Last Updated: July 17, 2026
Doxa Insurance Holdings, LLC, and its subsidiaries and affiliates (collectively, “DOXA”, the “Company”, “we”, “us”, “our”), take your privacy seriously. This Global Privacy Statement (“Statement”) describes how we collect, use, disclose, transfer across borders, and otherwise handle (collectively, “process”) your personal information. This Statement also describes your choices regarding our handling of your personal information and how to make those choices, how we safeguard your personal information, and how you may contact us regarding our privacy practices.
The term “personal information” as used in this Statement means, unless specified otherwise, any information related to or about an identified or identifiable natural person.
This Statement contains the following sections:
1 – Scope of this Statement
You may interact with DOXA online and offline for a variety of reasons. This section explains when the Statement applies to DOXA’s processing of your personal information.
DOXA as Data Controller: Unless stated otherwise, this Statement applies to any personal information you provide to DOXA and any of your personal information we collect when you:
This Statement also applies to personal information DOXA may collect from or about the corporate representatives of clients, vendors, suppliers, business partners, and others for the purposes of conducting our own business, such as contracting and invoicing. This personal information generally is limited to contact details and other limited information necessary to complete business transactions (“Business Contact Information”).
Identification of the Data Controller: The DOXA entity whose website or physical location you visit, event you attend, or Service you use also is responsible for the processing of your personal information collected in relation to the visit, event, Service, or business relationship (“data controller”).
This Statement does not apply to the processing of your personal information described below:
DOXA as Data Processor: At times, DOXA may collect and otherwise process personal information in our capacity as a data processor, meaning that we handle your personal information only on our client’s behalf and in accordance with their instructions. This Statement does not apply to DOXA’s processing of personal information as a data processor. For information about this processing of your personal information, please refer to the website of the DOXA client on whose behalf DOXA provides the service.
DOXA as Employer: This Statement applies to the personal information processed by DOXA in our capacity as an employer, including the personal information of job applicants who apply for employment with DOXA or the Company’s current or former employees or independent contractors. DOXA maintains separate policies, as required by law, with respect to the Company’s processing of personal information in its capacity as employer.
Third-Party Sites: The Site may include links to, and plug-ins from, sites or applications operated by third parties (“Third-Party Sites”). DOXA does not control any Third-Party Sites and is not responsible for any personal information they may collect. The information collection practices of Third-Party Sites are governed by their privacy policies. If you choose to enter any Third-Party Site from the Site, please refer to that site’s privacy policy to learn more about that site’s processing of your personal information.
2 – Personal Information We Collect
The types of personal information we collect will vary depending upon the reason that you are interacting with us and may include the following:
DOXA may collect personal information which, in some jurisdictions, may be classified as “sensitive” or “special category” personal information (such as health information, race, religion, sexual orientation/sex life, and criminal history information) as described above. We do so only to the extent necessary for the provision of Services and only if and to the extent permitted by applicable laws. Where required by applicable law, we will obtain your consent prior to collecting or processing sensitive personal information. In other circumstances, we may process sensitive personal information where permitted by applicable law, including where necessary to provide Services, comply with legal or regulatory obligations, prevent or investigate fraud, administer claims, establish, exercise, or defend legal claims, or otherwise conduct our business.
If you provide us with personal information relating to other people (e.g., your spouse, civil partner, dependents, beneficiaries, etc.), we will process that information in accordance with this Statement. You are responsible for the accuracy of such information and for ensuring that those people are informed that you provided their personal information to DOXA and that we will process their personal information in accordance with this Statement.
Automated Collection of Information on the Site
When you browse our Site, we may collect information automatically through technology to help enhance our ability to serve you. This may include: the name of the domain and host from which you access the Internet; the Internet protocol (IP) address of the computer you are using; the browser software you use and your operating system; the date and time you access our Site; geolocation information, the Internet address of the site from which you linked directly to our Site, and other information collected through cookies and similar technologies.
We may use this information only as anonymous aggregate data to determine the number of visitors to different sections of our Site, to ensure the Site is working properly, and to help us make our Site more useful. For example, we may use your IP address to assist in correcting server problems and to administer our Site. Additionally, we may use this information for statistical purposes, such as determining user demographics for advertising purposes.
Cookies: Cookies are small pieces of data stored by your internet browser on your computer’s hard drive. Cookies may be used to recognize device types, remember preferences, analyze website traffic, improve Site functionality, and support security and fraud prevention activities. We do not use cookies to directly track or identify any individuals.
If you are browsing our Site, we may also use cookies or similar mechanisms to help us measure the number of visits, time spent, pages viewed and other statistics about traffic to our Site. We may also use cookies provided by Google Analytics for collecting website analytics to help us understand how visitors interact with our Site, improve Site functionality, and analyze trends and usage patterns. For more information on Google Analytics, and how it collects and processes data, go to: https://policies.google.com/technologies/partner-sites
You may set your browser to notify you when you receive a cookie or to prevent cookies from being sent. Please note that when you block the acceptance of cookies you limit the functionality we can provide when you visit our Site.
3 – Sources of Personal Information
We may collect personal information about you from the following sources:
4 – How We Use Personal Information
DOXA may use personal information about you for the following purposes depending on the nature of the interaction:
Providing Services to You or on Your Behalf:
Communicating With You:
Managing Our Business:
Complying With Legal Obligations and Protecting Ourselves:
Improving our Services:
Legal Basis for Processing
Where applicable law requires a legal basis for collecting, using, disclosing, or otherwise processing your personal information, this processing is based on the following legal grounds, as applicable:
Under the data protection law of some jurisdictions, by providing your personal information to DOXA as data controller, you consent to DOXA’s processing of your personal information as described in the Statement, as it may be modified from time to time.
Where processing of your personal information requires explicit consent, such as when collecting your sensitive personal information in some jurisdictions, the Company will provide you with a separate notice and request your explicit consent.
Please understand that you are not obliged to provide your personal information to the Company. However, if you do not provide your personal information, or otherwise do not consent to the processing of your personal information or withdraw your consent to the processing, where your consent is required, the Company may not be able to provide you with certain Services, administer policies or claims, or otherwise maintain its relationship with you.
You may have the right under applicable law to withdraw your consent.
For more information about this right, please refer to Section 11 of this Statement.
5 – How We Disclose Personal Information
We do not, and will not, sell your personal information or disclose it to third parties for cross-context behavioral advertising (“sharing”). We may disclose aggregated information about our users without restriction.
We may disclose personal information to the following categories of third parties for the following purposes and as permitted by law:
The Company will make the disclosures described above only as permitted by applicable laws.
6 – Choices About How We Use and Disclose Your Information
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:
Tracking Technologies and Advertising. You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. Please consult your browser’s documentation to learn how. Note that certain portions of the Services may not operate as intended if you refuse certain cookies.
Marketing Choices. You may opt out of receiving marketing communications from us at any time by following the unsubscribe instructions included in our marketing emails, by updating your communication preferences where available, or by contacting us using the details in the Contact Us section below. Even if you opt out of marketing communications, we may still send you non-marketing messages, such as communications about your policies, claims, transactions, or our ongoing business relationship with you.
7 – Cross-Border Data Transfers
Due to the global nature of our business and for the purposes set forth above, we may transfer personal information to parties located in countries other than the one where you reside, including in the United States. For example, we may transfer personal information internationally among DOXA entities, affiliates, subsidiaries, service providers, contractors, business partners, insurance carriers, reinsurers, and governmental or public authorities in another country in connection with the performance of our Services. The laws of these countries may provide a different level of protection for personal information than the country where you reside.
We will, where required by applicable law, rely on legally recognized transfer mechanisms when transferring personal information across borders, including adequacy decisions, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the Standard Contractual Clauses, and other lawful transfer mechanisms recognized under applicable data protection laws. We also implement reasonable contractual, technical, and organizational safeguards designed to protect personal information transferred internationally. Please contact us using the contact details provided under Section 13 (Contact Us), below, if you would like to request a copy of the relevant standard data transfer clauses.
8 – Information Security
We work to secure your personal information from being lost, accessed, used, modified, or disclosed to unauthorized persons. Only employees who need the information to perform a specific job are granted access to personal information. These employees are made aware of our security and privacy practices. Please note that despite our reasonable efforts, no security measure is ever perfect or impenetrable, so we cannot guarantee the security of your personal information. REGARDLESS OF THESE EFFORTS, WE CANNOT GUARANTEE THE SECURITY OR CONFIDENTIALITY OF ANY OF THE INFORMATION YOU PROVIDE TO US OVER THE INTERNET.
9 – Retention of Personal Information
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Statement, unless a longer retention period is required or permitted by law. We also retain records to meet our legal, regulatory, tax, accounting, and/or internal data retention policy needs, and will retain files where we reasonably believe there is a prospect of litigation.
The retention period for your personal information will vary depending on the context, and we determine the appropriate period based on criteria including:
When personal information is no longer needed, we will delete, destroy, anonymize, or deidentify it in accordance with applicable law and our records-retention practices.
10 – Consent and Withdrawal
Where required by law, we will obtain your consent before collecting, using, or disclosing your personal information. You may withdraw your consent at any time by contacting us using the details in the Contact Us section below. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
11 – Information Rights Specific to Your Region
Additional State-Specific Information for Individuals Who Reside in the United States
Scope of This Section
This section applies only to individuals who reside in the states of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia (collectively, “U.S. Residents”). This section provides U.S. Residents with information that is not provided elsewhere in this Statement and is required by the law of the state where they reside (collectively, “Applicable State Privacy Laws”).
This section does not apply to:
Certain personal information we process in connection with insurance products and services is subject to sector-specific privacy laws, including the Gramm-Leach-Bliley Act and applicable state insurance privacy laws. Our handling of that information, and any related privacy choices, are described in the separate privacy notice(s) provided to you in connection with those products and services.
Your Privacy Rights
Subject to any applicable limitations and exceptions, U.S. Residents have the following rights under Applicable State Privacy Laws:
If you reside in Delaware or Maryland: In addition to the rights described above, you also have the right to obtain a list of the categories of third parties to which we have disclosed your personal information.
If you reside in Minnesota: In addition to the rights described above, you also have the right to obtain a list of the specific third parties to which we have disclosed your personal information. If we do not maintain the information in a format specific to you, a list of specific third parties to whom we have disclosed any individuals’ personal information may be provided instead.
If you reside in Oregon: In addition to the rights described above, you also have the right to obtain, at DOXA’s option, a list of specific third parties to which we have disclosed either your personal information, or any personal information.
How to Exercise Your Privacy Rights
To exercise your rights, please email your request to privacy@doxa.com, mail to Doxa Insurance Holdings, LLC, ATTN Privacy Officer, 101 E. Washington Blvd, 10th Floor, Fort Wayne, IN 46802.
Alternatively, you may call us at (888) 747-3692. You will be asked to provide information necessary for us to process your request.
Except for residents of California and Utah, U.S. Residents may also have the right to appeal any decision we make in response to a request to exercise privacy rights, by emailing privacy@doxa.com or by calling us at the telephone number listed above. We will inform you of any action taken in response to an appeal, along with a written explanation of the reasons for our decision(s), in accordance with Applicable State Privacy Laws.
How We Will Verify Your Request
When you submit a request, we will take steps to verify your identity by matching the information you provide with the information we maintain in our records. To help us verify and process your request, please include the following in your request: (1) your first and last name; (2) your email address; and (3) your ZIP code. In some cases, we may request additional information to verify your request or where necessary to process it. If we are unable to adequately verify your identity to a sufficient degree of certainty to respond securely to your request, we will notify you.
Authorized Agent
If an authorized agent submits a request to know, correct, or delete on your behalf, the authorized agent must submit with the request a document signed by you that authorizes the authorized agent to submit the request on your behalf. In addition, we may ask you to follow the applicable process described above to verify your and the authorized agent’s identity. You can obtain an “Authorized Agent Designation” form by contacting us at privacy@doxa.com.
Response Timing
We will respond to your request within the timeframe required by Applicable State Privacy Laws, generally within 45 days of receipt. If we require more time, we may extend our response period by an additional 45 days (for a maximum of 90 days) where permitted by law, and we will notify you of the extension and the reason for it within the initial 45-day period.
Additional Information for California Residents
The California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”) requires the following additional information for California residents. The information below concerning the collection and disclosure of California residents’ personal information as well as the information in Sections 2 through 5, above, apply to DOXA’s collection, use, and disclosure of California residents’ personal information during the twelve months preceding the last updated date of this Privacy Statement and prospectively.
Notice at Collection
The Company collects the categories of personal information identified in Section 2 (Personal Information We Collect), above, for the purposes identified in Section 4 (How We Use Personal Information), above, and retains personal information for the period described in Section 9 (Retention of Personal Information), above. We do not, and will not, sell your personal information or disclose it to third parties for cross-context behavioral advertising (“sharing”). In addition, we have no actual knowledge that we sell or share the personal information of individuals of any age, including the personal information of children under 16. We also do not collect or process sensitive personal information for the purpose of inferring characteristics about you.
Shine the Light
Under California Civil Code Section 1798.83 (“Shine the Light“), California residents have the right to request in writing from businesses with whom they have an established business relationship, (a) a list of the categories of personal information (e.g., name, e-mail and mailing address and the type of services provided to the consumer) that a business has disclosed to third parties (including affiliates that are separate legal entities) during the immediately preceding calendar year for the third parties’ direct marketing purposes; and (b) the names and addresses of all such third parties. To request the above information, please contact us as directed in the Contact Us section below with a reference to Shine the Light inquiry.
Additional Information About the Categories of Personal Information We Collect
The personal information we collect falls within the following “categories of personal information” listed in the CCPA:
Additional Information About Disclosures of Personal Information
We may disclose your personal information to third parties for the following “business purposes” as that term is defined in the CCPA and as a supplement to the disclosure described in Section 5 (How We Disclose Personal Information), above:
Note on Deidentified Information
At times, DOXA converts California residents’ personal information into deidentified information using reasonable measures to ensure that the deidentified information cannot be associated with the individual (“Deidentified Information”). We maintain Deidentified Information in a deidentified form and do not attempt to reidentify it, except that we may attempt to reidentify the information solely for the purpose of determining whether its deidentification processes ensure that the information cannot be associated with the individual. DOXA prohibits vendors, by contract, from attempting to reidentify the Company’s Deidentified Information.
Additional Information Specific to Individuals Who Reside Outside the United States
If you reside in the European Union (“EU”) or the United Kingdom (“UK”) (collectively, “Non-U.S. Residents”), the following also applies to you:
Your Rights with Respect to Your Personal Information
Subject to any limitations and exceptions provided by the law applicable to your country of residence, you have the right to:
Additional Rights Applicable to EU, and UK Residents
Subject to any limitations and exceptions provided by the law applicable to your country of residence, EU and UK residents also have the right to:
How to Exercise Your Privacy Rights
For EU and UK residents: exercise your rights by submitting a request to us at privacy@doxa.com. We will respond to your request without undue delay and, in any event, within one month of receipt. Where necessary, considering the complexity and number of requests, we may extend this period by up to two further months, and we will inform you of any such extension, and the reasons for it, within one month of receiving your request. Where we require additional information to verify your identity or to clarify the scope of your request, the response period may not begin until we have received that information.
12 – Children
We do not knowingly collect personal information directly from children under the age of 13. Our Services are directed to adults who may provide us with personal information concerning their children under the age of 13 in connection with our Services, for example, where a child under the age of 13 is named as a dependent or beneficiary on an insurance policy. If we are notified that we have collected the personal information of a child under the age of 13 directly from the child and without verifiable consent from a parent or other individual or entity authorized to disclose such personal information, we will delete it from our files as expeditiously as possible.
13- Contact Us
If you have any questions about this Statement or the rights conferred to you under the applicable data privacy law, please contact us at privacy@doxa.com, Doxa Insurance Holdings LLC, ATTN Privacy Officer, 101 E. Washington Blvd, 10th Floor, Fort Wayne, IN 46802. Alternatively, you may call us at (888) 747-3692.
EU/UK Representative and Data Protection Contact. DOXA has appointed a data protection officer to oversee compliance with this Statement. You may contact our data protection contact regarding this Statement or our processing of your personal information at privacy@doxa.com. EU and UK residents may also lodge a complaint with their local supervisory authority, as described above.
14 – Changes to the Statement
We review this Statement regularly and may make changes at any time to take account of changes in our business activities, legal requirements, or the way we process personal information. We will place updates on this website and where appropriate we will give reasonable notice of any changes. You should periodically review this Statement to ensure you understand how we collect and use your personal information.