OMNIDYA, INC.

PRIVACY POLICY

Personal Automobile Insurance Products and Services

1. Scope and Applicability

This Privacy Policy (“Policy”) describes how Omnidya, Inc. and its affiliates (“Omnidya,” “we,” “our,” or “us”) collect, use, disclose, retain, and protect Personal Information in connection with: (a) our websites at www.omnidya.com, www.omnidyashield.com, and www.omnidya.com/shield, and any subdomains, subpages, marketing landing pages, promotional microsites, or campaign-specific web pages operated by or on behalf of Omnidya under the omnidya.com or omnidyashield.com domains or any other domain that identifies Omnidya as the operator (collectively, the “Omnidya Websites”); (b) the Omnidya mobile application; (c) Omnidya-provided dashcam devices; and (d) all insurance products, services, and programs we offer, including the Computer Vision Program (collectively, the “Services”).

The URLs of specific landing pages and campaign pages may change from time to time. Regardless of the specific URL, any web page that is operated by Omnidya or on Omnidya’s behalf, that displays the Omnidya or Omnidya Shield name or branding, or that links to this Policy is covered by this Policy. Third-party websites that are not operated by or on behalf of Omnidya are not covered, even if linked from an Omnidya Website.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual or household. Where this Policy references “Sensitive Data,” it means Personal Information that includes precise geolocation data, biometric data, Social Security Numbers, driver’s license numbers, or financial account information.

This Policy applies to policyholders, prospective customers, authorized drivers listed on an Omnidya policy, and individuals who interact with our websites or application. Certain provisions apply specifically to residents of particular states, as identified in Section 10.

Entity Structure: Omnidya operates as a Managing General Agent (MGA). Insurance policies are underwritten by our carrier partner(s). Omnidya is the data controller for all Personal Information collected through the Services. When Omnidya discloses Personal Information to its insurance carrier partner(s) for underwriting and claims processing, the carrier partner(s) become independent data controllers for the data they receive, subject to their own privacy policies and regulatory obligations. Omnidya’s obligations under this Policy apply to data within Omnidya’s custody and control. Omnidya requires its carrier partner(s) to maintain privacy and security standards at least as protective as those described in this Policy through written contractual agreements.

2. Information We Collect

2.1 Personal Information You Provide

When you apply for insurance, create an account, or interact with our Services, we collect: your name; mailing and home address; email address; telephone number; date of birth; driver’s license number and state of issuance; Social Security Number (for identity verification and underwriting only — see Section 8 for enhanced SSN protections); vehicle identification number (VIN), make, model, and year; automobile accident history and traffic violation history; payment and billing information; emergency contact information; and information about other drivers to be covered under your policy.

Legal Basis: Contract performance (necessary to evaluate, issue, and administer your insurance policy) and legal obligation (regulatory requirements for identity verification and record-keeping).

2.2 Vehicle and Driving Data (Telematics)

If you participate in the Computer Vision Program, our dashcam device and mobile application collect the following data when your vehicle is in motion (triggered by the dashcam’s motion sensor or the mobile application’s detection of changing GPS coordinates):

Legal Basis: Contract performance (telematics data is a core component of the Computer Vision Program and directly determines premium pricing). Consent for Sensitive Data (precise geolocation) obtained through the standalone Sensitive Data Consent form at enrollment.

2.3 Video and Image Data

Our dashcam device records video of both the vehicle cabin and the exterior road environment when the vehicle is in motion (activated by the dashcam’s motion sensor). Full video recordings are transmitted to Omnidya’s systems for analysis. Specific data derived from video includes:

Audio: Omnidya dashcam devices do not contain microphones. No audio is recorded, transmitted, or stored under any circumstances.

Legal Basis: Contract performance and consent. See Section 2.4 for biometric-specific legal basis and disclosures.

2.4 Biometric Data — Enhanced Disclosure

This section provides disclosures required under state biometric privacy laws, including the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code §503.001), the Illinois Biometric Information Privacy Act (740 ILCS 14), and similar statutes in jurisdictions where Omnidya policyholders or their vehicles may be present.

2.5 Derived and Inferred Data

Omnidya generates the following derived data from the information described above: driver risk scores; behavioral risk profiles; driving pattern analyses; and Computer Vision Program eligibility determinations. These derived data points are used in underwriting, pricing, and claims evaluation as described in Section 3.

Legal Basis: Contract performance (risk scores directly determine premium pricing under the Computer Vision Program) and legitimate interest (product improvement and fraud detection), subject to your right to opt out of processing for product improvement purposes.

2.6 Account and Policy Information

We maintain records associated with your account, including: insurance policy details and coverage selections; claims history; premium payment records; Computer Vision Program participation status and eligibility; correspondence and communications with Omnidya; and identity verification records.

2.7 Website and Application Usage Data

When you use our websites or application, we automatically collect: IP address; device type, operating system, and browser type; pages visited, features used, links clicked, and session duration; and referring URLs. This data is collected through cookies and similar technologies as described in Section 7.

Legal Basis: Legitimate interest (website security, performance optimization, and user experience improvement). Consent for non-essential cookies as described in Section 7.

2.8 Information from Third-Party Sources

We obtain information from third-party sources to support underwriting and servicing, including: motor vehicle records and driving history from state DMVs or authorized data providers; vehicle history reports; claims history from industry databases (e.g., CLUE, A-PLUS); and credit-based insurance scores where permitted by applicable law and disclosed at the point of application.

3. How We Use Your Information

We use Personal Information for the following specific purposes, each tied to a stated legal basis:

3.1 Insurance Operations (Legal Basis: Contract Performance, Legal Obligation)

3.2 Automated Decision-Making and Algorithmic Processing

Omnidya uses proprietary algorithmic models, which may incorporate artificial intelligence and machine learning technologies, in the following areas: underwriting risk assessment; premium pricing; claims triage and evaluation; fraud detection and prevention; and driver risk scoring based on telematics and video data.

Omnidya’s use of telematics data, driving risk scores, and algorithmic models in underwriting and pricing is consistent with the rating plans, usage-based insurance program descriptions, and actuarial methodologies filed with and approved by the applicable state department of insurance.

Your Right to Human Review: You have the right to request human review of any decision produced by automated processing that materially affects your insurance coverage, premium amount, or claim outcome. To request human review, contact consumer.compliance@omnidya.com. We will complete the review within thirty (30) calendar days of verifying your request and will provide a written explanation of the outcome. If the human reviewer overturns or modifies the automated decision, the corrected decision will apply retroactively to the extent feasible.

Omnidya does not disclose the specific algorithms, model architectures, training data, or proprietary methodologies used in automated decision-making, as these constitute trade secrets under the Defend Trade Secrets Act (18 U.S.C. §1836) and applicable state law. Upon request, we will provide a plain-language explanation of the categories of factors considered in any automated decision affecting your coverage or premium.

Fair Credit Reporting Act: Omnidya’s driving risk scores, behavioral risk profiles, and Computer Vision Program analytics are generated using Omnidya’s proprietary data and methodologies for Omnidya’s own underwriting and pricing purposes. These outputs are not “consumer reports” as defined by the Fair Credit Reporting Act (15 U.S.C. §1681 et seq.) and are not provided to third parties for the purpose of determining consumer eligibility for credit, insurance, or employment. To the extent Omnidya obtains information from third-party sources (Section 2.8), such information is used in accordance with the Fair Credit Reporting Act and applicable state insurance laws, including providing adverse action notices where required.

Algorithmic Fairness: Omnidya conducts periodic bias audits on its algorithmic models to evaluate whether underwriting, pricing, and risk scoring outputs produce statistically significant disparate outcomes across protected classes. Omnidya’s algorithmic models are designed to comply with applicable state insurance anti-discrimination laws and the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (December 2023). Omnidya does not use race, ethnicity, religion, national origin, gender, sexual orientation, or any characteristic prohibited by applicable law as an input variable in its algorithmic models. Aggregate bias audit findings are available to state regulators upon request.

3.3 Service Operations (Legal Basis: Contract Performance, Legitimate Interest)

3.4 Product Improvement (Legal Basis: Legitimate Interest, Subject to Opt-Out)

We may use de-identified and aggregated data derived from telematics and driving information to improve our products, services, and risk models. You may opt out of the use of your data for product improvement purposes (while remaining enrolled in the Computer Vision Program) by contacting consumer.compliance@omnidya.com. Opting out of product improvement processing will not affect your insurance coverage, premium pricing, or Computer Vision Program participation.

3.5 Legal and Regulatory Compliance (Legal Basis: Legal Obligation)

4. Omnidya Does Not Sell Your Personal Information

Omnidya does not sell, rent, lease, license, or trade your Personal Information to any third party.

Omnidya does not exchange your Personal Information for monetary or other valuable consideration.

Omnidya does not share your Personal Information with third parties for cross-context behavioral advertising.

These commitments apply to all categories of Personal Information and Sensitive Data described in this Policy. These commitments apply regardless of how “sale,” “sharing,” or analogous terms are defined under any applicable state or federal privacy law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Texas Data Privacy and Security Act (“TDPSA”), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), and any similar statute enacted in any jurisdiction.

To the extent Omnidya displays promotional content within its own application or websites, such content is based solely on Omnidya’s first-party data generated through your direct interactions with Omnidya. It is not informed by data purchased from, or shared with, third-party advertising networks, data brokers, or data aggregators.

5. When We Disclose Your Information

Omnidya discloses Personal Information only in the circumstances described below. The following table maps data categories to recipient categories and purposes:

Data CategoryRecipientPurposeLegal Basis
Underwriting data, risk scores, policy informationInsurance carrier partner(s)Policy issuance, renewal, underwritingContract performance
Event Footage (60s pre / 30s post collision)Insurance carrier partner(s)Claims processingContract performance; consent
Payment dataPayment processorsPremium collectionContract performance
Name, DL#, VINMVR / vehicle history providersDriving and vehicle records retrievalContract performance; legal obligation
Claims dataClaims administratorsClaims investigation and resolutionContract performance
Telematics, video (encrypted)Cloud infrastructure providersSecure hosting and storageContract performance (processor)
As required by legal processCourts, regulators, law enforcementLegal complianceLegal obligation
All categories (upon M&A with 30-day notice)Successor entityBusiness continuityLegitimate interest; notice provided

5.1 Insurance Carrier Partner(s)

We disclose underwriting data, claims data, and driving risk scores to our insurance carrier partner(s) as necessary for them to fulfill their obligations as the policy underwriter. In the event of a collision or reported safety event, Omnidya may disclose video footage from the sixty (60) seconds immediately preceding, during, and thirty (30) seconds immediately following the detected event (“Event Footage”). Event Footage includes both exterior and cabin-facing dashcam recordings. Omnidya does not disclose video footage beyond the Event Footage window unless: (a) you provide specific written authorization; or (b) a valid legal process requires broader disclosure.

5.2 Service Providers

We engage service providers to assist with: cloud hosting and data storage; payment processing; motor vehicle record and vehicle history retrieval; claims administration support; customer communications; and dashcam and application technology maintenance. Each service provider is bound by a written data processing agreement requiring them to: (a) process data solely on Omnidya’s documented instructions and for the contracted purpose; (b) implement technical and organizational security measures at least as protective as those described in Section 8; (c) not sub-process data without Omnidya’s prior written approval; (d) assist Omnidya in fulfilling consumer rights requests; and (e) delete or return all data upon termination of the engagement.

5.3 Legal and Regulatory Disclosures

We disclose Personal Information when required by valid legal process, including subpoenas, court orders, and regulatory demands from state departments of insurance, attorneys general, or other governmental authorities with jurisdiction. We will comply with valid legal process directed at Omnidya. Where legally permitted, we will provide you with notice of such disclosure.

5.4 Business Transactions

In the event of a merger, acquisition, reorganization, asset sale, or similar corporate transaction, your Personal Information may be transferred to the successor entity. In such event, we will: (a) provide at least thirty (30) days’ advance written notice via the email address associated with your account and through a prominent notice on our websites; (b) describe the nature of the transaction and the identity of the successor entity; and (c) provide you the opportunity to cancel your policy before the transfer takes effect if the successor entity’s privacy practices are materially less protective than this Policy.

5.5 At Your Direction

We disclose Personal Information to third parties at your specific, verified instruction — for example, to another insurance provider, a lienholder, or an authorized repair facility.

Omnidya does not disclose Personal Information to data brokers, advertising networks, data aggregators, or any entity for purposes unrelated to providing, administering, or improving Omnidya’s insurance Services.

6. Data Retention and Destruction

We retain Personal Information for the minimum period necessary to fulfill the purposes described in this Policy and to satisfy legal and regulatory retention obligations. Specific retention periods by data category are:

Data CategoryRetention Period & Destruction Method
Video and Image Data15 days in active encrypted storage. Transferred to encrypted cold storage thereafter. Automatically purged 36 months after date of collection via cryptographic erasure. If an open claim requires retention, purged within 90 days of final claim resolution.
Biometric Data (facial geometry)15 days in active encrypted storage. Permanently destroyed within 3 years of last interaction or when purpose is fulfilled, whichever is first. Destruction via cryptographic erasure. Quarterly compliance audits conducted.
Telematics / Driving DataDuration of policy plus 3 years, or resolution of any open claim plus 3 years, whichever is longer. Destroyed via secure deletion.
Account and Policy InformationDuration of policy plus 7 years, or as required by applicable insurance record retention regulations, whichever is longer.
Claims DataFinal resolution of claim plus 7 years, or as required by applicable statute of limitations and insurance regulations, whichever is longer.
Social Security NumbersDuration of the identity verification or underwriting purpose. Destroyed within 90 days of purpose completion via secure deletion of the segmented storage.
Website Usage / Traffic Data13 months from date of collection.
De-Identified DataMay be retained indefinitely. See Section 6.2 for de-identification standards.

6.1 Operational Continuity

The retention and destruction timelines stated in this Policy represent Omnidya’s standard operational commitments. In the event that a technical disruption, system failure, natural disaster, or other force majeure event prevents a scheduled destruction cycle from executing on time, Omnidya will complete the destruction within thirty (30) days of the resolution of such event. An operational delay of this nature does not constitute a change in Omnidya’s retention practices, purposes of processing, or the obligations described in this Policy.

6.2 De-Identification Standards

When Omnidya de-identifies data, it applies statistical and technical methods that meet the requirements of CCPA/CPRA §1798.140(m), specifically: (a) the information cannot reasonably identify, relate to, describe, or be linked to a particular consumer or household; (b) Omnidya has implemented technical safeguards that prohibit re-identification; (c) Omnidya has implemented business processes to prevent inadvertent release of de-identified information; and (d) Omnidya makes no attempt to re-identify the information. Omnidya additionally implements contractual prohibitions on re-identification imposed on any recipient of de-identified data and ongoing monitoring to detect and remediate any re-identification risk. De-identified data is not Personal Information under this Policy.

7. Cookies and Tracking Technologies

Our websites — including all landing pages, campaign pages, and promotional microsites covered by this Policy — and our application use cookies and similar technologies (web beacons, pixels) for the following purposes:

Omnidya does not deploy advertising cookies, cross-site tracking cookies, or retargeting pixels on its websites. We do not participate in third-party advertising networks. You may control non-essential cookies through your browser settings. Disabling non-essential cookies may limit certain website functionality but will not affect your insurance coverage or Computer Vision Program participation.

Analytics providers engaged by Omnidya operate as data processors under written agreements and are prohibited from using data collected through our websites for their own independent purposes.

8. Data Security

Omnidya maintains a written Information Security Program designed to protect Personal Information against unauthorized access, acquisition, disclosure, alteration, and destruction. The program is reviewed and updated at least annually and includes:

Enhanced SSN Protections: Social Security Numbers receive additional safeguards including: access restricted to personnel with a verified, specific business need for SSN data; masking in all user-facing interfaces (only the last four digits are displayed); storage in a logically segmented, separately encrypted database partition; and comprehensive audit logging of all SSN access events.

These measures are designed with reference to the NAIC Insurance Data Security Model Law and applicable state implementations. Omnidya’s written Information Security Program is available for regulatory examination upon request. No security system is impenetrable. In the event of a security incident affecting your Personal Information, Omnidya will notify you and applicable regulators within the timelines required by each applicable state data breach notification statute, including: Arizona (ARS §18-552: without unreasonable delay); Texas (Bus. & Com. Code §521.053: within sixty (60) days); and any other state in which affected individuals reside. In no event will Omnidya delay individual notification beyond sixty (60) days from discovery of the incident, except where a shorter timeline is required by applicable law or where law enforcement requests a delay in writing.

All Personal Information is stored within the United States. Omnidya does not transfer Personal Information outside of the United States.

9. Mobile Application Permissions and Dashcam Operations

The Omnidya mobile application requests the following device permission:

The application does not request or access: your device microphone; your device camera (the dashcam is a separate hardware device); your contacts, photos, calendar, or other device data not listed above.

Dashcam Operations: The dashcam device activates its recording function when its internal motion sensor detects vehicle movement. Recording continues for the duration of the driving session and ceases when motion is no longer detected. The dashcam does not record, transmit, or store data when the vehicle is stationary except for brief device health check transmissions (connectivity status and software version only; no video, location, or telematics data).

10. Your Privacy Rights

10.1 Rights Available to All Omnidya Customers

Regardless of your state of residence, Omnidya provides the following rights:

10.2 Additional Rights for Texas Residents (TDPSA)

Under the Texas Data Privacy and Security Act, Texas residents additionally have the right to:

Sensitive Data Consent: Before Omnidya processes Sensitive Data (including precise geolocation and biometric data), we obtain your affirmative consent through a clear, standalone consent mechanism presented during Computer Vision Program enrollment. This consent is separate from the insurance application and any other agreement, and specifically identifies: (a) the categories of Sensitive Data to be processed; (b) the purposes of processing; and (c) your right to withdraw consent. You may withdraw your consent to Sensitive Data processing at any time by contacting consumer.compliance@omnidya.com. Withdrawal of consent will result in disenrollment from the Computer Vision Program and loss of associated premium discounts but will not affect the validity or enforceability of your underlying insurance policy.

Because Omnidya does not sell Personal Information as defined by TDPSA, an opt-out of sale is not applicable.

Omnidya has completed a Data Protection Assessment as required by TDPSA §541.105 for its processing of Sensitive Data, including precise geolocation and biometric data. A summary of this assessment is available to the Texas Attorney General upon request.

10.3 Rights for Residents of Other States

As Omnidya expands operations, we will honor the privacy rights provided by the laws of each state in which we operate or in which our policyholders reside. This includes, where applicable, rights under the CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and other state privacy statutes. State-specific supplements will be appended to this Policy before Omnidya commences operations in any new state that imposes additional privacy requirements.

10.4 How to Exercise Your Rights

Submit requests to: consumer.compliance@omnidya.com

Identity Verification: To protect your information, you must provide your Omnidya policy ID number and the email address associated with your account. For requests involving Sensitive Data or deletion, we may request additional verification (such as confirmation of your date of birth or the last four digits of your SSN).

Authorized Agents: You may designate an authorized agent to submit privacy requests on your behalf. The authorized agent must provide: (a) a signed, written authorization from you; or (b) a valid power of attorney under applicable law. We may contact you directly to verify that you authorized the agent and to confirm your identity before processing the request.

Response Timeline: We will acknowledge receipt of your request within five (5) business days. We will provide a substantive response within thirty (30) calendar days of completing identity verification. If additional time is required, we will notify you of the extension (not to exceed an additional fifteen (15) calendar days) and the reason for the delay.

Non-Discrimination: You will not be charged a different premium, denied coverage, provided a different level of service, or otherwise penalized for exercising any privacy right described in this Policy.

Appeal Process: If we deny your request in whole or in part, we will provide the specific reasons in writing. You may appeal by responding to the denial notice within sixty (60) days. We will respond to your appeal within thirty (30) calendar days. If your appeal is denied, you may contact the Texas Attorney General at www.texasattorneygeneral.gov, the applicable state attorney general, or the Texas Department of Insurance at www.tdi.texas.gov.

10.5 Universal Opt-Out Mechanisms

Omnidya recognizes and will honor opt-out preference signals, including the Global Privacy Control (GPC), as a valid opt-out request on its websites in any jurisdiction where recognition of such signals is required by applicable law. In jurisdictions where GPC recognition is not legally mandated, Omnidya will treat a GPC signal as a request to opt out of targeted advertising and will process it accordingly. Omnidya does not require you to submit a separate opt-out request if a recognized universal mechanism has already communicated your preference.

11. Third-Party Vehicle Occupants and Bystanders

Omnidya’s dashcam devices may incidentally capture images of individuals who are not Omnidya policyholders or authorized drivers, including vehicle passengers, other motorists, and pedestrians. Omnidya implements the following protections with respect to incidentally captured individuals:

12. Children’s Privacy

Omnidya’s Services are designed for adults who are eligible to hold automobile insurance policies. We do not knowingly collect Personal Information directly from children under the age of sixteen (16). We do not knowingly collect Personal Information from children under the age of thirteen (13) as defined by the Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected Personal Information from a child under 16 without appropriate consent, we will delete that information promptly. If you believe a child has provided us with Personal Information, contact consumer.compliance@omnidya.com.

Our dashcam devices may incidentally capture images of minor passengers. Such images are processed solely for driving environment assessment (not for identification of the minor), are not used to generate any profile or record associated with the minor, and are subject to the retention and destruction schedules in Section 6.

To the extent any data collected by Omnidya constitutes data from a known child as defined by TDPSA §541.001(29) or similar state statutes, Omnidya will process such data in accordance with its obligations for Sensitive Data processing, including obtaining any required consent.

13. Changes to This Policy

Material Changes: For material changes to this Policy — including changes to the categories of Personal Information collected, the purposes of processing, the categories of third-party recipients, data retention periods, or our data sharing or sale commitments — we will: (a) provide at least thirty (30) days’ advance written notice via the email address associated with your account and through a prominent notice on our websites and mobile application; (b) clearly describe the nature of each change; and (c) provide you the opportunity to cancel your insurance policy before the changes take effect if you do not agree to the revised terms. Material changes will not be applied retroactively to data collected under the prior version of this Policy unless you provide affirmative consent.

Non-Material Changes: For non-material changes (such as clarifications, corrections, formatting, or updates to contact information), we will update the “Last Updated” date and post the revised Policy. Non-material changes are effective upon posting.

We will maintain an archive of prior versions of this Policy, accessible upon request.

14. Contact Information and Accessibility

For questions about this Policy, to exercise your privacy rights, or to submit a complaint:

Privacy and Compliance Team

Email: consumer.compliance@omnidya.com

Omnidya, Inc.

[Mailing Address], [City, State ZIP]

For complaints not resolved to your satisfaction, you may contact:

Accessibility: This Policy is available in alternative accessible formats upon request, including large print, screen-reader-optimized text, and Spanish-language translation. To request an alternative format, contact consumer.compliance@omnidya.com.