Legal
Privacy Policy
Last updated: 23rd March 2026
At Genairate Technologies Ltd (Company Number: 13926837), we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.genairate.io, use our products such as SnapLine, or otherwise engage with us.
1. Who We Are
Genairate Technologies Ltd is a UK-based AI insurtech firm providing digital transformation solutions for insurance and related financial services. Our flagship product, SnapLine, uses artificial intelligence to extract, triage, and structure broker submissions for property underwriters operating in the Lloyd's and London Market.
We are registered in England and Wales (Company Number: 13926837) and act as a data controller in respect of personal data we collect and process.
2. Information We Collect
We may collect and process the following categories of data:
- Personal Information: Name, email address, phone number, job title, and company details when you contact us or complete forms on our website.
- Technical Data: IP address, browser type and version, time zone setting, operating system, and platform.
- Usage Data: Information about how you use our website, including pages visited, interactions with content, and page response times.
- Customer and Submission Data: If you are a client using SnapLine, we process document metadata and structured information submitted through our platform. This may include business contact data and submission content relevant to insurance underwriting workflows.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and improve our services, including SnapLine.
- To respond to enquiries and support requests.
- To manage our contractual and commercial relationship with you.
- To send updates, alerts, or marketing communications where we are legally permitted to do so.
- To comply with legal and regulatory obligations.
- To improve the performance, accuracy, and reliability of our AI-powered features.
4. Legal Basis for Processing (UK GDPR)
We rely on the following lawful bases under UK GDPR:
- Consent: Where you provide information voluntarily or opt in to communications.
- Contract: Where processing is necessary to perform a contract with you or take steps prior to entering a contract.
- Legal Obligation: Where processing is required to comply with a legal or regulatory requirement.
- Legitimate Interests: For operating and improving our business, securing our systems, and delivering our services — where these interests are not overridden by your rights and freedoms.
5. Artificial Intelligence — How We Use AI and Your Data
Genairate Technologies builds and operates AI-powered products. This section explains how artificial intelligence features within SnapLine interact with your data, and how we ensure its responsible and transparent use.
5.1 How AI Is Used in Our Products
SnapLine uses large language models (LLMs) and machine learning techniques to process broker submissions. Specifically, AI is used to:
- Extract and structure data from unstructured documents (PDFs, emails, spreadsheets, images).
- Triage and classify submission content relevant to property underwriting.
- Generate structured, decision-ready outputs for review by qualified underwriters.
- Identify potential data gaps, inconsistencies, or anomalies within submission documents.
5.2 Human Oversight and No Fully Automated Decisions
SnapLine is designed as a decision-support tool, not a decision-making system. All AI-generated outputs are presented to qualified human underwriters for review, assessment, and final determination. No legally or commercially significant decisions — including acceptance, rejection, or pricing of insurance risks — are made solely by automated means without human review.
In accordance with Article 22 of UK GDPR, we do not subject individuals to decisions based solely on automated processing that produce legal or similarly significant effects. Where any automated processing is involved in producing outputs that inform consequential decisions, human oversight is always maintained.
5.3 Third-Party AI Infrastructure
To deliver our AI-powered features, we use infrastructure and model providers including Amazon Web Services (AWS) and its AI services (including Amazon Bedrock). These providers process data on our behalf under appropriate data processing agreements and in compliance with applicable data protection laws. We do not use other LLM providers to process client submission data unless explicitly disclosed and agreed with you.
5.4 Use of Client Data for AI Model Training
We do not use your submission data, business data, or personal data to train, fine-tune, or improve our AI models — or those of our third-party AI providers — without your explicit prior consent. Where we use data for internal model improvement, it is anonymised and aggregated before use.
5.5 Ethical AI Commitment
We are committed to the responsible development and deployment of artificial intelligence. Our principles include:
- Transparency: We are open about where and how AI is used within our products, and what data it processes.
- Fairness: We actively work to avoid bias or discriminatory outputs in our AI systems, including through regular testing and review of model behaviour.
- Accountability: We maintain internal governance processes to monitor AI performance, manage risk, and respond to issues.
- Security: AI processing is conducted within secure, access-controlled environments with encryption in transit and at rest.
- Compliance: Our AI systems are developed and operated in accordance with UK GDPR, the UK ICO's guidance on AI and data protection, and applicable insurance regulation.
5.6 AI-Related Rights
In relation to AI processing of your data, you have the right to:
- Request information about whether and how AI has been used to process your data.
- Request human review of any AI-generated output that has materially affected you.
- Object to processing of your personal data in AI-driven features where that processing is based on legitimate interests.
- Lodge a complaint with the ICO if you believe your data rights have been infringed.
To exercise any of these rights, contact us at hello@genairate.io.
6. Sharing Your Information
We do not sell your personal data. We may share your data with:
- Service providers who support our operations (e.g., cloud hosting, email, analytics, AI infrastructure).
- Regulatory bodies or law enforcement when required by law.
- Business partners where relevant to your use of SnapLine, and only with appropriate safeguards in place.
All third parties are required to respect the security of your data and to process it only in accordance with our instructions and applicable law.
7. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, loss, or disclosure. These include encryption in transit and at rest, access controls, and regular security reviews. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO and affected individuals in accordance with our legal obligations.
8. International Transfers
Your data may be transferred to and stored outside the UK and European Economic Area, including on AWS servers. Where such transfers occur, we ensure they are conducted in compliance with UK GDPR using appropriate safeguards, including standard contractual clauses or equivalent transfer mechanisms.
9. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, regulatory, tax, or reporting requirements. When data is no longer required, it is securely deleted or anonymised.
10. Your Rights
Under UK data protection law, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your data where we no longer have a lawful basis to retain it.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Request transfer of your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing purposes.
- Withdrawal of Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at hello@genairate.io. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. Cookies
We use cookies to enhance user experience and analyse site usage. You can manage your preferences via our cookie banner or your browser settings. For full details on the cookies we use, please refer to our Cookie Policy.
12. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or product features. Updates will be posted on this page with a revised “Last updated” date. Where changes are significant, we will notify affected users directly where we hold contact details.
14. Contact Us
If you have questions, concerns, or requests relating to this policy or our data practices, please contact:
Genairate Technologies Ltd
Registered in England and Wales
Company Number: 13926837
17 St Helens Place, London, EC3A 6DG
Email: hello@genairate.io
Tel: +44 204 630 0123