless required by law. Metis does recognize legally valid universal opt-out mechanisms as described in Section 11.4.
The Services may link to government websites, social-media platforms, public databases, commercial sources, or other third-party services. Metis is not responsible for their content, availability, accuracy, security, or privacy practices. Individuals should review the third party's applicable notices.
Metis may create and use information that has been aggregated or de-identified so that it cannot reasonably be linked to an identified individual. Metis may use such information for analytics, benchmarking, security, research, product development, and other lawful purposes.
Where required by law, Metis will maintain de-identified information in de-identified form and will not attempt to re-identify it except to test whether de-identification processes are effective or as otherwise legally permitted.
Metis may update this Privacy Policy to reflect changes in the Services, data practices, legal requirements, or business operations. The revised policy will identify the updated date. Where required, Metis will provide additional notice or obtain consent before a material change applies. Metis will not materially reduce the protections applicable to Customer Personal Data during a current paid Subscription Period except as required by law, permitted by the governing agreement, or accepted by the Customer.
Metis Solutions LLC may convert, reorganize, or transfer its business to a corporation, Affiliate, or successor entity. Personal Data may be transferred as part of that transaction subject to this Privacy Policy, applicable law, and any additional notice or choice legally required.
Questions, complaints, privacy requests, correction requests, and appeals may be submitted through the contact method available at https://metisinsured.com or mailed to:
Metis Solutions LLC
Attn: Privacy
1106 S Redwood Rd, Unit 13, Salt Lake City, UT 84104, United States
Website: https://metisinsured.com
This Notice at Collection summarizes the categories of Personal Data Metis may collect, the purposes for which it is used, applicable retention considerations, and available privacy rights. Context-specific notices may also be presented at signup, through cookies, in forms, in integrations, or within search workflows.
Metis may collect the following categories of Personal Data:
Metis uses these categories to:
Metis retains each category only for as long as reasonably necessary for the purposes described above, subject to contractual, security, source-license, legal, tax, accounting, audit, dispute, and backup requirements.
Metis does not sell account credentials, payment information, confidential Customer Data, or Sensitive Personal Data, and does not share Personal Data for cross-context behavioral advertising as of the Effective Date. If an authorized commercial-source transfer legally qualifies as a sale, Metis will provide and honor the applicable opt-out right.
The complete Privacy Policy explains available rights and how to submit a request through the contact method available at https://metisinsured.com.
This process is intended for an owner, officer, registered agent, sole proprietor, professional licensee, or other natural person who believes that Metis has associated, summarized, displayed, or disclosed inaccurate or inappropriate information concerning that person.
A requester should provide only the information reasonably necessary to evaluate the request, such as:
Metis may verify identity and authority, review internal matching information, inspect the underlying source, consult a data provider, request additional documentation, preserve information needed to prevent fraud, and determine whether an exception applies.
Depending on the facts and applicable law, Metis may:
Metis will not unlawfully discriminate or retaliate against an individual for submitting a good-faith privacy, correction, or dispute request.