Privacy policy
Last updated 16 July 2026
ClaimLensIQ is a claims forensic intelligence platform developed by Aurum Digital Consulting Limited. This policy explains what the platform holds, why, and who decides.
Two relationships, and they are not the same. For claims data, the insurer is the data controller and ClaimLensIQ is a data processor — we examine what the insurer sends us, on the insurer's instructions, for the insurer's purposes. For business-contact details submitted through this website, ClaimLensIQ is the controller.
Claims data — we process, the insurer controls
When an insurer uses ClaimLensIQ, their adjusters upload documents and photographs submitted with a claim: repair estimates, invoices, medical or police reports, damage photographs, and the structured details captured with them — policy and incident dates, incident location, and the parties involved in the claim, such as a garage, a hospital, an assessor, a payout account or a claimant's contact details.
We examine that evidence and return findings. We do not decide what an insurer collects, how long they keep it, or what they do with a claim afterwards — those are the insurer's decisions as controller, and they are set out in the data processing agreement between us.
What we do with it:
- Examine files for signs of alteration — the metadata a camera writes, the internal structure of a document, and whether a file has appeared on another claim in the same insurer's book.
- Compare claims within a single insurer's book to surface shared parties across unrelated claimants.
- Produce an evidence report for the claims team handling the claim. It surfaces evidence for human review — it is not a determination of fraud, and every claim decision rests with the insurer.
Data stays inside its own insurer. Every record is scoped to the insurer it belongs to and enforced at the database, not merely in the application. No claim, file, finding or party is visible to another insurer, and cross-claim matching only ever runs within a single insurer's own book.
Where it is held, and for how long
- Evidence files are stored privately and are never publicly addressable.
- Access is through short-lived links issued to a signed-in user of that insurer, and every issue of one is recorded.
- Retention is the insurer's decision as controller, and is set in the data processing agreement. We delete on their instruction.
Sub-processors
Analysis runs on our own infrastructure. Two categories of work reach outside it: an AI review of images and claim narratives, and a weather and geocoding lookup used to check whether an incident is plausible. Where a claim's evidence is sent to a sub-processor for those checks, it is sent for that check alone and not retained for training. The current list of sub-processors is maintained in the data processing agreement, and insurers are notified of changes to it.
Nigeria Data Protection Act
Our processing of claims data is governed by the Nigeria Data Protection Act 2023 and the data processing agreement with each insurer. As a processor we act only on the insurer's documented instructions, keep the data confidential, secure it, and assist the insurer in meeting requests from data subjects.
If you are a claimant and you want to know what is held about you, or want it corrected or erased, contact your insurer. They are the controller, and the request is theirs to decide. We will assist them in answering it, and the platform can produce a structured export of everything it holds on a claim for that purpose.
Website and demo requests — we control
If you ask for a demonstration through this site, we hold the name, work email, organisation and the details you volunteer about your line of business and claim volume, so that we can respond. We do not store the IP address a request arrives from; we store only a one-way hash of it, and only to stop the form being abused.
We use those details to reply to you and to keep in touch about the demonstration. We do not sell them, and we do not pass them to anyone outside Aurum Digital Consulting Limited for marketing.
Security
- Every record is scoped to its insurer and enforced at the database layer.
- Privileged roles — managers, analysts and administrators — must use time-based two-factor authentication.
- Actions that matter are written to an append-only audit log: who did what, to which claim, and when.
- Evidence is held in private storage, reachable only through short-lived signed links.
Contact
For data protection questions, requests, or to reach our data protection contact, email privacy@claimlensiq.com.
If you are a claimant, please contact your insurer first — as controller, they hold the decision on your request, and reaching them directly is the fastest route.