Renewal Book

Data Processing Addendum

Version 2026-10-01 · effective October 1, 2026

This Data Processing Addendum (“Addendum”) is part of the Terms of Service. It is between your agency and FEVO LLC, doing business as Renewal Book. It covers personal information about your clients and their contacts that you put into Renewal Book (“Client Data”).

1. Roles and instructions

Your agency decides what Client Data to collect and why. Renewal Book (“we”) processes Client Data only to provide the Service, on your documented instructions: the Terms, this Addendum, and what you and your users do in the Service. We’ll tell you if we believe an instruction breaks the law.

2. What we commit to

  • Purpose. We use Client Data only to provide, secure and support the Service for you. We don’t sell it, share it for advertising, or combine it with other data for our own purposes.
  • Confidentiality. Only people who need access to run the Service have it, and they are bound to keep it confidential.
  • Security. We maintain an information security program appropriate to the nature of Client Data, including: encryption in transit; encryption at rest for documents and stored credentials; separation of each agency’s data enforced by the database; two-step sign-in; audit logging; daily backups; and limited, logged administrative access. See Security.
  • Sub-processors. We use the providers listed on the Sub-processors page, under written terms that protect Client Data at least as well as this Addendum. We’ll post notice at least 30 days before adding a provider that processes Client Data; you may object on reasonable grounds, and if we can’t resolve the objection you may close your account and receive a prorated refund of prepaid fees.
  • Security incidents. If we learn that Client Data has been accessed, used or disclosed without authorization, we’ll notify you without undue delay and in any case within 72 hours, with what we know, and keep you updated. We’ll help you meet any notification duties you have to clients or regulators.
  • Requests from individuals. The Service lets you find, correct, export and delete Client Data. Where it doesn’t, we’ll help you respond to requests from the people the data is about. Requests that reach us directly are passed to you.
  • Return and deletion. You can export Client Data at any time. When your account is closed, we delete Client Data from the Service within 30 days, and it leaves our backups within a further 14 days, unless the law requires us to keep it.
  • Oversight. On reasonable request, we’ll give you the information you need to show your oversight of us as a service provider, including a description of our security program. The Service is hosted in the United States.

3. Insurance data security laws

We understand that agencies are subject to the Gramm-Leach-Bliley Act and its Safeguards Rule and, in many states, insurance data security laws based on the NAIC Insurance Data Security Model Law, which require oversight of service providers. We maintain the safeguards described above so that you can meet those duties, and we’ll reasonably cooperate with your risk assessments and due-diligence questionnaires.

4. Your commitments

You have a lawful basis, and any notices or consents needed, to put Client Data into the Service. You’ll use the Service’s access controls sensibly, such as giving each person their own sign-in and removing people who leave.

5. Liability

This Addendum is subject to the limits of liability in the Terms.