Thank you for choosing CommonPoint Inc. (“CommonPoint,” “we,” “us,” or “our”). We are a B2B, technology‑enabled professional services company that helps insurance carriers, MGAs, self‑insureds, risk managers, brokers, and other enterprise clients evaluate and manage third‑party administrators (TPAs) and related claims vendors. This Privacy Policy explains how we collect, use, disclose, and protect Personal Data in connection with our websites (including commonpoint.com and any subdomains), web‑based and cloud‑hosted services, portals and applications, marketing activities, and professional services (together, the “Services”).
Below is a high‑level summary of the categories of Personal Data we may collect, the sources, purposes, retention, and whether we “sell” or “share” it for cross‑context behavioral advertising (CCBA). Detailed descriptions appear in Sections 3–7.
We do not knowingly collect or use Sensitive Personal Information for purposes that require a right to limit under California law. We do not sell Personal Data and we do not “share” it for cross‑context behavioral advertising. If this ever changes, we will update this policy, honor browser‑based opt‑out signals (e.g., Global Privacy Control) where required, and provide clear opt‑out mechanisms.
We obtain Personal Data directly from you, from your employer, from our clients, partners, service providers, and from public/commercial sources to maintain accurate, current business records.
We do not seek to collect government identifiers (e.g., SSN), precise geolocation, financial account numbers, or health information through our controller‑mode Services. If a client requests processing that involves such data in our processor role, we do so only under contract and instructions, with appropriate safeguards.
We use Personal Data to:
When GDPR/UK GDPR applies, our lawful bases include: performance of contract, legitimate interests (e.g., to secure and improve our Services, B2B marketing to corporate emails, fraud prevention), consent (where required for certain cookies/marketing), and legal obligation.
We do not use Personal Data to make decisions that produce legal or similarly significant effects about individuals based solely on automated processing. If that changes, we will provide the required disclosures and rights.
We disclose Personal Data to:
We do not sell Personal Data and do not share it for CCBA. We also do not knowingly allow third parties to collect Personal Data on our Services for CCBA.
We are headquartered in the United States and may transfer Personal Data to countries that may have different data protection laws than your country of residence. Where required (e.g., for EEA/UK/Swiss data), we use approved Standard Contractual Clauses (SCCs) and implement additional safeguards. If we later self‑certify to the EU‑U.S. Data Privacy Framework (and the UK/Swiss extensions), we will update this policy and our transfer mechanisms accordingly.
We use first‑party and service‑provider cookies and similar technologies for authentication, security, performance, and analytics. In jurisdictions where consent is required for non‑essential cookies, we will provide a consent banner and honor your choices.
Depending on your state, you may have rights to access, correct, delete, port, and opt out of certain processing (sale/sharing/targeted advertising and, in some states, profiling in furtherance of decisions with legal or similarly significant effects). California residents also have the right to limit the use/disclosure of Sensitive Personal Information in certain cases.
How to exercise: Submit a request to privacy@commonpoint.com or through our web form (if provided). Please tell us your state of residence and the right you wish to exercise. We will verify your identity and respond within the time required by applicable law. You may also designate an authorized agent to submit a request on your behalf (we may require proof of authorization). You have the right to appeal our decision if we decline to act—appeal instructions will be provided in our response.
We will not discriminate against you for exercising your privacy rights.
You may have rights to access your Personal Data, rectify inaccuracies, erase it, restrict or object to processing, and data portability. Where we rely on consent, you may withdraw it at any time (this does not affect processing prior to withdrawal). You also have the right to lodge a complaint with a supervisory authority in your country/region.
We implement appropriate administrative, technical, and physical safeguards designed to protect Personal Data, including encryption in transit, access controls, logging and monitoring, and vulnerability management. No system can be 100% secure; if we learn of a security incident affecting your data, we will notify you and regulators as required by law and our contracts.
We retain Personal Data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and for other legitimate and lawful business purposes. Where feasible, we aggregate or de‑identify data for analytics and product improvement. We will not attempt to re‑identify de‑identified data except to assess whether our de‑identification processes satisfy applicable legal standards.
Our Services are intended for professionals and are not directed to children under 16. We do not knowingly collect Personal Data from children under 16.
Our Services may include links to third‑party sites or integrations with third‑party tools (e.g., single sign‑on, analytics, communications, project management). Those third parties’ privacy practices are governed by their own policies. Please review their notices before providing them with Personal Data.
We may update this Privacy Policy from time to time. We will post the updated version and change the “Last updated” date. If changes are material, we will take additional steps to notify you.
CommonPoint Inc.
Attn: Privacy Officer
privacy@commonpoint.com
If you are located in the EEA/UK/Switzerland, you may also contact your local supervisory authority. If we designate an EU/UK representative, we will update this section.
This Privacy Policy is intended to be informative and transparent. It does not create contractual or legal rights beyond those required by applicable law or existing contracts with our customers.
Last Updated: September 29, 2025
CommonPoint uses cookies and similar technologies to operate our Services, improve performance, and analyze usage.
Your Choices: - Manage cookies through your browser settings. - In the EEA/UK/Switzerland, non-essential cookies require your consent via our cookie banner. - We honor browser-based opt-out signals such as Global Privacy Control (GPC) where required.
For more details, see our Privacy Policy above.
Last Updated: September 29, 2025
To deliver our Services, CommonPoint uses trusted sub-processors who process limited Personal Data under contract:
Updates: - We will update this list before engaging new sub-processors. - Clients may object to a new sub-processor for legitimate data protection reasons, as provided in our Data Processing Addendum (DPA).
For more information, please contact privacy@commonpoint.com.
For requests to access, correct, or delete your information, please contact us at privacy@commonpoint.com.
By accessing or using the websites, portals, and services provided by CommonPoint Inc. (“CommonPoint,” “we,” “us”), including commonpoint.com and related applications (the “Services”), you agree to these Terms of Service. The Services are offered exclusively for business use by insurance carriers, MGAs, self-insureds, risk managers, brokers, and related enterprise clients, and their authorized representatives. Individual accounts are tied to professional roles within client organizations. You represent and warrant that you are using the Services on behalf of your business and in compliance with applicable laws.
You may use the Services only as permitted under applicable agreements with CommonPoint, these Terms, and our Privacy Policy (above). We retain all intellectual property rights in the Services, including proprietary software, benchmarking tools, workflows, and related materials. Except as expressly permitted by CommonPoint, you may not copy, reverse-engineer, resell, or otherwise misuse the Services. Accounts are personal to the designated Business User and must be kept secure; you are responsible for activities conducted under your login.
The Services are provided “as is” and “as available” without warranties of any kind, except as otherwise set forth in a written agreement between you and CommonPoint. To the fullest extent permitted by law, CommonPoint disclaims liability for indirect, incidental, or consequential damages arising from use of the Services. These Terms are governed by the laws of the State of North Carolina, without regard to conflict of law principles. Any disputes will be resolved in the courts located in Orange County, North Carolina, unless otherwise agreed in writing. We may update these Terms from time to time, and continued use of the Services constitutes acceptance of the updated Terms.