How Keel Technologies, Inc. collects, uses, shares, and protects information when you use our benefits enrollment platform and related services.
Keel Technologies, Inc. ("Keel," "we," "us," or "our") provides a broker-branded benefits platform. Brokers and employers use Keel to run open enrollment; the employees they sponsor use Keel to compare plans, model costs, ask questions, and submit their elections. This Privacy Policy describes how we handle information when you visit our website at keelbenefits.com (the "Site"), when you use the Keel application at app.keelbenefits.com or at a broker- or employer-branded subdomain of keelbenefits.com (the "Platform"), and when you otherwise interact with Keel.
Keel is based in the United States and our infrastructure is hosted in the United States. References to "you" in this policy include site visitors, broker users, employer administrators, and plan participants — the employees and dependents whose information we process in connection with the Platform.
For most of what we do with plan participant information, we act on the instructions of our customer — the broker or employer that sponsors the benefits program. That customer decides what data reaches us and why. Where you have a question we cannot answer without their direction, we will route it to them.
When a broker or employer engages Keel, they direct us to receive information about the employees and dependents they sponsor. This usually arrives through a connection to their HR or payroll system, or by direct upload. It may include:
Keel does not connect to insurance carriers, and we do not receive information from them.
Keel does not receive claims files, explanations of benefits, prescription records, or diagnoses. We do not accept them, and our customer agreements forbid sending them to us. But choosing a health plan means telling us something about your health situation, and some of what you tell us is consumer health data under Washington's My Health My Data Act, Nevada's SB 370, and similar state laws. This section is our account of that data. It applies in addition to the rest of this policy, and it controls where the two conflict.
All of it comes directly from you, in the Platform. We do not buy consumer health data, we do not infer it from third-party sources, and we do not receive it from carriers, pharmacies, or providers.
We use consumer health data for one purpose: to produce benefits guidance for you — plan comparisons, cost estimates, eligibility results, a plan recommendation, and answers to the questions you ask. That is the whole list. Specifically:
Where the law requires your consent before we collect consumer health data, we ask for it in the Platform — before the questionnaire or your first conversation with Amanda begins, and separately from any other agreement you are asked to accept.
Not every question is optional:
You may withdraw your consent at any time, and you may ask us to delete your consumer health data. Withdrawal is prospective: it stops further collection and use. Deletion removes your questionnaire answers, your conversation transcripts, and the summary derived from them, and we will pass the deletion request on to the subprocessors described in Section 3.4 that hold any of it. If you withdraw or delete, Amanda loses the context behind any guidance she has already given, so we may no longer be able to show you a personalized recommendation — your elections and your coverage are unaffected.
To withdraw consent, request deletion, or ask what consumer health data we hold about you, email [email protected]. We will confirm your identity using information we already hold, and we will respond within the timeframe the applicable law requires. We will not discriminate against you for exercising any of these rights.
We do not sell personal information, we do not use plan participant information for advertising, and we do not share it for cross-context behavioral advertising.
Amanda is Keel’s AI adviser. She talks with plan participants over web chat, SMS, email, voice, and video.
Keel captures elections; it does not transmit them to carriers. At the close of enrollment, Keel produces a submission report and per-carrier export files. Your broker and an employer administrator review and approve them, and the broker uploads them into the employer's benefits administration system — most often Employee Navigator — or a carrier's own portal. That system, not Keel, transmits enrollment to the carriers and drives payroll deductions.
Keel has no direct connection to any insurance carrier. We do not send enrollment, eligibility, or premium files to carriers, and we do not submit evidence-of-insurability applications on your behalf.
Where your employer asks us to, we write benefit deduction amounts back to their payroll system through that provider.
We engage a small number of vendors to operate the Platform on our behalf. They are bound by contracts requiring them to protect information consistent with this policy and to use it only to provide their service to us. Their categories are in Section 7, and we name them on request.
We may disclose information if we believe in good faith that doing so is necessary to comply with applicable law, regulation, legal process, or a lawful governmental request; to enforce our agreements; or to detect, prevent, or address fraud, security, or technical issues. Where law permits, we will give a customer notice and an opportunity to seek a protective order before responding to compulsory legal process directed at that customer's data.
If Keel is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service to another provider, information may be transferred as part of that transaction. Any acquirer remains bound by the commitments in this policy — including those in Section 3 — for information collected before the transfer, and we will use commercially reasonable efforts to notify customers of any material change in how their information is handled.
We will share information for any other purpose we disclose to you at the time we collect it, or with your consent.
We engage a small number of vendors to operate the Platform on our behalf: for infrastructure, for artificial intelligence, for communications, and for connectivity to our customers’ HR and payroll systems. All of them process information in the United States. Each is bound by contract to protect it consistent with this policy and to use it only to provide its service to us.
We provide the current list, naming each vendor, to customers and prospective customers on request at [email protected], and we give customers advance notice of a new subprocessor as our agreements require.
We keep information for as long as it is needed to provide the Platform to the customer whose benefits program it belongs to, and afterwards only for as long as that customer’s agreement and applicable law require. Conversation transcripts are kept for the conversation and the summary drawn from it, and are then deleted. On termination we return or delete customer data as the customer’s agreement provides.
Where we hold information to resolve a dispute or meet a legal obligation, we keep it for that purpose and no other. To ask what we hold about you, contact [email protected].
Where we handle protected health information on behalf of an employer’s group health plan, we do so under a Business Associate Agreement, and that agreement governs the information rather than this policy. We sign a Business Associate Agreement where our customer or its plan requires one.
Keel maintains a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the information it holds. That program includes encryption in transit and at rest, separation of each customer’s data from every other customer’s, controls on who may reach production data, and a documented incident response process. We will notify affected customers and individuals of a security incident as applicable law and our customer agreements require.
No security measure is perfect. If you believe your account, or any account at Keel, may have been compromised, contact [email protected] without delay.
Your employer or broker decides what information about you reaches Keel and why. You can exercise your privacy rights through them, and they may direct us to act. You can also come to us directly using the contact details in Section 15 — we will verify who you are and either handle the request or route it to your employer or broker and support them in answering it.
For your questionnaire answers and your conversations with Amanda, you can come straight to us: see Section 3.5.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to ask us to (i) disclose the categories and specific pieces of personal information we hold about you, (ii) delete personal information we have collected, (iii) correct inaccurate personal information, and (iv) limit the use and disclosure of sensitive personal information. You have the right not to be discriminated against for exercising these rights.
We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not knowingly process the personal information of consumers under sixteen (16) years of age.
To exercise a right, email [email protected]. We will verify your request against information we already hold and may need to ask for more to confirm your identity. You may use an authorized agent, who must provide written authorization we can verify.
Washington residents (My Health My Data Act) and Nevada residents (SB 370) have specific rights in their consumer health data — to know what we collect and who receives it, to withdraw consent, and to have it deleted. Section 3 is written to serve those rights; Section 3.5 tells you how to use them. Washington's law also gives residents a private right of action.
Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws have rights similar to those in Section 11.2. To exercise them, follow the process there.
If you are in the EEA, the UK, or Switzerland and the General Data Protection Regulation, UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing, you have the right to access, rectify, erase, restrict, port, or object to our processing of your personal data, and you may lodge a complaint with your local supervisory authority. Where Keel acts as a processor for a customer, direct your request to that customer first. Where Keel acts as a controller, contact us at [email protected].
Most browsers let you control cookies in their settings. If you block cookies, some Platform features may not work as expected. We honor Global Privacy Control (GPC) signals as a valid opt-out request where applicable law recognizes them. We do not respond to the older "Do Not Track" browser setting, for which no industry standard was established.
You can opt out of marketing email by following the unsubscribe instructions in any marketing message, or by contacting [email protected]. We will still send the transactional and service messages needed to operate the Platform and run your enrollment.
Keel is based in the United States and our infrastructure is hosted in the United States. If you access the Platform from outside the United States, your information will be transferred to, stored in, and processed in the United States. Where we transfer personal data from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, and the Swiss Addendum, as applicable, supported by the additional safeguards described in our security documentation (available on request).
The Platform is not directed to children under sixteen (16), and we do not knowingly collect personal information directly from them. Information about a dependent child — a name, a date of birth, a Social Security number, a relationship — reaches us from the employer, the broker, or a parent or guardian acting through the enrollment experience, so the child can be enrolled in coverage.
Dependent information is provided under the authority of the enrolling parent or guardian, is used solely for enrollment, eligibility, and the administration of the coverage it was provided for, is protected with the same field-level encryption as adult data, and is never used to train AI models. A parent or guardian can review or correct a dependent’s information at any time through the enrollment experience, through their employer, or by contacting us at the address in Section 15.
We may update this policy from time to time. Each version carries a version string (this one is v2026-09-07) and a "Last updated" date. If we make a material change — in particular, any change to Section 3 — we will post the updated policy at this URL, update the version, and notify customers in writing or through the Platform. Where the law requires your fresh consent for a new use of consumer health data, we will ask for it before that use begins, not by quietly amending this page.
Questions about this policy, or about how we handle your information:
Keel Technologies, Inc.
[email protected]