1. Who this policy covers
“Ansa,” “we,” “us,” and “our” mean Ansa Benefits and the entity operating the applicable Ansa service. This policy applies to visitors to ansabenefits.com, people who contact us, and users of the Ansa application and related services (collectively, the “Services”).
If you use Ansa through your employer, brokerage, or another organization, that organization may control the account and the information submitted to the Services. In that situation, your organization’s instructions and privacy notices may also apply.
2. Information we collect
Information you or your organization provide
- account and contact details, such as your name, work email, organization, role, and support messages;
- business and benefits information entered into or submitted to the Services; and
- preferences, feedback, and information provided when you book a demo or communicate with us.
Information from connected accounts
If you choose to connect a Google or Microsoft mailbox, the provider and the permissions you approve determine what Ansa can access. Depending on the enabled integration, this can include your email address, email headers and metadata, message content, attachments, and calendar information. The Ansa application is designed to use the mailbox permissions shown during connection; you can disconnect a mailbox from the application or revoke access through the provider.
Information collected automatically
We may receive standard technical information such as IP address, browser and device type, operating system, approximate location, pages viewed, referring page, timestamps, and error or diagnostic information. We may use cookies or similar technologies needed to keep a connection secure, remember preferences, and understand website usage.
3. How we use information
We use information to:
- provide, maintain, and secure the Services;
- connect and operate the mailbox and calendar integrations you select;
- organize, summarize, extract, and route benefits-related work, including through automated systems and AI-assisted features;
- respond to requests, provide support, and communicate with you;
- monitor performance, troubleshoot problems, prevent fraud and abuse, and improve reliability; and
- comply with law, enforce agreements, and protect rights and safety.
We do not use connected mailbox content for advertising. We do not sell personal information. If our practices change, we will update this policy and provide any notice required by law.
4. AI-assisted processing
Some Ansa features use automated models, classifiers, extraction tools, or agents to help process benefits work. These systems may analyze information submitted to the Services to produce summaries, classifications, drafts, or other workflow assistance. AI-generated results can be incomplete or incorrect and should be reviewed by an appropriately qualified person before being used for a benefits, employment, legal, financial, or other important decision.
Customer content is processed to provide the Services and under the customer’s instructions. Any use of customer content for model training, evaluation, or product improvement is subject to the applicable customer agreement, configuration, and law. We do not make a promise in this policy that overrides those terms.
5. When we share information
We may share information with:
- service providers that host, secure, support, analyze, or help operate the Services;
- mailbox and calendar providers, such as Google, Microsoft, or an integration provider, when you or your organization enables that connection;
- professional advisers, auditors, insurers, and other parties where reasonably necessary to operate our business;
- a successor or buyer in connection with a merger, financing, acquisition, reorganization, or sale of assets; and
- government authorities, courts, or other parties when required by law or reasonably necessary to protect people, property, or the Services.
We require service providers to handle information only for authorized purposes and to maintain appropriate protections. Your organization may also direct us to share information with its brokers, administrators, carriers, or other service providers.
6. HIPAA and protected health information
HIPAA may apply when a covered entity or business associate uses Ansa to create, receive, maintain, or transmit protected health information (PHI). Whether information is PHI and whether Ansa is acting as a business associate depends on the specific parties, services, and use case.
Customers must not submit PHI to an Ansa service unless the applicable agreement authorizes that processing and Ansa has executed a BAA with the customer when required. A BAA, customer agreement, or product-specific security documentation may impose additional limits on permitted services, subprocessors, retention, access, and deletion. This Privacy Policy does not replace any of those documents.
Customers are responsible for using the minimum necessary information, obtaining required permissions and notices, and configuring their workflows in accordance with HIPAA and other applicable law. Ansa does not provide legal, medical, insurance, or compliance advice through the Services.
7. Retention and deletion
We retain information for as long as reasonably necessary to provide the Services, meet the purposes described here, comply with legal and contractual obligations, resolve disputes, and enforce our agreements. Customer content may be retained or deleted according to the customer agreement and the customer’s instructions.
Disconnecting a mailbox stops the applicable connection from being used for future access, but does not automatically delete information already processed or retained under the applicable customer agreement. To request deletion or ask a question about retention, contact us using the address below.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting credentials and for using the Services only through authorized accounts and devices.
9. Your choices and rights
Depending on where you live and the role of your organization, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or limit certain processing. If your employer or another organization controls the information, we may direct your request to that organization or act on its instructions.
To submit a privacy request, email hello@ansa.health with “Privacy request” in the subject line. We may need to verify your identity and may retain information where required or permitted by law.
10. Children
The Services are intended for business and professional use and are not directed to children under 13. We do not knowingly collect personal information from children under 13.
11. Changes and contact
We may update this policy from time to time. The “Effective date” above shows when the current version took effect. Material changes will be communicated in a manner appropriate to the Services and applicable law.
Questions about this policy can be sent to hello@ansa.health or by mail to Ansa Benefits, 1860 Jackson St, San Francisco, CA.