1. Introduction and Scope
1.1. This Privacy Policy (this "Policy") is issued by AgentTech I/O, Inc., a corporation organized and existing under the laws of the State of Nevada ("Company," "we," "us," or "our"). AgentTech I/O, Inc. is a subsidiary of Solved Telephony, which is in turn a subsidiary of Solved Ventures; our corporate affiliates under common control include Solved Enrollment, Solved Marketing, Solved Solutions, and Solved Insurance (collectively, the "Solved Family"). This Policy describes how we collect, use, store, process, share, disclose, and protect information in connection with the AgentTech Dialer platform; the AgentTech 360 platform and each of its workspaces (including Home, CRM, Telephony, Commissions, Contracting, Quote and Enroll, Network, Analytics, Call Marketplace and Routing, and Admin); the AgentTech Dialer mobile app, whether installed as a Progressive Web App or from an app store; white-label tenant domains operated on behalf of our Customers; our website located at agenttech.io, including its contact, demo booking, careers, and newsletter forms; our APIs; and all related services (collectively, the "Service").
1.2. This Policy applies to all users of the Service, including account holders ("Customers"), authorized users and agents ("Authorized Users"), visitors to our website, and any other individuals whose information we collect or process in connection with the Service. Capitalized terms not defined in this Policy shall have the meanings ascribed to them in our Terms of Service, which are incorporated herein by reference.
1.3. By accessing or using the Service, creating an account, or providing information to us, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy and our Terms of Service. If you do not agree to the practices described herein, you must immediately discontinue all use of the Service.
1.4. Our Role. We act in two different capacities, and your rights depend on which one applies:
- As a service provider or processor. Most of the information in the Service is submitted by our Customers, or generated on their behalf, about people who are not our customers: called parties and text recipients, prospective and current policyholders, Producers and their downline agency staff, Payees, and Marketplace counterparties' contacts (collectively, "Customer-Submitted Data," which corresponds to "Customer Data" in the Terms of Service). For Customer-Submitted Data, the Customer (for AgentTech 360, the Tenant Owner) determines the purposes and means of processing, and we process it only on the Customer's documented instructions and as permitted by Section 12 of the Terms of Service. We do not sell it, use it for our own marketing, or use it in identifiable form to train AI models made available to others. If your information was submitted to us by one of our Customers, please direct requests to access, correct, or delete it to that Customer; we will assist the Customer in responding, and Section 10(g) explains how.
- As a business or controller. For account holders and Authorized Users' account and registration information, for visitors to our website, for people who book a demo, contact us, subscribe to our newsletter, or apply for a job, and for billing relationships with our Customers, we determine how the information is used and are directly responsible to you under this Policy.
2. Information We Collect
We collect a broad range of information in connection with the provision, operation, and improvement of the Service. The categories of information we collect include, but are not limited to, the following:
(a) Account and Registration Data
When you create an account or register for the Service, we collect information including: full name; email address; telephone number; National Producer Number (NPN); company or agency name; agency vertical or industry classification; job title or role; login credentials (including username and hashed password); multi-factor authentication settings; account roles and permissions; the Tenant or Tenants to which you belong and your position in each Tenant's agency hierarchy; profile photo, if provided; Slack member ID or similar collaboration identifiers, if you connect them; and account activation status.
(b) Device and Technical Data
When you access or use the Service, we automatically collect technical information including: Internet Protocol (IP) addresses; device fingerprints; user agent strings; browser type, version, and configuration; device type (desktop, mobile, tablet); operating system and version; session identifiers; session data; current page and navigation paths; login timestamps; last activity timestamps; screen resolution; and other technical identifiers and telemetry data.
(c) Call and Telecommunications Data
When calls are placed, received, or processed through the Service, we collect comprehensive call detail records and telecommunications data, including: caller identification numbers (caller ID); called telephone numbers; call direction (inbound, outbound, internal, transfer, conference); call start, answer, and end timestamps; ring duration; talk duration; total call duration; call status and disposition; hangup cause codes; Session Initiation Protocol (SIP) signaling data; call routing and queue information; conference identifiers; call monitoring events; and caller geographic information (state codes).
(d) Call Recording and Transcription Data
The Service records and transcribes calls as configured by the Customer. We collect and process: audio recordings of calls (in multiple file formats); recording metadata including start time, end time, file size, and file hash; recording status and processing information; real-time and post-call transcriptions with speaker identification (agent, caller, system); transcription confidence scores; transcription source provider identifiers; transcription chunk and segmentation data; voicemail recordings and transcriptions; and conference recording data including participant counts and durations.
(e) SMS and Messaging Data
When SMS text messages are sent or received through the Service, we collect: message content (body text); sender and recipient telephone numbers; message direction (inbound, outbound); delivery status (pending, sent, delivered, failed, read); timestamps (sent, delivered, read); message segment counts; messaging costs; conversation thread data; and last message previews.
(f) Email Communications Data
When emails are sent or received through the Service, including through the CRM Conversations inbox, we collect: sender and recipient email addresses; email subject lines; email body content and attachments; delivery status (sent, failed, bounced, opened, clicked); send, open, and click timestamps; email service provider message identifiers; conversation thread data; and error messages for failed deliveries.
(g) Contact and CRM Data
When Customers use the built-in CRM features of the Service, we collect and store: contact first and last names; dates of birth; email addresses; telephone numbers (home, mobile, work); physical mailing addresses (street, city, state, ZIP code, country); company and organization names; job titles; contact notes and annotations; disposition and outcome data; custom field data; contact tags and labels; contact sharing permissions and relationships; avatar or profile image URLs; and all associated interaction history.
(h) Calendar and Scheduling Data
When Customers use the calendar and scheduling features, we collect: event titles and descriptions; event dates and times; event types; participant names, contact types, and contact information; and all-day event flags.
(i) Compliance and Quality Assurance Data
The Service collects and generates compliance-related data, including: platform-level and agency-level compliance analysis results; compliance question responses and scores; compliance carrier information; compliance settings and configurations; AI-generated compliance scores and assessments; and quality assurance metrics and evaluations.
(j) Billing and Financial Data
We collect billing and payment information, including: Stripe customer identifiers and payment processing data; payment transaction records and history; prepaid wallet balances, transaction types (recharge, deduction, adjustment, refund), and transaction history; per-minute billing rates, per-seat pricing, and Tenant or Module fees; usage records for VoIP minutes, SMS, AI transcription, AI Agent voice minutes, AI compliance analysis, Marketplace Campaign charges, and other metered services; billable minute calculations; phone number provisioning costs; Marketplace consolidated invoices and Publisher payment records; and payment method information (processed and stored by our third-party payment processor, Stripe). For Customers that use the Commissions Workspace, we also collect the funding account designation and Payout Processor identifiers used to fund payout cycles. We do not directly store full credit card numbers, debit card numbers, or bank account numbers on our servers; where a Payee's bank account is required to execute a Payout, it is collected and stored by the Payout Processor, and we retain only a tokenized reference and the last four digits.
(k) AI Configuration and AI-Generated Data
When Customers use AI-powered features, we collect and process: AI Voice Agent configurations including system prompts, persona definitions (name, role, company, tone), knowledge base content, qualifying question sets, success and failure criteria, voice model preferences, language settings, temperature parameters, and interaction time limits; transcripts and recordings of calls handled by AI Voice Agents, including answers captured from End Users and warm-transfer briefings; AI Mock Call training session results including overall scores, dimension scores, stage results, compliance violation records, knowledge accuracy assessments, AI-generated feedback summaries, identified strengths and weaknesses, and improvement recommendations; AI training competency items and evaluation criteria; AI compliance rule definitions, scorecards, indicators, analysis profiles, and evaluation prompts; fraud and risk indicator results; conversation stage definitions and behavioral prompts; objection angle configurations; coaching knowledge base entries including trigger keywords, categories, and content; Carrier Statement matching results; and text and classifications extracted from uploaded documents by optical character recognition.
(l) Suppression and Do Not Call Data
We maintain suppression lists containing: telephone numbers that have been suppressed from outbound communications; the agency associated with each suppression; the user who created the suppression; associated notes; and active/inactive status.
(m) Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service and our website and to understand how they are used. See Section 13 (Cookies and Tracking Technologies) for additional details.
(n) Producer and Contracting Data
When a Customer uses the Contracting or Network Workspaces of AgentTech 360, the Customer and its Producers submit, and we retrieve on the Customer's behalf, information about licensed insurance producers, including: full legal name and any prior names; National Producer Number; date of birth; Social Security number or taxpayer identification number; residential and business addresses; email addresses and telephone numbers; state license numbers, license types, lines of authority, license status, and expiration dates; Carrier appointment records by state and line of authority, including appointment dates, terminations, and appointment fees; NIPR Producer Database reports and change alerts; per-Carrier upline and commission-level hierarchy assignments; continuing education and product training records and certificates, including AHIP, anti-money-laundering, annuity suitability, long-term care, and Carrier-specific certifications; errors and omissions insurance carrier, policy number, limits, expiration date, and declaration pages; FINRA CRD number and broker-dealer affiliation; responses to Carrier background questions; background screening reports and results (which are Consumer Reports under the Fair Credit Reporting Act) and related disclosures, authorizations, and adverse action records; Form W-9 information; electronic funds transfer and bank account details for Carrier payments; electronic signatures, including the signer's IP address, timestamp, and consent records; contracting request status and Carrier responses; uploaded documents such as voided checks and signature authorizations, and the text and classifications we extract from them; the derived can-sell status for each Carrier, product, and state; and the Producer's branded-portal login and activity data.
(o) Policy, Enrollment, and Commission Data
When a Customer uses the CRM, Quote and Enroll, Commissions, or Analytics Workspaces, we collect and process: policy records, including policy number, insured and applicant names, dates of birth, addresses, Carrier, product line and plan, premium, effective and issue dates, writing agent, status (sold, submitted, issued, paid, declined, cancelled, lapsed), and the event timeline for each policy; quotes, plan comparisons, and enrollment applications, which may include Medicare Beneficiary Identifiers, Medicare Part A and Part B effective dates, current coverage, prescription and provider information, and other protected health information, processed in conjunction with our affiliate Solved Enrollment; imported Carrier commission and production statements and every line item on them; commission schedules, compensation templates, roles, rules, hierarchies, splits, and overrides; advance, as-earned, and chargeback balances per policy, Payee, and Carrier; payout cycles, payout approvals and the approving user, Payout amounts, statuses, and Payout Processor transaction identifiers; payee statements; and tax reporting information for Payees.
(p) Hierarchy, Tenant, and Role Data
For AgentTech 360 Tenants we maintain: the agency tree, including each agency's name, parent, and depth; each user's memberships across one or more Tenants; role assignments and permission scopes by Agency Path; "view as" aliasing events, including the administrator, the aliased role, and timestamps; Tenant branding, custom domain, and domain verification records; and Tenant provisioning, suspension, and configuration history.
(q) Marketplace and Call Routing Data
When Customers participate in the Marketplace or configure call routing, we collect: Publisher applications and vetting materials, including descriptions of lead sources, consent capture practices and sample consent language, TCPA compliance documentation, and historical performance information; Campaign definitions, including vertical, state coverage, lead type, bid range, cost per call, daily caps, and status; Buyer targets and agency queue subscriptions; per-call routing decisions and SIP signaling; shared performance scorecards, including calls delivered, talk time, agent acceptance, dispositions, AI compliance scores, and disputes; dispute submissions and resolutions; and consolidated billing and Publisher payment records.
(r) Team Chat and Conversations Data
When Authorized Users use Team Chat, we collect channel names and memberships, messages and direct messages, announcements, attachments, reactions, read receipts, and timestamps. Team Chat content is encrypted at rest. When Customers use the CRM Conversations inbox, we collect the inbound and outbound email and SMS threads described in Sections 2(e) and 2(f), associated with the relevant contact record.
(s) Website, Demo Booking, Careers, and Newsletter Data
When you interact with agenttech.io, we collect: contact form submissions, including your name, email address, telephone number, company, the topic you select, and message; demo booking submissions, including your name, email address, telephone number, company, notes, the appointment date and time you select, and the team member assigned to your demo; careers applications, including your name, email address, the position applied for, your answers to screening questions, any note you provide, and any resume or other document you upload; newsletter subscriptions, including your email address, the source of your subscription, and whether and when you open or click our emails; and anti-spam signals such as form timing and honeypot fields. To display demo availability, our scheduling system reads the free/busy status of our team members' connected Google calendars; it does not read calendar content belonging to visitors.
(t) Mobile Application and Push Notification Data
When you install the AgentTech Dialer mobile application, whether as a Progressive Web App or from an app store, we collect: push notification tokens; device model, operating system, and application version; installation and notification permission status; and diagnostic and crash data. Push notification content may include the caller's name or number, a message preview, or a Team Chat excerpt as configured by your Customer.
Sensitive Personal Information
Some of the information described above is "sensitive personal information" under the California Privacy Rights Act and similar laws, including: Social Security and taxpayer identification numbers; driver's license and other government identifiers; bank account and other financial account numbers; account login credentials; health information, including PHI and Medicare identifiers; and the contents of communications where we are not the intended recipient. We collect sensitive personal information only where it is necessary to perform the function a Customer has requested (for example, to complete a Carrier contracting packet, execute a Payout, or process an enrollment), we mask it in the user interface and in exports except for users whose role requires the full value, we do not use it to infer characteristics about individuals, and we do not sell or share it. Section 10(c) describes your right to limit our use of sensitive personal information.
3. How We Use Your Information
We use the information we collect for the following purposes, and for any other purpose consistent with the context in which the information was collected or as otherwise described at the time of collection:
- (a) Providing the Service: To operate, provide, maintain, administer, and deliver the Service, including processing and routing voice calls, SMS messages, voicemail, and email communications;
- (b) Recording and Transcription: To record, transcribe, monitor, and analyze voice calls, voicemail messages, and other communications as configured by the Customer;
- (c) AI Compliance Monitoring: To perform AI-powered compliance scoring, monitoring, alerting, and quality assurance analysis on calls and communications;
- (d) AI Transcription and Coaching: To provide real-time and post-call transcription, AI-powered coaching recommendations, sentiment analysis, and call summarization;
- (e) AI Agent Operations: To operate AI Voice Agents for autonomous inbound and outbound call handling, lead qualification, and warm transfer; AI Mock Calls for agent training; and related AI-powered communication features;
- (f) Billing and Payments: To process payments, manage subscriptions, calculate usage-based charges, manage prepaid wallet balances, generate invoices, administer Marketplace consolidated billing and Publisher payments, and administer billing;
- (g) Customer Support: To respond to inquiries, provide technical support, troubleshoot issues, and resolve disputes, including Marketplace disputes;
- (h) AI Model Development and Training: To develop, train, test, validate, improve, retrain, and refine our artificial intelligence models, machine learning algorithms, and related technologies using De-identified Data only. We do not use identifiable Customer-Submitted Data to train AI models that are made available to other customers or third parties, and we never use protected health information, Consumer Reports, sensitive personal information, financial account or tax identification numbers, or identifiable Commission Data for AI training in any form other than De-identified Data created in accordance with Applicable Law. We may use a Customer's own identifiable data (for example, its scripts, knowledge base, and scorecards) to configure AI features solely for use within that Customer's own account or Tenant;
- (i) De-identified and Aggregated Data: To create and use De-identified Data and Aggregated Data for industry benchmarking, analytics, research, and product development, without attempting to re-identify any individual, Customer, or Tenant;
- (j) Platform Improvement: To analyze usage patterns, conduct internal research, develop new features, improve existing functionality, optimize performance, and enhance the user experience;
- (k) Security and Fraud Prevention: To detect, prevent, investigate, and respond to security incidents, fraud, abuse, and violations of our Terms of Service, and to enforce Tenant isolation and role-based access controls;
- (l) Legal Compliance: To comply with Applicable Law, respond to legal process (including subpoenas, court orders, and regulatory inquiries), cooperate with law enforcement and regulatory authorities, and protect our legal rights;
- (m) Research and Analytics: To conduct internal research, compile benchmarks, generate statistical analyses, and produce de-identified industry reports;
- (n) Marketing Communications: To send promotional offers, product updates, newsletters, and marketing communications to Customers, prospects, and subscribers (subject to your opt-out rights as described in Section 10). We do not send marketing communications to End Users, Producers, or other individuals whose information was submitted by a Customer;
- (o) Enforcement: To enforce our Terms of Service, this Privacy Policy, and any other agreements, and to protect the rights, property, and safety of Company, our customers, and others;
- (p) Commissions and Payouts: On a Customer's instruction, to import and reconcile Carrier Statements against policy records, calculate advance and as-earned compensation and chargebacks according to the Customer's configuration, assemble and present payout cycles for the Customer's approval, transmit approved Payouts to the Payout Processor, generate payee statements, and produce the reports a Customer needs for its tax reporting;
- (q) Contracting and Licensing: On a Customer's instruction, to build a producer profile, retrieve and monitor license and appointment data from NIPR, assemble and validate Carrier contracting packets, collect electronic signatures, transmit packets to Carriers, track appointment status, monitor continuing education, training, errors and omissions coverage, and FINRA status, facilitate background screening through a consumer reporting agency and deliver the disclosures and notices the Customer directs, and derive a can-sell status for routing and quoting;
- (r) Quoting and Enrollment: On a Customer's instruction, to retrieve plan data, generate quotes and comparisons, save quotes to the contact record, check the Producer's appointment status, and hand off to enrollment through our affiliate Solved Enrollment;
- (s) Marketplace Operations: To vet Publisher applicants, list and match Campaigns to agency queues, route Marketplace calls, generate shared performance scorecards, resolve disputes, and administer consolidated billing and Publisher payments;
- (t) Fraud and Risk Indicators: To generate compliance scorecards and fraud and risk indicators that a Customer, and where the Customer directs, its Carriers or FMO, may use as assistive tools to review enrollment risk across their distribution, subject to Section 9.11 of the Terms of Service;
- (u) White-Label Rendering: To render a Customer's Tenant, login pages, Producer portal, and notifications under the Customer's branding and custom domain;
- (v) Demo Scheduling, Newsletter, and Hiring: To schedule and confirm demos, send appointment reminders, deliver newsletters you have subscribed to, evaluate job applications, and communicate with applicants.
4. Legal Basis for Processing
We process personal information under the following legal bases:
- (a) Performance of Contract: Processing necessary for the performance of our contract with you, including providing the Service, processing communications, and managing your account;
- (b) Legitimate Interests: Processing necessary for our legitimate business interests, including platform improvement, AI model training and development, security and fraud prevention, analytics and research, and enforcing our rights, where such interests are not overridden by your fundamental rights;
- (c) Legal Obligations: Processing necessary to comply with our legal obligations, including tax and accounting requirements, regulatory compliance, responding to legal process, and cooperating with law enforcement and regulatory authorities;
- (d) Consent: Where you have provided your consent to specific processing activities, such as marketing communications and certain uses of cookies. Where processing is based on consent, you have the right to withdraw consent at any time, though withdrawal shall not affect the lawfulness of processing conducted prior to withdrawal;
- (e) Customer Instructions: For Customer-Submitted Data, we process on the documented instructions of the Customer, which is responsible for establishing its own legal basis, including any permissible purpose under the Fair Credit Reporting Act for Consumer Reports, any authorization under HIPAA for protected health information, and any consent required for recording, texting, or automated calls.
5. Data Sharing and Disclosure
We may share, disclose, or transfer your information with or to the following categories of recipients, for the purposes described in this Policy:
- Telecommunications Providers: We share call data, caller identification information, and telephone numbers with VoIP and telephony carriers and providers who facilitate the routing, delivery, and processing of voice calls and SMS messages through the Service.
- Payment Processors: We share billing and payment information with Stripe, Inc. and other payment processors for the purpose of processing payments, managing subscriptions, and administering billing.
- Payout Processors and Banks: For Customers that use the Commissions Workspace, we share Payee identity, tax identification, and bank account information, and approved Payout instructions, with the Payout Processor and, through it, the ACH network and the Payee's receiving financial institution, for the purpose of executing Payouts the Customer has approved.
- AI and Machine Learning Service Providers: We share call audio, transcription data, text content, and other data with third-party AI and machine learning service providers, including but not limited to AssemblyAI and xAI, for the purpose of providing transcription, compliance analysis, sentiment analysis, coaching recommendations, AI Voice Agent conversations, document recognition, and other AI-powered features. These providers process data on our behalf under contracts that prohibit them from using it to train their own models or for any purpose other than providing services to us.
- Insurance Carriers: On a Customer's instruction, we transmit contracting packets, appointment requests, Producer Data (including background question responses, training certificates, and errors and omissions details), producer profile changes, and enrollment applications to the Carriers the Customer or its Producers select. Each Carrier's use of that information is governed by the Carrier's own agreements and privacy practices.
- NIPR and State Insurance Departments: On a Customer's instruction, we query and receive Producer license, line-of-authority, appointment, and demographic data from the National Insurance Producer Registry, and may transmit renewal and appointment transactions to NIPR and state insurance departments.
- Consumer Reporting Agencies: Where a Customer requests background screening on a Producer, we transmit the Producer's identifying information and the Customer's disclosure and authorization records to an independent consumer reporting agency and receive the resulting Consumer Report on the Customer's behalf. The consumer reporting agency's own privacy notice governs its processing.
- E-Signature Providers: We share document content, signer identity, and signing events with the e-signature provider used to execute contracting packets and authorizations.
- Errors and Omissions Providers: Where a Producer elects to purchase errors and omissions coverage during contracting, we share the Producer's identifying and licensing information with the third-party licensed insurance producer or Carrier that offers the coverage.
- Solved Family Affiliates: We share information with our corporate affiliates under the common control of Solved Ventures, including our direct parent Solved Telephony and our affiliate Solved Enrollment, which powers the Quote and Enroll Workspace and processes quotes, plan comparisons, and enrollment applications (including protected health information under the applicable Business Associate Agreement) on our behalf. Affiliates may also process information for consolidated billing, security, compliance, and corporate administration. Each affiliate that processes Customer-Submitted Data is bound by obligations at least as protective as this Policy and the Terms of Service.
- Marketplace Counterparties: When a Customer participates in the Marketplace, the shared performance scorecard for each Campaign (calls delivered, talk time, agent acceptance, dispositions, AI compliance scores, and disputes) is visible to both the Publisher and each Buyer of that Campaign. Publishers see the queues that subscribe to their Campaigns; Buyers see the Publisher's vetting status and Campaign economics. Excerpts of recordings or transcripts may be disclosed to a counterparty to the extent necessary to resolve a specific dispute. End User personal information is not shared with a counterparty beyond what is necessary to deliver and account for the call or lead.
- Within a Customer's Hierarchy: In AgentTech 360, information about Producers, calls, policies, and commissions is visible to the Customer's Tenant Owner and to agency administrators and supervisors above the relevant user in the agency hierarchy, according to the roles and permissions the Customer configures. Administrators may also use "view as" aliasing to see the Platform as any role in their downline; these events are logged. If you are a Producer or downline agency user, your upline can see the records within its Agency Path.
- Email and SMS Delivery Providers: We share email addresses, telephone numbers, message content, and delivery data with email and SMS delivery providers, such as SendGrid, Resend, and Amazon SES, for the purpose of delivering transactional and marketing communications.
- Google: Our demo scheduling system uses the Google Calendar API to read the free/busy status of our team members' connected Google accounts and to create, update, and delete demo appointments on their calendars, including sending a calendar invitation to the email address you provide when you book. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to display availability and manage appointments and is never used for advertising or transferred to others except as necessary to provide scheduling.
- Collaboration Tools: Our internal team uses Slack and similar tools to receive notifications about new support tickets, demo bookings, and sales activity. Those notifications may include the name, company, and contact details you provide to us.
- Cloud Infrastructure Providers: We store and process data on servers and infrastructure provided by third-party cloud hosting, storage, content delivery network (CDN), and database service providers located in the United States.
- Compliance Monitoring: We use Vanta to continuously monitor our SOC 2 and HIPAA controls. Vanta receives system configuration, access, and personnel metadata about our own infrastructure and workforce, not Customer-Submitted Data.
- Analytics Providers: We may share usage data and telemetry about the Service with analytics providers for platform performance monitoring, usage analytics, and product improvement. We do not share personal information with advertising networks.
- Professional Advisors: We may disclose information to our legal counsel, auditors, accountants, insurers, and other professional advisors in connection with legal, compliance, audit, and insurance matters, subject to confidentiality obligations.
- Law Enforcement and Regulatory Authorities: We may disclose information (including Customer Data, call recordings, transcriptions, call detail records, account information, and any other data) to governmental authorities, regulatory bodies, law enforcement agencies, and courts: (i) in response to valid legal process, including subpoenas, court orders, search warrants, civil investigative demands, and regulatory inquiries; (ii) as required by Applicable Law; or (iii) voluntarily, where Company in its sole discretion deems disclosure reasonably necessary to protect the safety of any person, prevent fraud or abuse, protect Company's rights or property, or comply with any legal or regulatory obligation. Where the disclosure concerns Customer-Submitted Data, we will notify the Customer unless legally prohibited.
- Business Transfers: In connection with any merger, acquisition, consolidation, reorganization, asset sale, joint venture, financing, bankruptcy, dissolution, or similar corporate transaction involving Company or any member of the Solved Family, Customer Data and all other information may be disclosed, transferred, or assigned to the acquiring or succeeding entity. You acknowledge and agree that any such successor entity shall be bound by this Privacy Policy and shall have the same rights to your data as Company.
- With Your Consent: We may share your information with additional third parties where you have provided your express consent to such sharing.
6. Ownership of Customer Data and Our Limited License
6.1. Customers Own Their Data. As set forth in Section 12 of our Terms of Service, our Customers own the Customer Data they submit to the Service and the Platform Data generated for them, including their call recordings, transcriptions, compliance scorecards, Producer Data, Commission Data, and policy records. Company acquires no ownership interest in Customer Data.
6.2. Our Limited License. Customers grant Company a non-exclusive, royalty-free license, for the subscription term and a limited retention period afterward, to process Customer Data solely as necessary to provide, operate, secure, support, and improve the Service; to prevent fraud and abuse; to comply with Applicable Law; to resolve disputes and enforce our agreements; and to create De-identified Data and Aggregated Data. We may sublicense those rights only to our affiliates and subprocessors to the extent needed for them to perform services for us, under written obligations at least as protective as our own. The license ends when we no longer hold the relevant Customer Data, except for our rights in De-identified Data and Aggregated Data described in Section 6.3.
6.3. De-identified and Aggregated Data. Company owns De-identified Data and Aggregated Data that it creates from Customer Data, together with improvements to the Service and to Company's AI models that do not incorporate identifiable Customer Data. De-identified Data and Aggregated Data are not personal information, are not subject to access, correction, or deletion requests, and may be used for industry benchmarking, analytics, research, and product development. We maintain De-identified Data only in de-identified form, we publicly commit not to attempt to re-identify it, and we contractually prohibit recipients from doing so. Derivative Data that identifies or is linked to a Customer, its users, its Producers, or its End Users remains Customer Data owned by the Customer.
6.4. AI Training. We train and improve our AI models using De-identified Data only. We do not use identifiable Customer Data to train AI models made available to other customers or third parties, and we never use protected health information, Consumer Reports, sensitive personal information, financial account or tax identification numbers, or identifiable Commission Data for AI training except as De-identified Data created in accordance with Applicable Law (including, for protected health information, the de-identification standard of 45 C.F.R. § 164.514). AI model learnings, weights, and parameters derived from De-identified Data are Company's intellectual property.
6.5. Restricted Data Categories. Regardless of any other provision of this Policy, we process protected health information only as permitted by a Business Associate Agreement; Consumer Reports only to deliver them to the Customer that obtained them and store them on the Producer's record for the Customer's permissible purpose; bank account, payment card, and taxpayer identification numbers only to execute Payouts and wallet transactions, satisfy tax reporting, and prevent fraud; Producer Data only to perform the contracting, network, commissions, routing, and enrollment functions a Customer directs; and Commission Data only to perform the commissions and analytics functions a Customer directs, resolve disputes, and comply with law. None of these categories is used for AI training, benchmarking, or marketing in identifiable form.
7. Call Recording, Monitoring, and Transcription
7.1. Recording Disclosure. The Service provides call recording, real-time transcription, AI-powered monitoring, compliance scoring, sentiment analysis, and quality assurance capabilities. All voice calls (including calls handled by AI Voice Agents), voicemail messages, conference calls, SMS and email conversations, Team Chat messages, and other communications processed through the Service may be recorded, transcribed, monitored, and analyzed, both in real-time and post-call, and may be listened to, whispered into, or barged into by supervisors within the Customer's agency hierarchy.
7.2. Customer-Configured Policies. Call recording and retention policies are configurable by the Customer at multiple levels, including global, agency, department, queue, and individual agent levels. Customers may configure recording percentages and retention periods within the Platform. Company has no obligation to verify that Customer-configured recording or retention policies comply with Applicable Law.
7.3. Third-Party Processing. Call recordings and audio data are processed by third-party AI service providers for transcription, speaker identification, compliance analysis, and other AI-powered features. By using the Service, you consent to the transmission and processing of call audio and transcription data by such third-party providers.
7.4. Company Access and Use. Company may access, review, listen to, copy, retain, store, process, and analyze call recordings, transcriptions, voicemail recordings and transcriptions, conference recordings, SMS messages, Team Chat messages, and other communications data solely for the following purposes: (a) providing, operating, securing, supporting, and improving the Service, including performing the transcription, compliance scoring, coaching, and analytics functions a Customer has enabled; (b) quality assurance of the Service; (c) resolving disputes, including Marketplace disputes, and supporting litigation to which Company is a party; (d) safety, security, and fraud prevention; (e) developing, training, testing, and improving AI and machine learning models using De-identified Data only, as described in Section 6.4; (f) creating De-identified Data and Aggregated Data; (g) responding to legal process and regulatory inquiries; and (h) enforcing our Terms of Service. Company personnel access identifiable communications content only on a need-to-know basis, and that access is logged.
7.5. Customer Consent Obligations. Customer is solely and exclusively responsible for obtaining all consents required under applicable federal and state recording consent laws (including one-party and two-party/all-party consent jurisdictions) before recording any call or communication through the Service. Company assumes no liability for Customer's failure to obtain required recording consents.
7.6. AI Voice Agents. If you call or are called by one of our Customers, you may be speaking with an AI Voice Agent rather than a person. AI Voice Agents answer and place calls on the Customer's behalf, ask questions the Customer has configured, record your answers to the Customer's contact record, and may transfer you to a licensed agent along with a transcript of the conversation. Calls with AI Voice Agents are recorded, transcribed, and compliance-scored in the same way as calls with human agents. Our Customers are responsible for disclosing the use of an automated or artificial voice where Applicable Law requires it and for honoring your requests to stop calls. AI Voice Agents are not permitted to sell or enroll you in insurance; those steps are performed only by the Customer's licensed producers.
8. Data Retention
We retain information for the periods described below, or longer where required by Applicable Law, permitted by our Terms of Service, or reasonably necessary to protect our legal interests:
- Account and Registration Data: Retained during the active subscription period and for twenty-four (24) months following termination or expiration of the account, unless longer retention is required by Applicable Law or necessary for the resolution of pending disputes.
- Call Recordings: Retained in accordance with Customer's configured retention policy within the Platform, subject to a minimum retention period of one (1) year regardless of Customer's configuration. Company may retain identifiable copies beyond the Customer's configured period only where needed to resolve a pending dispute, comply with a legal hold or Applicable Law, or complete a compliance review the Customer has requested, and may retain De-identified Data derived from recordings indefinitely.
- Transcriptions: Retained for the same period as the corresponding call recordings. De-identified Data derived from transcriptions may be retained indefinitely for AI model training, research, and analytics purposes.
- Billing and Financial Records: Retained for seven (7) years following the date of the transaction, in accordance with applicable tax, accounting, and financial record-keeping requirements.
- Commission, Payout, and Carrier Statement Records: Retained for seven (7) years following the close of the payout cycle or the statement date, consistent with tax record-keeping requirements and the NACHA Operating Rules, and available for export by the Customer throughout that period and the Export Window described in the Terms of Service.
- Policy and Enrollment Records: Retained for ten (10) years following the policy's termination or the enrollment date, consistent with CMS record retention requirements for Medicare Advantage and Part D enrollment, or for such shorter period as the Customer configures where CMS requirements do not apply.
- Producer and Contracting Records: Producer profiles, license and appointment history, contracting requests, signed packets, training certificates, and errors and omissions records are retained for the duration of the Producer's relationship with the Customer's Tenant and for seven (7) years thereafter, or for such longer period as state insurance producer record-keeping laws require.
- Background Screening Reports: Consumer Reports and related disclosure, authorization, and adverse action records are retained for the period the Customer configures, which defaults to three (3) years after the related contracting decision, and are then disposed of in accordance with the FTC Disposal Rule. Consumer Reports are never retained in De-identified Data or used for any purpose other than the Customer's permissible purpose.
- SMS Messages: Retained for three (3) years from the date of transmission or receipt.
- Team Chat and Conversations Data: Retained for the period the Customer configures, which defaults to the life of the Customer's account plus twenty-four (24) months.
- Compliance and Quality Assurance Data: Retained for ten (10) years, consistent with CMS Medicare record retention requirements and industry best practices for regulatory compliance documentation.
- Marketplace Vetting and Scorecard Data: Retained for the duration of the participant's Marketplace participation and for four (4) years thereafter, consistent with the limitations period for claims under the TCPA.
- Hierarchy, Role, and Audit Data: Retained for the life of the Tenant and for seven (7) years thereafter, so that access and aliasing history remains available for audits and disputes.
- Session and Login Data: Retained for two (2) years from the date of the session or login event.
- Website, Demo Booking, Newsletter, and Applicant Data: Retained for twenty-four (24) months after your last interaction with us or, for newsletter subscribers, until you unsubscribe plus a suppression record so that we do not contact you again. Applicant data may be retained longer where required by employment law or where you ask us to consider you for future roles.
- Google Calendar Tokens: OAuth tokens for team members' connected Google accounts are stored encrypted and deleted when the account is disconnected. Free/busy data is cached for no more than thirty-five (35) days.
- Mobile Push Tokens: Retained until the application is uninstalled, notifications are disabled, or the token is invalidated by the platform.
- AI Configuration and Tenant-Specific AI Data: AI Voice Agent configurations, knowledge bases, scorecards, and AI Mock Call results are Customer Data retained for the life of the Customer's account and the Export Window, then deleted with the rest of the account.
- De-identified Data and Aggregated Data: Retained indefinitely. De-identified Data and Aggregated Data are not personal information and are not subject to access, correction, or deletion requests; Derivative Data that identifies a Customer or individual follows the retention period of its source category.
- Suppression and DNC Data: Retained for the duration of the applicable suppression period and for two (2) years thereafter for compliance verification purposes.
Company reserves the right to retain any information for such additional periods as may be required by Applicable Law, ordered by a court or regulatory authority, or reasonably necessary to establish, exercise, or defend legal claims, enforce our agreements, or protect Company's legitimate business interests.
9. Data Security
9.1. Security Measures. We implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, disclosure, alteration, and destruction. Our security measures include, but are not limited to: encryption of data in transit using Transport Layer Security (TLS 1.2 or higher); encryption of data at rest using Advanced Encryption Standard (AES-256) or equivalent, including for call recordings, transcriptions, CRM data, Team Chat messages, and stored OAuth tokens; cryptographic hashing of authentication credentials; Tenant isolation enforced at the database layer; role-based access controls scoped to the agency hierarchy, with least-privilege defaults; masking of Social Security numbers, taxpayer identification numbers, and Medicare Beneficiary Identifiers in the user interface and in exports; multi-factor authentication and single sign-on capabilities; IP allow-lists for supervisor tools; signed, replay-protected webhooks and scoped API keys; handling of payment card data exclusively by a PCI DSS Level 1 processor; an audit trail of logins, recording playback, exports, aliasing events, and configuration changes; continuous dependency scanning, a fixed patch cadence, and at least annual independent penetration testing; and incident response procedures. Our SOC 2 program (security, availability, and confidentiality) and our HIPAA program are monitored continuously through Vanta, and current reports and our Business Associate Agreement are available to Customers and prospects under a non-disclosure agreement.
9.2. Breach Notification. In the event of a data security breach involving the unauthorized acquisition of unencrypted personal information that triggers notification obligations under Applicable Law, Company shall notify affected individuals and applicable regulatory authorities as required by the Nevada data breach notification statute (NRS 603A.220), the Florida Information Protection Act (Fla. Stat. § 501.171), the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400 through 164.414) where protected health information is involved, and any other applicable federal or state breach notification laws. Company shall notify affected Customers within seventy-two (72) hours of confirming a reportable breach affecting their Customer-Submitted Data so that they can meet their own notification obligations, and shall notify affected individuals and authorities within the timeframe required by Applicable Law.
9.3. Disclaimer. While we implement reasonable security measures, no method of transmission over the Internet, no method of electronic storage, and no security system is impenetrable or guaranteed to be completely secure. We cannot and do not guarantee the absolute security of your information. You acknowledge that you transmit information to and through the Service at your own risk and that Company shall not be liable for any unauthorized access, use, or disclosure of your information except to the extent directly caused by Company's gross negligence or willful misconduct.
10. Your Privacy Rights
(a) General Rights (All Users)
Subject to the limitations set forth in this Section 10 and in our Terms of Service, all users may: (i) request access to the categories and specific pieces of personal information we have collected about them; (ii) request correction of inaccurate personal information; (iii) request deletion of personal information (subject to applicable exceptions and Company's retention rights); and (iv) opt out of promotional marketing communications by following the unsubscribe instructions in such communications or by contacting us at privacy@agenttech.io.
(b) Nevada Residents (NRS 603A.345)
If you are a Nevada resident, you have the right to submit a verified request directing us not to sell your personal information. We do not sell personal information as defined under Nevada Revised Statutes Chapter 603A. To submit a request, contact us at privacy@agenttech.io with the subject line "Nevada Privacy Request."
(c) California Residents (CCPA/CPRA)
If you are a California resident, you may have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you, taking into account the nature of the information and the purposes of processing.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions under the CCPA, including where retention is necessary for: performing our contract with you; complying with legal obligations; exercising or defending legal claims; internal uses reasonably aligned with your expectations; and other purposes permitted under the CCPA.
- Right to Opt Out of Sale or Sharing: You have the right to opt out of the "sale" or "sharing" of your personal information, as those terms are defined under the CCPA. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use advertising pixels or third-party advertising cookies on agenttech.io or in the Service. If our practices change, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism before doing so.
- Right to Limit Use of Sensitive Personal Information: We use sensitive personal information only for the purposes permitted by the CCPA without a right to limit, namely to perform the services a Customer has requested, to prevent fraud and security incidents, and to comply with law, as described in the Sensitive Personal Information callout in Section 2. We do not use or disclose sensitive personal information to infer characteristics about you. If you believe we are using your sensitive personal information for another purpose, you may ask us to limit that use by contacting privacy@agenttech.io.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Authorized Agents: You may designate an authorized agent to submit a request on your behalf. We will require the agent to provide proof of your written authorization and may require you to verify your identity directly with us.
Global Privacy Control: We treat a Global Privacy Control (GPC) signal from your browser as a valid request to opt out of any sale or sharing of personal information associated with that browser, as required by the CCPA and the privacy laws of Colorado, Connecticut, and other states. Because we do not sell or share personal information, honoring the signal does not change how the Service operates for you.
CCPA Business Exemptions: Certain categories of information we process may be exempt from the CCPA, including: (i) personal information reflecting a written or verbal business-to-business communication or transaction; (ii) personal information collected about a person acting in their capacity as an employee, officer, director, or contractor of a company, partnership, sole proprietorship, or government agency; and (iii) personal information processed by a service provider on behalf of a business pursuant to a written contract. Where we process Customer-Submitted Data as a service provider, the Customer is the "business" responsible for responding to your request, as described in Section 10(g). Job applicants and Authorized Users of our Customers are covered by the CCPA and may exercise the rights above with respect to information we hold as a business.
(d) Other State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Kentucky, Maryland, Minnesota, and other states with applicable consumer privacy laws may exercise privacy rights as provided under those laws. To submit a request, contact us at privacy@agenttech.io and specify your state of residence.
(e) Exercising Your Rights
To exercise any of the rights described in this Section 10, submit a request to privacy@agenttech.io. We will verify your identity before processing your request. We will respond to verifiable requests within forty-five (45) calendar days of receipt, or within such other timeframe as required by Applicable Law. If we require additional time, we will notify you of the extension and the reason therefor. We may decline requests where we are unable to verify your identity, where the request is manifestly unfounded or excessive, or where processing the request is not required under Applicable Law.
(f) Limitations on Deletion Rights
Your deletion rights are subject to the following limitations: (i) Company may retain and continue to use De-identified Data and Aggregated Data after a deletion request is processed, because they are not personal information; (ii) AI models trained on De-identified Data cannot be untrained, but no identifiable personal information is contained in them; (iii) deletion requests apply to identifiable personal information that is not required for legal compliance, contract performance, dispute resolution, security, or the retention periods described in Section 8, and where you are an End User, Producer, or other individual whose information was submitted by a Customer, the Customer's instructions and legal obligations (including insurance, tax, and CMS record-keeping requirements) determine what may be deleted; (iv) Company may retain copies of data as required by Applicable Law, including regulatory record-keeping requirements and legal holds; and (v) data that has been transmitted at a Customer's direction to Carriers, NIPR, consumer reporting agencies, Payout Processors, or other recipients is subject to those recipients' separate retention practices. Deletion of your personal information from our active systems does not constitute immediate deletion from backup systems; backup data is overwritten in the ordinary course of operations.
(g) Individuals Whose Information Was Submitted by Our Customers
If you are a called party or text recipient, a prospective or current policyholder, a licensed producer or downline agency user, a Payee, or another person whose information was placed in the Service by one of our Customers, the Customer is responsible for your information and for responding to your requests, and we act as its service provider. To exercise your rights: (i) contact the insurance agency, FMO, or call center you dealt with, which can identify you in its account and instruct us; (ii) if you do not know which Customer holds your information, email privacy@agenttech.io with the telephone number or email address involved and we will forward your request to the Customer within ten (10) business days, or tell you that we could not locate a matching record; and (iii) where a Customer instructs us to fulfil your request, we will do so within the time required by Applicable Law. If a background screening report was obtained on you through the Service, you have separate rights under the Fair Credit Reporting Act, including the right to receive a copy of the report and a summary of your rights from the Customer before any adverse action is taken, and the right to dispute inaccurate information directly with the consumer reporting agency identified in that notice; we will provide you the name and contact details of that agency on request. If you are a Producer who has left a Customer's network, you may request a copy of your own licensing, appointment, training, and payee statement records by emailing privacy@agenttech.io, and we will provide it to the extent permitted by the Customer's instructions and Applicable Law.
11. Children's Privacy
The Service is not directed at, marketed to, or intended for use by individuals under the age of eighteen (18). We do not knowingly collect, solicit, or receive personal information from children under the age of eighteen (18). If we become aware that we have collected personal information from a child under eighteen (18) without verification of parental consent, we will take commercially reasonable steps to promptly delete such information from our records. If you believe that we have collected personal information from a child under eighteen (18), please contact us immediately at privacy@agenttech.io.
12. International Data Transfers
12.1. The Service is operated from, and all data is processed and stored on servers located in, the United States of America. If you access or use the Service from a location outside the United States, you acknowledge and agree that your information will be transferred to, processed, and stored in the United States, where data protection laws may differ from and may be less protective than the laws of your jurisdiction.
12.2. By accessing or using the Service, you expressly and irrevocably consent to the transfer, processing, and storage of your information in the United States in accordance with this Privacy Policy and our Terms of Service. We do not represent or warrant that the Service or our data practices comply with the data protection or privacy laws of any jurisdiction other than the United States. If you do not consent to the transfer of your information to the United States, you must not access or use the Service.
13. Cookies and Tracking Technologies
13.1. Types of Cookies. We use the following categories of cookies and similar tracking technologies:
- Strictly Necessary Cookies: Essential for the operation of the Service, including session management, authentication, cross-site request forgery protection, security, and load balancing. These cookies cannot be disabled without impairing the functionality of the Service.
- Analytics and Performance Data: We may collect first-party information about how users interact with the Service and our website, including pages visited, features used, error occurrences, and performance metrics, to improve the Service and optimize the user experience. We do not use third-party advertising analytics on agenttech.io.
- Preference and Functionality Cookies: Used to remember your settings, preferences, and choices (such as language preferences and display configurations) to provide a more personalized experience.
- Third-Party Resources: Our website loads icon fonts and similar static assets from third-party content delivery networks. Those providers receive your IP address and user agent as a technical necessity of serving the file; we do not permit them to set advertising cookies. We do not use third-party advertising cookies, pixels, or tracking for cross-context behavioral advertising.
13.2. Managing Cookies. You may control and manage cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling certain cookies may impair the functionality of the Service. For more information about cookies and how to manage them, visit www.allaboutcookies.org.
14. Do Not Track and Global Privacy Control Signals
14.1. Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to interpret and respond to DNT signals, the Service does not currently alter its data collection and use practices in response to DNT signals alone.
14.2. We do honor the Global Privacy Control (GPC) signal. Where your browser or extension transmits a GPC signal, we treat it as a request to opt out of the sale or sharing of personal information associated with that browser, as described in Section 10(c). Because we do not sell or share personal information, honoring the signal does not change how the Service operates for you.
15. Changes to This Privacy Policy
15.1. We reserve the right to modify, amend, or update this Privacy Policy at any time, in our sole discretion. When we make material changes to this Policy, we will update the "Last updated" date at the top of this page and provide not less than thirty (30) days' advance notice to registered users via email or in-platform notification.
15.2. Your continued access to or use of the Service after the effective date of any changes to this Privacy Policy shall constitute your acceptance of and agreement to the revised Policy. If you do not agree to any changes, your sole and exclusive remedy is to terminate your account and discontinue use of the Service prior to the effective date of such changes.
15.3. Prior versions of this Privacy Policy are available upon written request to privacy@agenttech.io.
16. Contact Information
If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:
Legal Entity: AgentTech I/O, Inc., a Nevada corporation
Privacy Inquiries: privacy@agenttech.io
Legal Inquiries: legal@agenttech.io
Phone: +1 (866) 415-6192
Mailing Address: AgentTech I/O, Inc., Attn: Privacy, Tampa, Florida (full street address available on request to privacy@agenttech.io)
Registered Agent: As on file with the Nevada Secretary of State