Privacy Policy
Aleksifa Digital ("we," "us," or "our"), based in Serbia, Europe, operates Bolt COI, a certificate of insurance compliance platform for motor carriers, brokers, and networks. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Effective date: July 20, 2026
1. Who this policy applies to
This policy applies to visitors of our marketing website, operator users who create accounts and use the Bolt COI application, and third parties (such as carriers or affiliates) who upload documents through magic-link intake without creating an account.
Aleksifa Digital is the data controller for personal information processed through Bolt COI. We are located in Serbia, Europe.
2. Information we collect
Depending on how you interact with Bolt COI, we may collect:
- Account and profile data — name, email address, password (stored hashed), organization name, role, and security settings such as MFA enrollment.
- Organization and roster data — third-party names, contact details, workflow metadata, compliance status, notes, and related records you or your team enter in the service.
- Insurance documents and extracted data — certificates of insurance, endorsements, W-9s, and other files you or third parties upload, plus fields extracted from those documents (for example ACORD limits, policy dates, and named insured information).
- Third-party upload activity — when someone uses a magic link, we collect the files they submit and limited technical data needed to validate the link and deliver uploads to your organization.
- Usage and audit data — sign-in events, feature usage, review decisions, configuration changes, and other actions recorded in our audit log to support security and compliance workflows.
- Billing data — subscription tier, plan status, and billing identifiers. Payment card data is collected and processed by our payment provider; we do not store full card numbers.
- Contact form submissions — name, email address, optional company name, and message content when you use our public contact form.
- Technical data — IP address, browser type, device information, cookies, and similar data used to secure the service, remember preferences (such as marketing theme), and diagnose errors.
3. How we use information
We use the information above to:
- Provide, operate, and improve Bolt COI;
- Authenticate users, enforce access controls, and prevent fraud or abuse;
- Process uploaded documents, run compliance rules, and surface review queues;
- Send service-related emails such as verification, alerts, collection reminders, and support responses;
- Manage subscriptions, invoices, and account changes;
- Monitor reliability and security, including error reporting; and
- Comply with law and respond to lawful requests.
We do not sell personal information. We do not use uploaded insurance documents to train public AI models.
4. AI-assisted document processing
On eligible plans, Bolt COI may send document content to third-party AI providers (such as OpenAI) to extract structured fields from certificates and related PDFs. Final compliance decisions are made by deterministic rules in our platform, not by the AI model alone. We configure providers to process data only as needed to deliver the service.
5. How we share information
We may share information with:
- Service providers — hosting, email delivery, payment processing (Freemius), error monitoring (Sentry), and AI processing vendors that help us run Bolt COI under contractual confidentiality and security obligations.
- Your organization — data you upload or that third parties submit through your magic links is visible to authorized users in your organization according to role permissions.
- Legal and safety — when required by law, to protect rights and safety, or to enforce our Terms of Service.
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to continued protection of your information.
6. Cookies and similar technologies
We use cookies and local storage for authentication sessions, security, and marketing site preferences (such as light/dark theme). You can control cookies through your browser settings, but some features may not work correctly if essential cookies are disabled.
7. Data retention
We retain information for as long as your organization uses the service and as needed to provide features you rely on (including compliance history and audit logs). Retention periods for documents and records may be configurable within the product. When you delete data or close an account, we delete or anonymize information within a reasonable period unless we must retain it for legal, security, or backup purposes.
8. Security
We use administrative, technical, and organizational measures designed to protect information, including encryption in transit (TLS), encryption at rest for stored documents, signed and time-limited download links, role-based access controls, and append-only audit logging. No method of transmission or storage is completely secure; please use strong passwords and enable MFA where available.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Operator users can manage much of their account data in product settings. To submit a privacy request, email privacy@boltcoi.com. We may need to verify your identity before fulfilling a request.
If you are in the EEA, UK, Switzerland, or Serbia, you may have rights under applicable data protection law (including the GDPR and Serbian personal data protection law), including the right to lodge a complaint with a supervisory authority. If you are a California resident, you may have additional rights under the CCPA/CPRA.
10. International transfers
Bolt COI is operated from Serbia, Europe. Your information may also be processed in other countries where our infrastructure and service providers operate (including the United States). When we transfer personal data outside Serbia or the EEA, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law.
11. Children
Bolt COI is a business service not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on https://boltcoi.com/privacy and update the effective date above. Continued use of the service after changes become effective constitutes acceptance of the revised policy.
13. Contact us
Questions about this Privacy Policy or our data practices may be sent to privacy@boltcoi.com. Aleksifa Digital is located in Serbia, Europe.
Compliance assistance, not legal advice. These documents describe how Bolt COI operates; they are not a substitute for counsel on your specific obligations.
