ProEstimate Solutions, LLP
Version: 1.3
Effective Date: September 3, 2026
Owner: ProEstimate Solutions, LLP
Supersedes: Version 1.1 (August 22, 2026)
This Privacy Policy explains how ProEstimate Solutions, LLP (“PES,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with our websites and the ProAudit platform and related estimating services (collectively, the “Services”). It is incorporated by reference into our Terms of Service and our End User License Agreement. Where a business subscribes to ProAudit, that business signs a separate ProAudit Services Agreement, and this Policy describes the same handling that agreement permits.
1. Summary: What We Keep, and What We Do Not
Documents such as estimate PDFs submitted to the Services often contain personal information. We use them only to extract the estimating data. When extraction succeeds, we delete the working copy of the source document held with the audit job, including the stored file bytes, at the point the job is recorded as complete. That deletion happens inside the same processing run, in the database write that follows the one saving the extracted data. If extraction fails, or the run never reaches that point, we may keep the source document in the form received for fourteen days so the job can be retried; a clean-up process that runs several times a day then deletes it, so in practice a file can persist a few hours past the fourteenth day. During that window the file is held exactly as submitted, including everything printed on it.
A document sent through a connected inbox has a second copy, and that one is cleared on a schedule. The inbox keeps its own stored copy of the file. Where the document was routed for processing, we release that copy on the next clean-up pass once no audit work for it is still queued or running; there is no fixed waiting period, but the release is not instant. Where a document arrives in the inbox and is never routed for processing, we delete it within ten days.
We do not retain embedded photographs or other image or file attachments from a source document, other than photo-caption text that forms part of the estimating data. We do not retain the page text or an optical-character-recognition text layer after extraction. We do not extract or store, as a data field, the name, mailing address, telephone number, email address, driver’s-license number, license-plate number, or insurance policy number of a vehicle owner, claimant, insured, or driver.
Following extraction, what we retain from a source document is the insurance claim number, the vehicle identification number (VIN), and the file name the customer assigned to the document, together with the estimating and audit data needed to deliver and support the Services. That data includes estimate line items, parts, labor, sublet, and estimate metadata, and it can include photo-caption text. We recognize that a claim number and a VIN may be treated as personal information under applicable law, and we safeguard them accordingly.
We do not control what a customer types into a file name or a photo caption. Either can be free text, and either can contain a person’s name or other personal information. We hold the file name while the account is active, and it is removed from the reduced copy described in Section 6. A photo caption is different: caption text forms part of the estimating data, so a name written into a caption can stay with that record, including after the account ends. Please do not put personal information in either.
We keep a reduced copy of estimating data to improve the Services, and we may keep it after a customer’s account ends. That copy still contains the complete VIN, and it can also contain the insurance claim number and photo-caption text. It is not deidentified data, and it may still be personal data. Deleting an account does not always mean erasure: we are permitted to satisfy a deletion obligation by converting the record into that reduced copy. Section 6 sets out what it contains, why we keep it, and how deletion works, and Section 9 sets out the timing.
Estimates are read on our own systems. ProAudit itself may use automated rules, analytics, machine learning, or artificial intelligence, and it runs on systems we control. We do not send source documents, extracted estimate text, or customer content to an outside artificial-intelligence system, a hosted optical-character-recognition service, or a cloud document-intelligence vendor, with the single exception described in the next paragraph. Any optical character recognition used in parsing runs on systems we control.
The exception: an AI feature the customer has turned on. A customer may turn on an AI feature. Each feature is described on the AI settings page. One current feature, profile import, reads a carrier program document, meaning a rate, operations, or program-requirement sheet issued by or for an insurer or program sponsor, and proposes audit-rule settings from it. Two switches in the account must both be on before the feature does anything: AI processing for the account, and the feature itself. A customer’s authorized user turns them on and off on the AI settings page, we can turn a feature off for everyone, and if our staff change a switch at a customer’s request we record who at the customer asked. That page lists every AI feature available, what each one sends, what it never sends, the current AI provider, how long that provider states it keeps requests and responses and whether it uses them for training, with the source and date of that statement, and the history of who changed each switch and when. We may change the AI provider at any time, and while a feature is available the page names its current provider. When AI features launched, an account that had already turned on AI processing had profile import carried forward as on; every other account, and every feature added later, starts off. The exception covers only what the AI settings page lists for that feature. No AI feature is permitted to send an estimate, extracted estimate text, a workfile export, an advisor report, an image report, or any other source document, whichever feature or screen is used. Because the checks described below do not determine whether a file is an estimate or other source document, a user must not submit an estimate or other source document to an AI feature. A carrier program document is not a source document merely because it contains estimate information. Before sending a file we check its declared type, extension, leading signature bytes and size; we do not read, classify, or redact its contents. The page states what information from or about the customer or its users each feature sends, and we send no other such information for that feature. For the profile-import feature, we send the selected carrier program document. For that same feature we also send, for each audit rule that account can engage, including rules the customer wrote, the rule’s name and category and either its short trigger summary or, if it has none, its description, in either case shortened to no more than 160 characters, with the names, types and options of the settings the rule advertises and any default values included in the rendered catalog; and a one-way hashed form of the acting user’s identifier. We also send our own instructions, the response format we require, a caching key, a request identifier, and the file’s type and size. We do not send audit-rule scripts, ADAS calibration rules, or the raw user identifier. The proposal the feature returns can contain text drawn from the submitted document, and nothing in the customer’s configuration changes unless a person at the customer takes a further step to put it on a profile. We delete the proposal from active systems within ninety days of the earlier of the day we first make it available and the day the customer’s term ends; copies in disaster-recovery backups expire under our backup-retention schedule. We ask the AI provider to delete its copy of the submitted file as soon as processing finishes and run a scheduled check for anything left behind; the provider retains its own request, response, safety, and security records for the period it publishes, which the AI settings page shows. We do not grant the provider permission to train on what we send.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use third-party advertising or cross-site tracking technology on our websites. Section 7 describes separately how we use deidentified and aggregated data, which is not personal information.
2. Who This Policy Covers, and Our Role
This Policy applies to visitors to our public websites, to users of the Services, and to individuals whose information appears in documents our customers submit. Our customers are businesses: collision repair facilities and related organizations. Where a customer submits documents containing information about its own customers or claimants, that customer determines the purpose of the submission and is responsible for having the necessary rights and consents.
For personal information contained in the content a customer submits, that customer is the controller or business and PES acts as its processor or service provider. PES acts as an independent controller only for personal information we collect directly from a customer’s personnel for our own account administration, billing, security, fraud prevention, legal compliance, and exercise of legal rights. We do not act as an independent controller for customer content, except to the extent required by law or legal process or as necessary to establish, exercise, or defend legal claims arising from that agreement. For visitors to our public websites, including the first-party analytics described in Section 4, PES is the controller.
3. Information We Collect
Account and user information. Name, business email address, password credentials (stored only as a cryptographic hash), role and permission assignments, multi-factor authentication and passkey registration data, and preferences.
Business and shop information. Company name, business locations enrolled under the account, business contact details including the shop business address, and configuration such as labor rates and operational settings.
Estimate documents and extracted data. Estimates, supplements, and related documents submitted for audit or estimate preparation, including any advisor report, image report, or other companion document received with them. As described in Section 1, a source document is deleted on successful extraction and is otherwise held only for the limited retry or routing windows. What persists is the estimating and audit data, the claim number, the VIN, the customer-assigned file name, and photo-caption text. Customer content also includes repair-order and insurer identifiers, shop configurations, rule overrides, customer-created notes, and the customer-specific activity records we make available in the account. Where a customer has turned on an AI feature, we also receive what a user submits to it, as the AI settings page describes for that feature; for the profile-import feature that is the carrier program document a user selects, as Section 1 describes.
Data our customers are told not to submit. The Services are collision-repair estimating tools and are not designed to satisfy PCI DSS, HIPAA, or similar specialized regulatory requirements. Our customer agreements prohibit a customer from typing, pasting, separately attaching, or asking us to retain payment-card data, social security numbers, biometric identifiers, medical or health records, authentication secrets, export-controlled information, and the other restricted data those agreements list. A customer does not break that rule merely because a third-party estimating system prints a vehicle owner’s, claimant’s, insured’s, or driver’s name, contact details, driver’s-license number, license-plate number, or insurance policy number on a source document in the ordinary course of estimating, and we handle such a document as described in Section 1. Payment information entered on our payment processor’s own page is processed there.
Billing information. Subscription plan, billing contact, invoice and payment history, and the tokenized reference our payment processor returns. We do not receive or store full payment card numbers; card details are collected and processed directly by our payment processor.
Communications. Messages you send us, support requests, bug or error reports you submit, and records of email we send you, including delivery, bounce, and unsubscribe events.
Technical and usage data. Server logs and application telemetry generated when you use the Services. This includes sign-ins, sign-outs, and failed sign-in attempts; multi-factor, passkey, and other authentication events; account, user, permission, and configuration changes; features used, pages opened, and reports run; the internet protocol (IP) address a session comes from and changes to it during a session; browser or application type (user-agent), screen dimensions, and the referring page where a browser sends one; an approximate location derived from that IP address; a device label; and, for the ProAudit Connect desktop application, a device identifier and the computer name that device reports. We use this to operate, secure, test, troubleshoot, and improve the Services, enforce account limits, verify that use matches what has been paid for, prevent fraud, and investigate suspected misuse.
We do not collect GPS location. The approximate location we derive comes from an IP address database, it is often wrong by a considerable distance, and we use it only to notice a sign-in that does not look like you. Note also that a customer’s authorized administrators can see the activity records of users on their account. We do not sell or license these records while they identify you or can reasonably be linked to you, and we do not use them to track you across other companies’ websites. We may produce aggregated measures from them, in a form that cannot reasonably be linked back to you, another user, a customer, or a particular estimate.
Documentation share pages. Where a customer shares repair documentation through a link we generate, we record the visit for that shop’s internal claims records, and authorized members of that shop can view it. No other customer can see it, and our own staff can access it only to operate and support the Services. The visit record includes the pages or items viewed, time spent active or idle, scroll position, mouse activity counts, and whether a document was downloaded. It also includes a shortened IP address, city, region, country, and internet service provider, the browser and device description your browser sends, and the referring page. We create a protected hash of the full IP address to recognize repeat visits, and the readable full IP address is not stored. Detailed page activity, including which shared items were viewed, is kept for up to 90 days, and a summary of each visit is kept for up to 10 years. We do not sell this information and we do not use it for marketing; we otherwise disclose it only as Section 8 permits or the law requires. The first-party analytics described in Section 4 also runs on these pages. The notice shown on the share page itself governs that page.
4. Cookies and Similar Technologies
We use cookies that are strictly necessary to operate the Services: authenticating your session, keeping you signed in across our subdomains, remembering interface preferences, and protecting against cross-site request forgery and other abuse. We also set a short-lived cookie on documentation share pages so that we can tell one visit from another for the visit record described in Section 3; it is not a sign-in cookie.
We also run our own first-party analytics on our websites. A script we host records the page address and any campaign tags in the link, the page title, the referring page, screen dimensions, time zone, a page-view identifier, a session identifier, whether the view started the session, and how long the page was engaged. As with any web request, our servers also receive your IP address and browser user-agent string, and from those we derive an approximate city, region, and country, your browser, operating system, and device type, and a technical visitor identifier that changes every day. If you are signed in, the record is associated with your user account and your organization. The script stores a session identifier in your browser’s session storage and a randomly generated visitor token in local storage so that repeat visits can be counted; those are browser storage rather than cookies, and the token is converted to a protected hash on our servers.
If your browser sends a Global Privacy Control or Do Not Track signal, we do not create or send that persistent visitor token. Be aware of what that does and does not do: it stops the token, and the rest of the measurement above continues. It is not a complete opt-out of our first-party analytics, and we do not currently offer one. Clearing your browser storage removes the stored identifiers but does not stop collection, and a new token may be created on a later visit. Individual analytics events are deleted after 90 days; the aggregated counts we build from them are kept longer, as described in Section 7.
We do not use third-party advertising cookies, advertising pixels, cross-site tracking, or third-party web analytics services on our websites. The analytics described above are first party: the data comes to us, not to an advertising or analytics company, and we do not use it to build a profile of you across other companies’ websites. Blocking essential cookies in your browser will prevent you from signing in.
5. How We Use Information
- to provide, maintain, and support the Services, including auditing estimates and producing the resulting findings and reports;
- to create and administer accounts, authenticate users, and enforce permissions and tenant isolation;
- to process subscriptions, invoices, and payments, and to manage billing disputes;
- to communicate with you about the Services, including service, security, billing, and administrative messages;
- to send product and marketing communications where permitted, which you may opt out of at any time using the unsubscribe link or by contacting us (we will still send necessary transactional and service messages);
- to monitor, secure, and troubleshoot the Services, detect and prevent fraud, unauthorized or automated access, and other misuse;
- to operate, support, secure, and improve the Services; and, using the reduced copy described in Section 6, to develop, train, and evaluate our audit rules and models and to determine vehicle build, factory equipment, options, and configuration;
- to create and use deidentified and aggregated data as described in Section 7; and
- to comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use identifiable customer content or customer reports to create benchmarks or analytics products, to market or commercialize data, to publish research, or to perform services on behalf of another customer, unless that customer gives prior written consent. Those broader uses are based only on deidentified or aggregated data, as described in Section 7.
Where applicable law requires a legal basis for processing, we rely on the performance of our contract with you, our legitimate interests in operating, securing, and improving the Services, your consent where we ask for it, and compliance with legal obligations.
6. Data We Keep to Improve the Services
We keep a reduced copy of estimating data specifically so that we can operate and improve ProAudit. Our Services Agreement calls it Internal Improvement Data. We describe it plainly here because it is the category of customer content most likely to still be personal data and to continue after the account it came from has ended.
What it contains. Internal Improvement Data is the estimating and audit data with the name, mailing address, telephone number, email address, driver’s-license number, license-plate number, and insurance policy number of any vehicle owner, claimant, insured, or driver removed as stored fields, and with the customer-assigned file name removed. We do not scrub free text. What remains includes the complete vehicle identification number, the insurance claim number, estimate line items and metadata, and photo-caption text.
A file name and a photo caption are treated differently, and the difference matters. We hold the customer-assigned file name while the account is active, and it is removed from this improvement copy. A photo caption is not removed, because caption text forms part of the estimating data itself. So a person’s name written into a photo caption can stay with the record, including after the account it came from has ended. This is the clearest reason not to put personal information in a caption.
It is not deidentified data, and it may still be personal data. We say so directly rather than describing it as anonymous. It remains the customer’s content, and to the extent applicable law treats a record of this kind as personal data, it is personal data and we protect it as such.
Why we keep the complete VIN. Vehicle build-sheet data is specific to an individual vehicle and cannot be retrieved from a partial VIN. We use that build data to support advanced driver-assistance system determinations, repair-procedure and calibration requirements, and other vehicle-specific repair determinations.
What we use it for. Solely to operate, support, secure, and improve the Services, including to develop, train, and evaluate our rules and models, and to determine vehicle build, factory equipment, options, and configuration. We do not use it to perform services on behalf of another customer.
What we do not do with it. We do not sell, license, publish, or otherwise disclose Internal Improvement Data to a third party, and we do not identify a customer as the source of any record in it. Submitting a VIN to a vehicle-specification, build-data, or repair-information source solely to obtain vehicle attributes is not such a disclosure, and we send that source no other Internal Improvement Data.
How long we keep it. We may retain Internal Improvement Data after a customer’s account ends, and only for the purposes above. Be clear about what that means in practice: those purposes last for as long as we operate and improve ProAudit, so a record can be held for years after the account it came from has closed, and no scheduled deletion date applies to it. The Services Agreement limits this retention by purpose rather than by a number of days.
Deletion, stated in full, because the two cases differ.
- A business customer’s commercial instruction does not reach it. Under the Services Agreement, a customer may direct us to delete or return the personal data we process on its behalf once the services are completed, but Internal Improvement Data is carved out of that direction. A customer cannot require us to delete Internal Improvement Data as a commercial instruction. That is a term of that business’s contract with us. It is not something the customer agreed to on behalf of you, a vehicle owner, a claimant, or any other individual, and it waives no right any individual has.
- A request from the individual is honored where the law requires deletion. We delete Internal Improvement Data, or the affected records within it, where applicable law requires deletion, including where we must give effect to an authenticated consumer or data-subject deletion request from the individual the information is about. The carve-out above applies only to a business customer’s own commercial instruction; it does not limit this, and a request the customer forwards to us reaches Internal Improvement Data too. These records are indexed by vehicle identification number and insurance claim number, not by a person’s name, so we may need one of those to find the right record. If your name appears only in a photo caption, tell us that and give us whatever you do have, such as the shop, an approximate date, a VIN, or a claim number, and we will use it to locate the record. Section 11 explains how to make a request.
7. Deidentified and Aggregated Data
Separately from Section 6, we create deidentified and aggregated data. Before using data for any purpose beyond operating, supporting, securing, and improving the Services, we apply reasonable measures designed to ensure the result cannot reasonably be associated with an identified or identifiable individual, a customer, a user, or a specific estimate, and cannot reasonably be used to reconstruct customer content.
A record that still holds a vehicle identification number, an insurance claim number, an insurance policy number, or a customer-assigned file name is not deidentified data, and we do not treat it as deidentified. That is why the Internal Improvement Data described in Section 6 is held under the stricter rules of that section and is never commercialized.
Our public commitment not to reidentify. We publicly commit not to reidentify deidentified data. We do not attempt to reidentify or reconstruct it, and we contractually require every recipient to maintain it in deidentified form and not to attempt reidentification or reconstruction.
Subject to those commitments, we may use, retain, disclose, license, sell, and commercialize deidentified data, aggregated data, and generalized insights for lawful business purposes, including improving and developing the Services, training and evaluating rules and models, benchmarking, industry research and reporting, white papers, analytics products, marketing, and services for other customers. That commercialization covers deidentified and aggregated data only, which is not personal information. We do not sell or share personal information as applicable law defines those terms. Data enters this program only once it meets the deidentification standard described in this section.
We will not sell or license to a third party a standalone data product derived predominantly from a single customer’s data, or one marketed or presented as a customer-specific dataset. We will not publicly identify a customer as a source of, participant in, or contributor to deidentified data, aggregated data, an industry study, a benchmark, an analytics product, or a commercial data product without that customer’s prior written consent.
8. How We Share Information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose information only as follows.
Affiliates and service providers. We use affiliates and vendors in the categories below under contract. Where a recipient acts as our processor or service provider, its contract limits it to our documented instructions and the purposes we permit; where a recipient has a different role under applicable law, the duties of that role govern. The categories are cloud hosting and infrastructure; security and monitoring; support; business email and file delivery, including transmission of report files and, where a customer enables a connected inbox, receipt of inbound files; analytics infrastructure, which today we operate ourselves as described in Section 4; payment processing; and professional services. We may change providers within these categories as our systems evolve. Any recipient whose actual role under applicable law is that of a processor, service provider, contractor, or subprocessor is held to the corresponding obligations, whatever label is used for it.
Other narrow recipients. Two kinds of lookup leave our systems, and each sends only what it needs:
- Vehicle specifications. We submit the vehicle identification number to the vehicle-specification service operated by the United States National Highway Traffic Safety Administration to obtain make, model, year, and related vehicle attributes. That service is a government data source and is not a subprocessor. We do not send it source documents, owner names, claim numbers, or estimate line items. Our customer agreements also permit us to submit a VIN to another vehicle-specification, build-data, or repair-information source for that same narrow purpose. Where the VIN comes from the Internal Improvement Data described in Section 6, we send that source no other Internal Improvement Data.
- Geocoding. Where a customer has a shop address on the account, we may submit that shop business address to a geocoding service to locate or validate the shop location. We do not send it source documents, the names of a vehicle owner, claimant, insured, or driver, claim numbers, or estimate line items. To the extent that address is personal data and the geocoding provider’s actual role under applicable law is that of a processor or service provider, we hold it to the corresponding obligations.
How card payments work. Card details are collected and processed directly by our payment processor. We receive a tokenized reference and never the full card number.
Artificial-intelligence and document-reading vendors. As stated in Section 1, we do not send source documents, extracted estimate text, or customer content to an artificial-intelligence system, a hosted optical-character-recognition service, or a cloud document-intelligence vendor, except where a customer has turned on an AI feature. For a feature that is on, we send its AI provider only the information from or about the customer or its users listed for that feature on the AI settings page. For profile import, that includes the selected carrier program document and the other material Section 1 describes. That provider acts on our behalf as an AI service provider and, to the extent it processes personal information, as our subprocessor. We name the current provider, and state the retention period it publishes, on the AI settings page in the account rather than here, so that page stays current between revisions of this Policy. Turning the feature off stops later requests once the setting is rechecked; it does not recall material already sent or cancel a request already sent, and requests to delete the provider’s copy still run. We may change the AI provider for a feature at any time. While the feature is available, the AI settings page names its current provider and states the retention period the provider publishes. A customer may turn the feature off at any time.
- Within your organization. Information in your account is visible to authorized users of your organization according to the roles and permissions your administrators configure.
- Professional advisers. Our own accountants, auditors, insurance carriers, financing sources, potential investors or acquirers, and lawyers, in each case only where they need the information and are bound by confidentiality obligations at least as protective as ours.
- Legal and safety. We disclose information when required by law, regulation, subpoena, or court order, and where legally permitted we give advance notice to the customer whose information is involved. Separately, we may use information to prevent fraud or harm, to secure the Services, and to establish, exercise, or defend legal rights, and we disclose it for those purposes only as our customer agreements permit or the law requires.
- Business transfer. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply to the transferred information.
Each vendor that processes personal data on a customer’s behalf is engaged under a written contract imposing obligations substantially the same as those we owe that customer, and we remain responsible for that vendor’s performance.
9. Retention and Deletion
Source documents. The working copy held with the audit job is deleted at the point the job is recorded as complete, inside the same processing run, in the write that follows the one saving the extracted data. Where extraction fails or a run never reaches that point, the file is held in the form received for fourteen days so the job can be retried, then removed by a clean-up process that runs several times a day. A document sent through a connected inbox has a second copy in the inbox: where it was routed for processing that copy is released on the next clean-up pass once no audit work for it is still queued or running, and where it is never routed it is deleted within ten days. Source documents are not retained for archival purposes and are not included in exports. The Services are not a customer’s archival system, and customers are responsible for keeping their own copies of source documents, photographs, and repair records.
While the account is active. Extracted estimating and audit data, together with the claim number, the VIN, the customer-assigned file name, and photo-caption text, is retained to provide the Services to your organization and to support historical reporting within your account.
After an account ends, the clock runs in two steps. First, for thirty days after termination, active customer content and customer reports remain available through the standard export functions, where technically and legally feasible. Only after that thirty-day export period ends do the deletion periods begin: identifiable customer content is deleted or rendered inaccessible in active systems within ninety days, and copies in disaster-recovery backups expire under our backup-retention schedule. That ninety-day period is measured from the end of the export window, not from the date the account ended.
How that deletion obligation may be satisfied. We may satisfy it by irreversibly converting customer content into the Internal Improvement Data described in Section 6, or into deidentified data described in Section 7. Where we do, the converted data is retained and used only as those sections permit. We state this plainly because it means information derived from an ended account can continue to exist in reduced form. What an AI feature sends and returns is the exception: it is not converted to Internal Improvement Data or to deidentified data. The profile-import proposal is deleted on the schedule in Section 1, and any other output an AI feature returns is deleted or rendered inaccessible on the schedule this section states for identifiable customer content. If we keep in our active systems a copy of the customer content sent for an AI feature, that copy is deleted or rendered inaccessible on the schedule this section states for identifiable customer content, and backup copies expire under our backup-retention schedule.
Retention beyond those periods. We keep identifiable customer content beyond those periods only where applicable law requires it, or, for the account, billing, and security records we hold as our own business records, where reasonably necessary for a legal hold, a pending dispute, a documented security investigation, fraud prevention, or billing. Anything kept on one of those grounds is isolated, accessed only for that purpose, and deleted when the purpose ends, and it is not used for model training, benchmarking, marketing, services for other customers, or other commercial data products.
What continues after an account ends. Internal Improvement Data is retained as described in Section 6: only for the purposes stated there, but for as long as those purposes continue, which can be years, and with no scheduled deletion date.
What may be kept indefinitely. Deidentified data, aggregated data, and our own software, rules, models, benchmarks, and generalized insights may be retained indefinitely, subject to Section 7. Security and error logs are retained on a rolling basis for operational and security purposes; where they hold personal data that we keep as our own business records, the limits in the preceding paragraphs apply.
10. Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal data in our control, appropriate to the nature and volume of the data. Depending on the system and the risk, those safeguards today include encryption of data in transit and at rest in production storage, logical isolation of each customer’s data, role- and permission-based access control, support for multi-factor authentication and passkeys, additional verification for sensitive operations, and monitoring and logging of security-relevant events. Access by our personnel is limited to those who need it to operate and support the Services.
If we discover or reasonably suspect a security incident affecting a customer, we notify that business customer without unreasonable delay, and sooner where applicable law requires it. We do not wait for an investigation to conclude before giving that first notice. We may delay only at the request of a law-enforcement authority, and only for the period requested, or as applicable law otherwise permits. The customer, not PES, decides on and sends any notice to individuals, insurers, and regulators, unless applicable law places that duty directly on us.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for managing the access your administrators grant.
11. Your Rights and Choices
Depending on where you live, applicable law may give you the right to request access to the personal information we hold about you, to request correction of inaccurate information, to request deletion, to obtain a portable copy, to opt out of the sale or sharing of personal information (which we do not do) and of targeted advertising (which we do not conduct), and not to be discriminated against for exercising these rights.
For residents of California, this includes rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Residents of other U.S. states with comprehensive privacy laws have comparable rights. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
Where information reaches us because one of our customers submitted it, that customer directs the processing and is responsible for receiving, verifying, and responding to your request. Referring your request to that customer is the usual path, and we support them in responding. Where applicable law requires us to act on your request ourselves, we do. If you send a request directly to us and we cannot act on it because we hold the information as that customer’s service provider, we will tell you so rather than leave it unanswered.
Deletion requests and improvement data. If you are an individual whose information appears in a document a customer submitted, and you make a deletion request that we must give effect to under applicable law, we delete the affected records from the Internal Improvement Data described in Section 6 as well. That holds whether the request reaches us directly or the customer forwards it to us: the contractual carve-out in Section 6 limits only what a business customer may instruct us to do as a commercial matter, and it does not limit your rights. Those records are indexed by vehicle identification number and insurance claim number, not by a person’s name, so we may need one of those to find the right record; if your name appears only in a photo caption, tell us so and give us whatever you do have, such as the shop, an approximate date, a VIN, or a claim number. We may also need to verify your identity before acting. We respond within the time applicable law requires. Section 16 has our contact details.
12. Canadian Users (PIPEDA)
Personal information about individuals in Canada may be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. This section is for Canadian users of the Services and also for Canadian vehicle owners, claimants, insureds, and drivers whose information appears in a document a customer submitted. What we keep from such a document is the insurance claim number, the vehicle identification number, the customer-assigned file name, and the estimating and audit data, which can include photo-caption text; the source document itself is deleted as described in Section 1. As described in Section 6, a reduced copy of that estimating data, which still contains the complete vehicle identification number and can contain the claim number and caption text, may be kept after an account ends in order to operate and improve the Services. You may request access to and correction of your personal information, may request deletion as the law provides, and may withdraw consent, subject to legal and contractual restrictions and to reasonable notice. You may also complain to the Office of the Privacy Commissioner of Canada. Section 16 has our contact details.
13. International Transfers
PES operates in the United States and information is processed and stored there. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection law may differ from that of your jurisdiction. Affiliates and vendors that process personal data on a customer’s behalf remain subject to the written-contract requirements described in Section 8. The Services are intended for United States commercial use, and our customer agreements require our prior written approval, and any required addendum, before a customer submits personal data that is subject to non-U.S. data law.
14. Children’s Privacy
The Services are business tools intended for use by adults in a professional capacity. They are not directed to children, and we do not knowingly collect personal information directly from anyone under the age of eighteen. If we learn that we have done so, we will delete it.
15. Changes to This Policy
We may update this Policy. Material changes will be communicated as required by applicable law and reflected in the version and effective date shown above. An updated Policy applies from its stated effective date to the extent applicable law and the governing terms permit. For account users, continued use can constitute acceptance where those terms and the law allow it; a change that requires affirmative acceptance does not take effect through continued use alone. This Policy does not amend a signed Services Agreement, and nothing in it asks anyone to give up a right the law provides. Prior versions are retained and available on request.
16. Contact Us
Questions, requests, or complaints regarding this Policy or our handling of personal information may be directed to ProEstimate Solutions LLP, Attn: Legal, 5900 Balcones Drive #28261, Austin, Texas 78731, or contact@proestimatesolutions.com. We will respond within the time required by applicable law and may need to verify your identity before acting on a request.