Privacy Policy
IU2 Technology LLC · INSUREU2 Corp · ScaleU2 · and All Affiliated Brands
Part 1. Introduction and Scope
1.1 About This Policy
IU2 Technology LLC, a Delaware Limited Liability Company, INSUREU2 Corp, a Wyoming Corporation, ScaleU2, and all affiliated brands, entities, subsidiaries, divisions, and related organizations operating under the INSUREU2 ecosystem, including without limitation INSUREU2, INSUREU2 AI, IU2 Technology, ScaleU2, INSUREU2 Marketing, INSUREU2 Leads, INSUREU2 CRM, INSUREU2 Merch, Craig's Insurance Agency (dba of Cbender Innovations Corp), and all future brands, products, platforms, and entities that may be developed, acquired, launched, or operated by any affiliated entity (collectively, "Company," "we," "us," or "our"), present this Privacy Policy ("Policy") to describe how the Company collects, uses, processes, discloses, retains, protects, and otherwise handles personal information across the entire INSUREU2 ecosystem.
This Policy applies to all websites, web applications, software platforms, mobile applications, artificial intelligence systems, SaaS products, marketing services, lead generation services, staffing services, virtual assistant services, consulting services, CRM platforms, media and content services, merchandise operations, referral programs, partner programs, and all other products, services, technologies, and business operations of the Company, including all future offerings that may be introduced under any INSUREU2-affiliated brand, domain, platform, or entity (collectively, the "Services").
By accessing or using any Service, visiting any Company website or platform, submitting information to the Company, or engaging with the Company in any capacity, you acknowledge that you have read and understood this Policy and consent to the collection, use, processing, and disclosure of personal information as described herein.
1.2 Ecosystem Coverage
This Policy is designed to govern the entire INSUREU2 ecosystem, including all current and future brands, entities, platforms, products, services, technologies, integrations, and business lines operated by or affiliated with the Company. References to "Company," "we," "us," or "our" throughout this Policy refer collectively to all entities, brands, and operations within the INSUREU2 ecosystem unless the context requires otherwise. The Company reserves the right to extend the coverage of this Policy to future entities, brands, products, and services as the ecosystem grows and evolves, without requiring a complete redrafting of this Policy.
1.3 Controller and Processor Distinction
The Company operates in two distinct capacities with respect to personal information depending on the context:
(a) Data Controller. The Company acts as an independent data controller when it collects and processes personal information directly from website visitors, prospective customers, registered users, account holders, marketing contacts, job applicants, business partners, referral partners, and others for its own business purposes, including account management, marketing, communications, product improvement, security, and internal operations.
(b) Data Processor. The Company acts as a data processor when it processes personal information on behalf of enterprise customers, agencies, carriers, organizations, and other business clients pursuant to applicable Master Services Agreements, Order Forms, Statements of Work, and Data Processing Addenda. In this capacity, the applicable customer is the data controller and bears sole responsibility for the lawfulness of personal information submitted to the Services and for obtaining all required consents and authorizations from individuals whose personal information is submitted. The Company's processing activities as a data processor are governed by the applicable Data Processing Addendum.
1.4 Technology Provider Status
The Company is a technology company, insurance technology provider, marketing services company, staffing services company, and business solutions provider. The Company is not an insurance carrier, insurance producer, insurance broker, managing general agent, managing general underwriter, claims adjuster, third-party administrator, law firm, accounting firm, compliance consultant, registered investment advisor, or any other licensed professional service provider in any jurisdiction unless separately licensed and expressly disclosed. This Policy does not address the privacy practices of the Company's enterprise customers, who are solely responsible for their own privacy compliance obligations with respect to their policyholders, insureds, customers, employees, and other individuals.
1.5 Customer Responsibility Allocation
Enterprise customers, agencies, carriers, organizations, and other business clients that use the Services to collect, process, transmit, or otherwise handle personal information about their own customers, employees, prospects, leads, or other individuals are solely responsible for:
- (a) ensuring that all personal information submitted to the Services has been collected lawfully and with all required consents and authorizations;
- (b) providing all required privacy notices to individuals whose personal information is submitted to the Services;
- (c) complying with all applicable privacy laws, data protection laws, insurance regulations, telemarketing laws, recording consent laws, and professional standards governing their collection, use, and disclosure of personal information;
- (d) obtaining all required consents for call recording, call monitoring, transcription, and communication processing;
- (e) ensuring that their submission and processing of personal information through the Services complies with all applicable regulatory requirements; and
- (f) ensuring that no personal information is submitted to the Services that the customer does not have the legal right to submit and process.
The Company does not provide privacy compliance advice. All enterprise customers are strongly encouraged to retain independent legal and compliance counsel to assess their specific privacy obligations.
1.6 Geographic Scope
The Company currently operates in the United States, Canada, and the Philippines, and may expand operations to Europe, Latin America, Asia-Pacific, and other regions as the business grows. This Policy applies to all personal information processed by the Company regardless of the geographic location of the individual whose information is processed, subject to the applicable legal requirements of each jurisdiction.
1.7 Future Products and Services
The Company is a growing technology ecosystem that continuously develops, acquires, licenses, and launches new products, services, platforms, technologies, brands, and business lines. This Policy is drafted to accommodate future growth and is intended to apply to all future products, services, platforms, and entities within the INSUREU2 ecosystem without requiring complete redrafting. The Company will update this Policy as materially new data processing activities are introduced.
Part 2. Information We Collect
2.1 Overview
The Company collects personal information from multiple sources and in multiple contexts across its ecosystem of products, services, platforms, and operations. The categories of personal information we collect depend on how you interact with the Services, the nature of your relationship with the Company, and the information submitted by enterprise customers on behalf of their personnel and end users. The Company collects personal information that is reasonably necessary to operate, deliver, maintain, improve, and expand the Services, fulfill contractual and legal obligations, support legitimate business interests, and comply with applicable law.
2.2 Information Provided Directly
The Company collects personal information that individuals, users, customers, and business representatives provide directly, including:
- (a) Account and Registration Information. Name, job title, employer or agency name, business email address, business phone number, username, password, professional license numbers, carrier appointments, and other information provided during account creation, registration, or profile setup across any Company platform.
- (b) Business and Professional Information. Company name, business address, business type, industry, professional credentials, licensing information, carrier relationships, agency information, and other professional details provided in connection with using or applying for any Service.
- (c) Billing and Payment Information. Billing name, billing address, payment method details, and transaction records associated with purchases of SaaS subscriptions, professional services, marketing services, staffing services, lead purchases, merchandise purchases, consulting services, training programs, or any other Company product or service. Full payment card numbers are processed by third-party payment processors and are not stored by the Company.
- (d) Contact and Communication Information. Information provided when contacting the Company by email, phone, web form, chat, support portal, or any other means, including the content, metadata, and attachments of such communications.
- (e) Onboarding and Configuration Information. Business information, operational information, workflow preferences, system configuration data, integration preferences, and related information provided during onboarding, implementation, or platform configuration for any Company product or service.
- (f) Training, Support, and Meeting Information. Information provided or discussed during training sessions, onboarding calls, support interactions, product demonstrations, webinars, workshops, or operational review meetings, including information captured in recordings of such sessions where recording consent has been obtained.
- (g) Marketing and Lead Generation Information. Information submitted through contact forms, landing pages, lead capture forms, demo request forms, event registrations, newsletter subscriptions, referral submissions, and other marketing and lead generation activities.
- (h) Survey and Feedback Information. Responses to surveys, product feedback submissions, feature requests, testimonials, reviews, and other voluntary input provided to the Company.
- (i) Staffing and Recruiting Information. Resumes, work history, professional qualifications, references, interview responses, compensation expectations, and other information provided by or about individuals in connection with the Company's staffing, virtual assistant, recruiting, and BPO services.
- (j) Merchandise and E-Commerce Information. Name, shipping address, billing address, product preferences, and order details provided in connection with merchandise purchases through any Company e-commerce platform.
2.3 Information Collected Automatically
When individuals access or use the Services, visit Company websites, or interact with Company platforms and applications, the Company and its service providers automatically collect certain technical, behavioral, and usage information, including:
- (a) Device and Browser Information. Device type, device model, operating system and version, browser type and version, browser language, screen resolution, device identifiers, hardware configuration, and related device characteristics.
- (b) Log and Network Data. IP address, access timestamps, pages and features accessed, duration of access, referring URLs, exit pages, error logs, network connection type, and related network and session data.
- (c) Usage and Behavioral Data. Feature usage patterns, session duration and frequency, click-stream data, navigation paths, search queries within the Services, actions taken within the platform, interaction data, and other behavioral data generated through use of the Services.
- (d) Performance and Diagnostic Data. Platform performance metrics, API response times, error rates, system diagnostic data, and related technical performance information.
- (e) Location Data. General geographic location derived from IP address. Precise device location is not collected without separate disclosure and applicable consent.
- (f) CRM and Pipeline Data. Interaction history, account status, lead stage, pipeline data, and related customer relationship management data generated through use of Company CRM features.
2.4 Customer Data Submitted to the Services
Enterprise customers, agencies, carriers, organizations, and other business clients may submit personal information about their own customers, employees, leads, prospects, policyholders, insureds, and other individuals to the Services in connection with their use of the platform ("Customer Data"). Customer Data may include without limitation:
- (a) names, contact information, demographic data, and insurance profile information of the customer's policyholders, insureds, leads, or prospects;
- (b) call recordings, call monitoring data, audio content, and communication logs;
- (c) call transcriptions, conversation analyses, and AI-generated summaries;
- (d) documents, files, policy documents, applications, forms, and other materials uploaded to the Services;
- (e) CRM data, account data, pipeline data, and customer relationship information;
- (f) quality assurance data, performance scores, and personnel evaluation data relating to the customer's employees and agents;
- (g) lead data, live transfer data, and consumer matching data processed through lead services; and
- (h) any other personal information submitted by the customer in connection with any Service.
The Company processes Customer Data on behalf of and under the direction of the applicable enterprise customer acting as the data controller. Enterprise customers are solely responsible for the lawfulness of Customer Data, the obtainment of all required consents, and compliance with all applicable privacy and data protection law. The Company's processing of Customer Data in its capacity as a data processor is governed by the applicable Data Processing Addendum.
2.5 Call Recordings, Transcriptions, and Communication Data
The Services include call recording, call monitoring, and transcription capabilities across multiple product lines. In connection with these capabilities:
- (a) audio recordings of telephone calls, live transfers, and other voice communications may be captured, processed, and stored by the Services and associated service providers;
- (b) AI-powered speech-to-text transcription systems automatically generate text transcriptions of recorded calls and communications;
- (c) conversation intelligence systems analyze transcriptions and recordings to generate quality assurance scores, performance metrics, summaries, recommendations, and other analytical outputs;
- (d) audio recordings may or may not be retained depending on the applicable product configuration, service tier, customer settings, and storage arrangements;
- (e) enterprise customers are solely and exclusively responsible for obtaining all legally required consents from all call participants prior to any recording or monitoring; and
- (f) the Company's provision of recording and transcription capabilities does not constitute legal advice regarding applicable recording consent laws, and the Company makes no representation that any customer's recording practices comply with applicable law.
2.6 AI System Inputs
The Services incorporate artificial intelligence systems that receive and process various types of inputs to generate outputs, recommendations, summaries, guidance, and analytical results. AI system inputs may include without limitation: text queries and conversational inputs submitted by users; call transcriptions and communication content; documents and files uploaded to the platform; CRM data and account information; knowledge base content configured by customers; interaction data; and other information submitted to or generated through the Services. The processing of such inputs by AI systems is described further in Part 5 of this Policy.
2.7 Information from Third Parties
The Company may receive personal information from third parties in connection with its operations, including:
- (a) referral partners, channel partners, affiliate partners, and strategic partners who introduce prospective customers to the Company;
- (b) lead generation partners, lead providers, and consumer matching services;
- (c) data enrichment and data append services that supplement account or contact information;
- (d) technology integration partners whose platforms connect with Company systems;
- (e) publicly available sources, including business directories, professional networks, and public records; and
- (f) marketing platforms, advertising networks, and analytics providers that provide audience data and attribution information.
Part 3. Cookies and Tracking Technologies
3.1 Overview
The Company and its authorized service providers use cookies, pixel tags, tracking pixels, web beacons, software development kits (SDKs), local storage, browser storage, session storage, device identifiers, advertising identifiers, and similar tracking technologies (collectively, "Tracking Technologies") across its websites, platforms, applications, and marketing properties to collect information, personalize experiences, measure performance, support marketing activities, and improve the Services.
3.2 Categories of Cookies
The Company uses the following categories of cookies:
- (a) Strictly Necessary Cookies. These cookies are essential for the operation of Company websites and platforms, including authentication, session management, security, and access control functions. These cookies cannot be disabled without impairing core functionality of the Services.
- (b) Functional and Preference Cookies. These cookies remember your preferences, settings, language selections, and account configurations to provide a more personalized experience across Company platforms.
- (c) Analytics and Performance Cookies. These cookies collect information about how users interact with Company websites and platforms, including pages visited, features accessed, time spent, errors encountered, and navigation paths. This information is used to improve platform performance and user experience.
- (d) Marketing and Advertising Cookies. These cookies are used to deliver targeted advertisements, measure advertising effectiveness, support retargeting campaigns, track conversion events, and support the Company's digital marketing activities across third-party platforms and advertising networks.
- (e) Session Cookies. Temporary cookies that expire when a browser session ends. Used for authentication, session continuity, and security purposes.
- (f) Persistent Cookies. Cookies that remain on your device for a set period to remember preferences, support returning user experiences, and support marketing attribution.
3.3 Specific Tracking Technologies
The Company may utilize the following categories of tracking technologies, among others:
- (a) Web Analytics Platforms including Google Analytics and Google Tag Manager for website traffic analysis, user behavior measurement, and campaign performance tracking;
- (b) Advertising Pixels including the Meta Pixel and LinkedIn Insight Tag for audience building, advertising measurement, retargeting, and conversion tracking across social media and advertising platforms;
- (c) CRM Tracking Technologies including HubSpot tracking and related CRM analytics for lead tracking, pipeline management, and marketing attribution;
- (d) Session Analytics and Heatmapping Tools for recording user sessions, generating heatmaps, analyzing user interactions, and identifying usability improvements;
- (e) Conversion Tracking Tools for measuring the effectiveness of advertising campaigns and marketing activities;
- (f) Advertising Attribution Systems for tracking the source and effectiveness of customer acquisition activities; and
- (g) such additional tracking technologies as the Company may deploy from time to time as business needs evolve.
The Company reserves the right to add, modify, or replace tracking technologies at any time without prior notice, subject to applicable legal requirements.
3.4 Third-Party Tracking
Third-party vendors and advertising networks may use their own cookies and tracking technologies when you interact with Company websites, platforms, or advertisements. The Company does not control the data collection practices of third-party tracking technologies. Third-party tracking is subject to the applicable third-party privacy policies, and the Company encourages users to review those policies.
3.5 Managing Cookie Preferences
You may manage cookie preferences through the following mechanisms:
- (a) Browser Settings. Most browsers allow you to refuse cookies, delete existing cookies, or receive alerts when cookies are placed. Browser-level cookie controls may impair certain features of Company websites and platforms.
- (b) Cookie Management Tools. Where required by applicable law, the Company may provide a cookie consent management tool through which you can manage non-essential cookie preferences.
- (c) Opt-Out Links. For interest-based advertising, you may opt out through applicable industry opt-out mechanisms, including the Network Advertising Initiative opt-out tool and the Digital Advertising Alliance opt-out tool.
- (d) Platform-Level Controls. Certain advertising platforms, including Google and Meta, provide user-level controls for advertising preferences through their respective account settings.
Please note that disabling certain cookies may impair the functionality, performance, or availability of certain features of the Services.
3.6 Do Not Track
Some browsers transmit "Do Not Track" signals to websites. The Company's current practices may not respond uniformly to Do Not Track signals due to the lack of a standardized industry or legal definition. The Company will adjust its practices as required by applicable law.
Part 4. How We Use Information
4.1 Service Delivery and Operations
The Company uses personal information to deliver, operate, maintain, support, configure, and improve the Services across the entire INSUREU2 ecosystem, including:
- (a) creating, managing, and maintaining user accounts and organizational accounts across all Company platforms;
- (b) processing transactions, managing subscriptions, and administering billing across all product and service lines;
- (c) delivering AI-powered features including Real-Time Guidance, Conversation Intelligence, Call Summaries, Knowledge Base Search, Workflow Assistance, CRM Automation, and all other AI-powered outputs;
- (d) providing customer support, technical assistance, onboarding services, training, and implementation services;
- (e) operating lead generation, live transfer, consumer matching, and lead distribution services;
- (f) delivering marketing services, social media management, content creation, video production, advertising campaigns, and related media services;
- (g) providing staffing, virtual assistant, BPO, call center, appointment setting, and administrative support services;
- (h) delivering consulting, operational improvement, sales training, and technology implementation services;
- (i) processing merchandise orders and managing e-commerce operations;
- (j) operating referral programs, affiliate programs, partner programs, and channel partner programs; and
- (k) fulfilling all contractual obligations to enterprise customers, partners, and individual users.
4.2 AI System Operations
The Company uses information to operate, maintain, monitor, improve, train, and develop its AI systems and automated processing capabilities, including:
- (a) processing inputs submitted to AI systems to generate requested outputs, recommendations, summaries, scores, and guidance;
- (b) using anonymized and aggregated interaction data, transcription data, and usage data to improve AI model accuracy, relevance, performance, and capability;
- (c) using anonymized and aggregated data to develop new AI features, capabilities, and product offerings;
- (d) monitoring AI system performance, identifying errors, addressing biases, and improving output quality;
- (e) developing, testing, and refining Prompt Libraries, knowledge architectures, retrieval systems, and AI-powered methodologies; and
- (f) training, retraining, fine-tuning, and evaluating AI models using appropriately anonymized and aggregated data.
The Company does not use personally identifiable Customer Data to train AI models without appropriate anonymization or without applicable authorization.
4.3 Marketing and Business Development
The Company uses personal information to support marketing, sales, and business development activities, including:
- (a) communicating with prospective and existing customers about Services, features, promotions, industry news, and other information;
- (b) sending marketing emails, SMS marketing messages, newsletters, and promotional communications;
- (c) conducting retargeting campaigns and interest-based advertising across digital platforms;
- (d) managing lead generation, lead nurturing, and sales pipeline activities;
- (e) measuring the effectiveness of marketing campaigns and optimizing marketing spend;
- (f) conducting customer satisfaction surveys and gathering product feedback; and
- (g) supporting referral program and partner program operations.
4.4 Security, Fraud Prevention, and Abuse Detection
The Company uses personal information and technical data to protect the security, integrity, and availability of the Services and to detect, investigate, and prevent fraud, abuse, and unauthorized access, including:
- (a) monitoring platform activity for anomalous, suspicious, or unauthorized behavior;
- (b) detecting, investigating, and responding to security incidents and potential data breaches;
- (c) verifying account authenticity and preventing unauthorized account access;
- (d) identifying and preventing abuse, misuse, and policy violations;
- (e) conducting internal security audits and compliance reviews; and
- (f) protecting the rights, property, and safety of the Company, its customers, and others.
4.5 Product Improvement and Research
The Company uses information, including usage data, performance data, and aggregated and de-identified data, to continuously improve, develop, and expand the Services and to conduct research and development activities, including:
- (a) analyzing user interaction patterns to identify product improvements and new features;
- (b) developing new platforms, modules, integrations, AI capabilities, and product lines;
- (c) conducting quality assurance, testing, and performance optimization;
- (d) developing industry benchmarks, research publications, and market analyses using aggregated and de-identified data; and
- (e) evaluating the effectiveness and suitability of the Services for different industries, use cases, and customer segments.
4.6 Legal, Compliance, and Regulatory Purposes
The Company uses personal information as necessary to comply with applicable laws and regulations, respond to lawful governmental requests and legal process, enforce its legal rights and agreements, protect against legal claims, and fulfill obligations under applicable insurance, financial, employment, privacy, and other regulatory frameworks.
4.7 Staffing and Recruiting Operations
The Company uses personal information submitted in connection with staffing, virtual assistant, BPO, and recruiting services to: identify and evaluate candidates; manage placement and deployment activities; fulfill staffing obligations to enterprise customers; administer employment and contractor relationships; and comply with applicable employment and labor laws.
4.8 Internal Business Operations
The Company uses personal information for general internal business purposes, including financial management, accounting, tax compliance, legal and compliance administration, investor relations, internal reporting, and operational planning.
Part 5. Artificial Intelligence and Automated Processing Disclosures
5.1 AI Processing Overview
The INSUREU2 ecosystem is built on a foundation of artificial intelligence and automated processing technologies. The Company's AI systems process various types of personal information and business data to generate outputs, recommendations, summaries, guidance, scores, analyses, and other AI-powered results across multiple product lines. This Part 5 describes the Company's AI and automated processing activities and establishes the framework of responsibility applicable to such activities.
5.2 AI Technologies Deployed
The Company deploys artificial intelligence and automated processing technologies including without limitation: large language models; natural language processing systems; speech recognition systems; real-time guidance engines; conversation intelligence systems; automated decision support systems; knowledge retrieval and search systems; CRM automation systems; workflow automation systems; analytics platforms; business intelligence systems; quality assurance scoring systems; and such additional AI and automated processing technologies as the Company may deploy from time to time as the ecosystem evolves.
5.3 AI Input Processing
AI systems within the INSUREU2 ecosystem may process the following categories of information as inputs:
- (a) call recordings, audio content, and voice data submitted for transcription and analysis;
- (b) call transcriptions and conversation text generated through transcription services;
- (c) documents, files, contracts, policies, applications, forms, and other content uploaded by customers and users;
- (d) text queries, conversational inputs, search queries, and prompts submitted by users;
- (e) CRM data, account information, lead data, and customer relationship information;
- (f) knowledge base content configured and populated by enterprise customers;
- (g) interaction data and usage data generated through platform activity; and
- (h) any other information submitted to or generated through the Services that is processed by AI systems to fulfill a requested function.
5.4 AI Output Generation
AI systems generate outputs based on processed inputs across multiple product lines, including without limitation: real-time guidance suggestions delivered during live customer interactions; call summaries and transcription analyses; conversation intelligence scores and quality assurance metrics; knowledge base search results and content recommendations; objection handling suggestions and sales guidance; workflow automation recommendations; CRM automation outputs; lead scoring and qualification results; analytics and reporting outputs; and other AI-generated results. AI outputs may contain information derived from or referencing personal information submitted as inputs.
5.5 AI Training and Model Development
The Company may use anonymized, aggregated, and de-identified data — including anonymized interaction data, anonymized call transcription data, anonymized usage data, and anonymized platform performance data — to train, retrain, evaluate, fine-tune, and improve AI models and systems. The Company does not use personally identifiable Customer Data for AI training purposes without appropriate anonymization or without the applicable enterprise customer's authorization as set forth in the applicable Data Processing Addendum. All AI model improvements, enhancements, and derivative works resulting from training activities constitute the Company's intellectual property.
5.6 AI Output Disclaimer and Limitations
AI outputs generated by the Company's systems are produced by probabilistic machine learning systems and are subject to significant limitations. AI outputs may be inaccurate, incomplete, misleading, outdated, internally inconsistent, or otherwise incorrect. AI outputs do not constitute professional advice of any kind, including without limitation legal advice, insurance advice, compliance advice, regulatory advice, tax advice, financial advice, underwriting advice, or coverage guidance. All AI outputs require mandatory human review and independent verification by qualified personnel before being relied upon, acted upon, communicated to any third party, or used in any professional, regulatory, or legal context. The Company does not warrant the accuracy, completeness, reliability, or suitability of any AI output for any purpose.
5.7 Automated Processing and Decision Support
Certain features of the Services involve automated processing of personal information to generate scores, recommendations, classifications, or guidance. Such automated processing is provided as decision support only and does not constitute automated decision-making that produces binding legal or similarly significant effects on individuals without human involvement, except to the extent expressly disclosed in connection with a specific product feature. Enterprise customers are solely responsible for ensuring that their use of automated processing features complies with all applicable laws governing automated decision-making, including without limitation applicable employment laws, insurance regulatory requirements, and consumer protection laws.
5.8 Customer Responsibility for AI-Related Data
Enterprise customers are solely responsible for:
- (a) ensuring that all data submitted to AI systems has been collected lawfully and with all required consents and authorizations under applicable law;
- (b) ensuring that their use of AI outputs complies with all applicable laws, regulations, carrier requirements, and professional standards;
- (c) implementing and maintaining appropriate supervisory, review, and verification procedures for all AI outputs before use or reliance;
- (d) obtaining all legally required consents for call recording, monitoring, and transcription activities that generate inputs to AI systems;
- (e) ensuring that AI-assisted customer interactions comply with all applicable insurance regulatory requirements, telemarketing laws, consumer protection laws, and professional licensing obligations; and
- (f) not representing AI outputs as the product of human professional judgment to any customer, regulatory authority, or in any legal proceeding without independent human review and verification.
5.9 AI Regulatory Compliance Disclaimer
The Company does not represent or warrant that any AI feature, AI output, or AI-assisted workflow satisfies any specific regulatory requirement applicable to any enterprise customer's business or industry. Enterprise customers are solely responsible for ensuring that their use of AI features complies with all applicable regulatory requirements, including without limitation insurance AI regulations, employment AI regulations, consumer protection requirements, anti-discrimination laws, and privacy laws. Regulatory requirements applicable to AI use are evolving rapidly, and the Company encourages all enterprise customers to consult qualified independent legal and compliance counsel regarding their AI-related compliance obligations.
Part 6. Aggregated and De-Identified Data
6.1 Company Rights to Aggregated Data
The Company reserves perpetual, irrevocable, worldwide, royalty-free rights to collect, generate, compile, process, analyze, use, retain, and commercialize aggregated, anonymized, de-identified, and statistical data derived from personal information, Customer Data, usage data, interaction data, platform performance data, and other information processed through the Services, from which all personally identifiable information has been removed and from which no individual or enterprise customer can reasonably be identified ("Aggregated Data").
6.2 Permitted Uses of Aggregated Data
The Company may use Aggregated Data for any lawful purpose without restriction, including without limitation:
- (a) training, retraining, evaluating, fine-tuning, and improving AI models, machine learning systems, and automated processing capabilities;
- (b) developing new products, features, platforms, integrations, services, and technologies;
- (c) generating industry benchmarks, market analyses, research publications, and business intelligence reports;
- (d) improving the performance, accuracy, reliability, and security of the Services;
- (e) conducting internal research and development activities;
- (f) supporting business planning, strategic development, and investor reporting;
- (g) developing and publishing anonymized industry insights and trend analyses; and
- (h) any other lawful internal or commercial purpose that does not identify any individual or enterprise customer.
6.3 Ownership of Aggregated Data
Aggregated Data constitutes the Company's intellectual property. Aggregated Data is not subject to confidentiality obligations, data subject rights requests, or deletion requirements under this Policy. Enterprise customers have no ownership interest in Aggregated Data derived from their use of the Services.
6.4 No Restriction on Future Use
The Company's rights to generate and use Aggregated Data are not restricted by the termination or expiration of any customer agreement. The Company may retain and continue to use Aggregated Data after any customer relationship ends, indefinitely and without limitation.
Part 7. How We Share Information
7.1 General Principle
The Company does not sell personal information to unaffiliated third parties for monetary consideration in the traditional sense. The Company shares personal information only as described in this Policy, as required or permitted by applicable law, or as authorized by the applicable enterprise customer or individual.
7.2 Service Providers and Subprocessors
The Company shares personal information with third-party service providers, vendors, contractors, subprocessors, and technology partners engaged to assist in the delivery, operation, maintenance, security, and improvement of the Services and Company business operations. Categories of service providers include without limitation:
- (a) cloud infrastructure, data hosting, storage, computing, networking, and database service providers;
- (b) artificial intelligence infrastructure and large language model API service providers;
- (c) telecommunications, telephony, voice routing, and call management service providers;
- (d) communications, SMS, and messaging service providers;
- (e) CRM, marketing automation, and sales enablement platforms;
- (f) analytics, monitoring, observability, and performance tracking service providers;
- (g) payment processing and billing service providers;
- (h) email marketing, newsletter, and marketing automation platforms;
- (i) advertising networks and digital marketing platforms;
- (j) session analytics, heatmapping, and user behavior analytics providers;
- (k) security monitoring, threat detection, and vulnerability management providers;
- (l) identity verification and authentication service providers;
- (m) meeting recording, transcription, and communication analysis providers;
- (n) data enrichment and audience intelligence providers;
- (o) legal, accounting, tax, and professional advisory service providers; and
- (p) staffing, recruiting, and workforce management platforms.
All service providers and subprocessors are authorized to use personal information only as necessary to provide services to the Company and are subject to contractual data protection obligations appropriate to the nature of the services provided. A current Subprocessor List is available upon request.
7.3 Affiliated Entities
The Company may share personal information among affiliated entities, brands, subsidiaries, and related organizations within the INSUREU2 ecosystem for purposes consistent with this Policy, including for service delivery, sales, marketing, account management, customer support, product development, and internal operations. Affiliated entities include without limitation IU2 Technology LLC, INSUREU2 Corp, ScaleU2, Cbender Innovations Corp, and all future affiliated entities operating within the INSUREU2 ecosystem.
7.4 Referral and Channel Partners
In connection with referral programs, affiliate programs, channel partner programs, and strategic partnerships, the Company may share limited business contact information with referral and channel partners for purposes of program coordination, lead management, and commission administration. Such sharing is governed by applicable program terms and confidentiality agreements.
7.5 Business Transfers
In the event of a merger, acquisition, consolidation, sale of all or substantially all of the Company's assets, reorganization, bankruptcy, or other business transaction involving any entity within the INSUREU2 ecosystem, personal information may be transferred to the acquiring or successor entity as part of the transaction. The Company will provide notice of any such transfer as required by applicable law. Following any such transfer, personal information will continue to be subject to a privacy policy that provides protections at least as protective as this Policy.
7.6 Legal Compliance and Protection
The Company may disclose personal information when it reasonably believes disclosure is required or permitted by law, including:
- (a) in response to a valid subpoena, court order, legal process, search warrant, or other governmental request;
- (b) to comply with applicable federal, state, local, or international laws, regulations, or regulatory obligations;
- (c) to protect the rights, property, or safety of the Company, its customers, employees, partners, or the public;
- (d) to detect, prevent, or respond to fraud, security incidents, abuse, or violations of Company policies;
- (e) to enforce the Company's legal rights, agreements, and policies; or
- (f) in connection with legal proceedings, regulatory investigations, or dispute resolution.
7.7 With Consent
The Company may share personal information with third parties when the applicable individual or enterprise customer has provided express written consent or authorization for such sharing, in addition to what is described in this Policy.
7.8 Aggregated and De-Identified Information
The Company may share Aggregated Data and de-identified information that does not identify any individual or enterprise customer with third parties, including business partners, research organizations, investors, and industry participants, for analytics, benchmarking, research, marketing, and business development purposes without restriction.
7.9 No Sale of Personal Information
The Company does not sell personal information as that term is defined under the California Consumer Privacy Act, the California Privacy Rights Act, or analogous state privacy laws, in exchange for monetary consideration. To the extent the Company engages in any sharing of personal information for cross-context behavioral advertising that may constitute a "sale" or "sharing" under applicable law, the Company provides applicable opt-out rights as described in Part 11 of this Policy.
Part 8. Data Retention
8.1 Retention Principles
The Company retains personal information for as long as reasonably necessary to fulfill the purposes for which it was collected as described in this Policy, to maintain and improve the Services, to comply with applicable legal and regulatory obligations, to resolve disputes, to enforce agreements, and to support the Company's legitimate business interests. Retention periods vary across the INSUREU2 ecosystem depending on the category of information, the applicable product or service, the nature of the customer relationship, and applicable legal requirements.
8.2 Account and Customer Information
Personal information associated with active user accounts and enterprise customer accounts is retained for the duration of the applicable customer relationship and for a reasonable period thereafter as necessary for legal, compliance, audit, tax, accounting, dispute resolution, and business continuity purposes. The specific post-termination retention period may vary based on applicable legal requirements and the nature of the customer relationship.
8.3 Customer Data
Customer Data submitted to the Services by enterprise customers is retained in accordance with the applicable Master Services Agreement, Order Form, and Data Processing Addendum. Following expiration or termination of the applicable agreement, the Company will make Customer Data available for export in accordance with the applicable agreement terms and will thereafter process deletion in accordance with the Company's standard data lifecycle procedures, subject to applicable legal hold and retention requirements.
8.4 Call Recordings and Transcriptions
The retention of audio recordings depends on the applicable product configuration, service tier, customer settings, and infrastructure arrangements. Transcriptions and AI-generated outputs derived from calls and communications are retained in accordance with the applicable service configuration and agreement terms. Enterprise customers are solely responsible for retaining any recordings, transcriptions, or communication records required by applicable law, regulation, carrier requirements, or compliance obligations.
8.5 Marketing and Lead Data
Personal information collected in connection with marketing activities, lead generation, and business development is retained for as long as reasonably necessary to support ongoing marketing, sales, and customer relationship activities, subject to applicable opt-out rights and applicable law.
8.6 Staffing and Recruiting Information
Personal information collected in connection with staffing, virtual assistant, BPO, and recruiting services is retained for as long as necessary to fulfill the applicable staffing engagement, to support future placement opportunities where applicable, and to comply with applicable employment, labor, and tax law requirements.
8.7 Usage and Technical Data
Usage data, log data, analytics data, and technical performance data may be retained for security monitoring, fraud prevention, compliance, product improvement, and analytics purposes for periods determined by the Company in accordance with applicable law and business requirements.
8.8 Aggregated and De-Identified Data
Aggregated and de-identified data that does not identify any individual or enterprise customer may be retained indefinitely for analytics, AI improvement, research, benchmarking, business intelligence, and product development purposes without restriction.
8.9 Legal Holds
Notwithstanding any standard retention period described in this Policy, the Company may retain personal information for longer periods as required by applicable legal hold obligations, regulatory requirements, pending or anticipated litigation, governmental investigation, or audit requirements. Legal hold obligations take precedence over standard deletion schedules.
Part 9. Security
9.1 Security Program
The Company maintains a comprehensive information security program designed to protect personal information and Customer Data against unauthorized access, use, disclosure, alteration, and destruction. The Company's security program encompasses administrative, technical, and physical safeguards calibrated to the nature, scope, and sensitivity of the information processed and the risks associated with the Services. The Company does not publicly disclose the specific tools, architectures, configurations, vendor identities, or technical specifications of its security controls, as such disclosure could compromise the effectiveness of those controls and create security risks.
9.2 Security Measures Generally
The Company's security program includes, without limitation, the following categories of controls, the specific implementation of which the Company does not publicly disclose:
- (a) encryption of personal information in transit and at rest using industry-recognized standards;
- (b) access controls and role-based permissions limiting access to personal information to authorized personnel with a legitimate business need;
- (c) multi-factor authentication requirements for access to production systems and sensitive data environments;
- (d) security monitoring, logging, and anomaly detection capabilities;
- (e) vulnerability assessment and patch management processes;
- (f) network security controls and perimeter defenses;
- (g) data segregation controls separating customer data environments;
- (h) endpoint security measures for systems used to access personal information;
- (i) employee security awareness training and confidentiality obligations;
- (j) incident response planning and procedures;
- (k) business continuity and disaster recovery planning; and
- (l) vendor security assessment and contractual security requirements for subprocessors and service providers.
9.3 Third-Party Security Standards
The Company engages infrastructure providers, cloud service providers, and subprocessors that may maintain industry security certifications and compliance frameworks, which may include SOC 2, ISO 27001, PCI DSS, HIPAA-related safeguards, and GDPR compliance frameworks, depending on the applicable provider. The Company does not guarantee that all third-party providers maintain any specific certification at all times, and certification status may vary by provider and service.
9.4 No Absolute Security Guarantee
No security system is impenetrable, and the Company cannot guarantee the absolute security of personal information. The transmission of information over the internet and through telecommunications networks involves inherent security risks beyond the Company's control. The Company shall not be liable for any security incident, data breach, or unauthorized access that occurs despite the implementation of commercially reasonable security measures, except to the extent required by applicable mandatory law.
9.5 Customer Security Responsibilities
Enterprise customers and users are responsible for implementing appropriate security measures on their side of the Services, including without limitation:
- (a) maintaining the confidentiality of all account credentials, API keys, and access tokens;
- (b) enabling and using multi-factor authentication where available;
- (c) promptly revoking access for personnel whose authorization has been terminated;
- (d) promptly reporting any suspected unauthorized access or security incident to the Company;
- (e) implementing appropriate endpoint security for devices used to access the Services; and
- (f) ensuring that data submitted to the Services is transmitted securely and in compliance with applicable requirements.
9.6 Security Incident Notification
In the event of a confirmed security incident involving unauthorized access to or disclosure of personal information, the Company will notify affected enterprise customers and applicable regulatory authorities as required by applicable data breach notification laws and the terms of the applicable Data Processing Addendum. Notifications will be provided in accordance with applicable legal requirements. The Company's notification of a security incident does not constitute an acknowledgment of fault or liability.
Part 10. International Data Transfers
10.1 Cross-Border Data Transfers
The Company operates across multiple jurisdictions, including the United States, Canada, and the Philippines, with planned expansion to Europe, Latin America, and Asia-Pacific. Personal information collected in connection with the Services may be transferred to, stored in, and processed in the United States and other countries where the Company, its affiliates, or its service providers maintain operations. Such countries may have data protection laws that differ from, and may provide less protection than, the laws of the country in which the individual resides.
10.2 United States as Primary Processing Location
The Company's primary data processing operations are located in the United States. Personal information transferred to and processed in the United States is subject to U.S. federal and state laws. The Company processes such information in accordance with this Policy and applicable law.
10.3 EU and EEA Transfers
To the extent the Company transfers personal data from the European Economic Area to the United States or any other country that has not received an adequacy decision from the European Commission, the Company will implement appropriate transfer safeguards as required by GDPR, which may include:
- (a) standard contractual clauses approved by the European Commission;
- (b) binding corporate rules where applicable;
- (c) reliance on applicable adequacy decisions; or
- (d) such other lawful transfer mechanisms as may be available under applicable GDPR provisions.
Enterprise customers subject to GDPR that require documentation of applicable transfer mechanisms should contact the Company using the information provided in Part 17.
10.4 UK Transfers
To the extent the Company transfers personal data from the United Kingdom, the Company will implement appropriate transfer safeguards as required by UK GDPR and the UK Data Protection Act 2018, which may include the International Data Transfer Agreement approved by the UK Information Commissioner's Office or such other lawful transfer mechanisms as may be available.
10.5 Canadian Transfers
To the extent the Company transfers personal information subject to Canadian privacy law, including PIPEDA and applicable provincial privacy laws, the Company implements appropriate contractual safeguards for such transfers and provides notification as required by applicable law.
10.6 Philippines Operations
The Company maintains staffing and BPO operations in the Philippines. Personal information processed in connection with Philippine operations is subject to applicable Philippine data protection law, including the Data Privacy Act of 2012, and is handled in accordance with this Policy and applicable law.
10.7 Transfer Documentation
Enterprise customers requiring specific transfer documentation, including standard contractual clauses or transfer impact assessments, should contact the Company at the contact information provided in Part 17 or through the applicable Data Processing Addendum process.
10.8 Future Jurisdictions
As the Company expands into additional geographic markets, the Company will implement appropriate data transfer mechanisms for new jurisdictions as required by applicable law.
Part 11. Privacy Rights
11.1 Overview
Applicable privacy law may grant individuals certain rights with respect to their personal information. The rights available to any individual depend on the applicable jurisdiction, the nature of the personal information, the capacity in which the Company processes such information, and applicable exceptions under law. Rights described in this Part 11 may be subject to limitations, conditions, verification requirements, and exceptions under applicable law. The Company will respond to privacy rights requests in accordance with applicable legal requirements.
11.2 California Privacy Rights (CCPA / CPRA)
California residents may have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- (a) Right to Know. The right to request information about the categories of personal information collected, the sources of collection, the business or commercial purposes for collection, the categories of third parties with whom personal information is shared, and the specific pieces of personal information collected about you.
- (b) Right to Delete. The right to request deletion of personal information the Company has collected about you, subject to applicable exceptions, including without limitation the exception for information necessary to complete a transaction, detect security incidents, comply with legal obligations, or fulfill other legally recognized purposes.
- (c) Right to Correct. The right to request correction of inaccurate personal information maintained by the Company, taking into account the nature of the information and the purposes of processing.
- (d) Right to Opt Out of Sale or Sharing. The right to opt out of the sale of personal information or the sharing of personal information for cross-context behavioral advertising. As described in Section 7.9, the Company does not sell personal information for monetary consideration.
- (e) Right to Limit Use of Sensitive Personal Information. The right to direct the Company to limit its use and disclosure of sensitive personal information to uses reasonably necessary to perform the Services, subject to applicable exceptions under CPRA.
- (f) Right to Non-Discrimination. The right not to receive discriminatory treatment for exercising any CCPA or CPRA privacy right.
- (g) Right to Opt Out of Automated Decision-Making. To the extent the Company engages in profiling in furtherance of decisions that produce legal or similarly significant effects on California residents, the right to opt out of such profiling, subject to applicable exceptions.
To exercise California privacy rights, please submit a verifiable consumer request using the contact information in Part 17. The Company will respond to verifiable requests within forty-five (45) days of receipt, with the option to extend the response period by an additional forty-five (45) days where reasonably necessary upon notice to you.
11.3 GDPR and UK GDPR Rights
To the extent the Company processes personal data subject to the General Data Protection Regulation or the UK General Data Protection Regulation, data subjects may have the following rights:
- (a) Right of Access (Article 15 GDPR). The right to obtain confirmation of whether the Company processes personal data about you and to receive a copy of such personal data, together with supplementary information about the processing.
- (b) Right to Rectification (Article 16 GDPR). The right to have inaccurate personal data corrected and incomplete personal data completed without undue delay.
- (c) Right to Erasure (Article 17 GDPR). The right to have personal data deleted in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where consent is withdrawn, or where the data has been unlawfully processed.
- (d) Right to Restriction of Processing (Article 18 GDPR). The right to restrict the Company's processing of personal data in certain circumstances, including while accuracy is contested or while an objection is being considered.
- (e) Right to Data Portability (Article 20 GDPR). The right to receive personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where processing is based on consent or contract and is carried out by automated means.
- (f) Right to Object (Article 21 GDPR). The right to object to processing based on legitimate interests or for direct marketing purposes. Where personal data is processed for direct marketing, the right to object is absolute.
- (g) Rights Related to Automated Decision-Making (Article 22 GDPR). The right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, except where such processing is necessary for a contract, authorized by law, or based on explicit consent.
- (h) Right to Lodge a Complaint. The right to lodge a complaint with the applicable supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement, or with the UK Information Commissioner's Office for UK GDPR matters.
Where the Company processes personal data as a data processor on behalf of an enterprise customer, data subject requests regarding Customer Data should be directed to the applicable enterprise customer who acts as the data controller. The Company will assist enterprise customers in responding to data subject requests in accordance with the applicable Data Processing Addendum.
The Company will respond to GDPR and UK GDPR requests within thirty (30) days of receipt, with the option to extend by an additional two (2) months for complex or numerous requests upon notice.
11.4 Virginia, Colorado, Connecticut, Texas, and Other U.S. State Rights
Residents of Virginia, Colorado, Connecticut, Texas, Nevada, and other states with enacted consumer data privacy legislation may have rights substantially similar to those described in Section 11.2, including rights of access, correction, deletion, portability, and opt-out of targeted advertising and profiling. The Company will respond to requests from residents of applicable states in accordance with applicable law. Response timeframes and available exceptions may vary by jurisdiction.
11.5 Canadian Privacy Rights
Individuals in Canada whose personal information is subject to PIPEDA or applicable provincial privacy laws may have rights of access, correction, and complaint. To exercise such rights, please contact the Company using the information provided in Part 17.
11.6 Submitting Privacy Requests
To exercise any applicable privacy right, please contact the Company using the contact information provided in Part 17. Privacy requests may be submitted by:
- (a) email to the privacy contact address;
- (b) written request by mail to the mailing address; or
- (c) through any privacy request portal or online form that the Company may make available.
The Company may require verification of your identity before processing any privacy request to ensure that requests are made by or on behalf of the individual whose information is at issue. Verification requirements may vary based on the sensitivity of the information and the nature of the request. The Company reserves the right to deny requests that cannot be verified or that are subject to applicable legal exceptions.
11.7 Authorized Agents
California residents may designate an authorized agent to submit privacy requests on their behalf. Authorized agents must provide written authorization from the consumer and may be required to verify their own identity separately. The Company may contact the consumer directly to verify the authorized agent's authorization.
11.8 Exceptions and Limitations
Privacy rights are subject to exceptions and limitations under applicable law. The Company reserves the right to deny privacy requests, in whole or in part, where applicable law permits such denial, including without limitation where the information is necessary to complete a transaction, detect security incidents, debug errors, comply with legal obligations, exercise legal claims, protect free speech rights, conduct research in the public interest, or fulfill other legally recognized purposes.
Part 12. Industry-Specific Privacy Disclosures
12.1 Insurance Industry
The INSUREU2 ecosystem serves insurance agencies, insurance carriers, MGAs, MGUs, wholesalers, brokers, captive agencies, independent agencies, and other insurance industry participants. The following disclosures are relevant to insurance industry operations:
(a) Technology Provider Status. The Company is an insurance technology provider only. The Company is not an insurance carrier, insurance producer, broker, adjuster, MGA, MGU, or any other licensed insurance entity in any jurisdiction unless separately disclosed. The Company's privacy practices described in this Policy apply solely to the Company's activities as a technology and services provider and do not address the privacy practices of enterprise customers, who are solely responsible for their own privacy compliance obligations under applicable insurance privacy laws.
(b) Insurance Privacy Regulations. Enterprise customers that are insurance agencies, carriers, MGAs, or other licensed insurance entities are solely responsible for complying with all applicable insurance privacy regulations, including without limitation state insurance privacy codes, applicable state consumer privacy laws, and any applicable insurance regulatory guidance regarding the use of AI, data analytics, and technology in insurance operations.
(c) Gramm-Leach-Bliley Act. To the extent the Company receives nonpublic personal financial information from or on behalf of enterprise customers that are financial institutions subject to the Gramm-Leach-Bliley Act, the Company processes such information as a service provider subject to appropriate contractual restrictions consistent with GLBA requirements. Enterprise customers subject to GLBA are solely responsible for ensuring that their use of the Services complies with their obligations under GLBA, including applicable privacy notice and opt-out requirements.
12.2 Marketing and Lead Generation Services
In connection with the Company's marketing services, lead generation, live transfer, and consumer matching operations, personal information about consumers may be collected, processed, and shared with enterprise customers for marketing and sales purposes. The Company's lead generation and consumer matching activities are conducted in compliance with applicable laws, including applicable telemarketing laws, the CAN-SPAM Act, and applicable consumer protection regulations. Enterprise customers that receive leads, live transfers, or consumer data from the Company are solely responsible for complying with all applicable laws governing their use of such data, including applicable TCPA requirements, state telemarketing laws, and applicable privacy regulations.
12.3 Staffing, BPO, and Virtual Assistant Services
In connection with the Company's staffing, BPO, virtual assistant, and call center services, personal information about enterprise customer personnel and end customers may be processed by Company personnel and contractors. The Company implements appropriate confidentiality and data handling requirements for personnel involved in staffing and BPO operations. Enterprise customers are responsible for ensuring that their use of staffing and BPO services complies with applicable employment, privacy, and regulatory requirements.
12.4 Health Information
To the extent any enterprise customer submits health-related information to the Services, such submission is the sole responsibility of the enterprise customer. The Company is not a covered entity under HIPAA unless separately contracted as a Business Associate. Enterprise customers that are covered entities or business associates under HIPAA and that intend to submit protected health information to the Services must execute a Business Associate Agreement with the Company prior to any such submission.
Part 13. Marketing Communications
13.1 Types of Marketing Communications
The Company may send the following categories of marketing communications to individuals who have provided contact information and, where required by applicable law, have consented to receive such communications:
- (a) email newsletters and product announcements;
- (b) promotional emails regarding new features, products, and services;
- (c) industry news, thought leadership content, and educational resources;
- (d) event invitations, webinar announcements, and training opportunities;
- (e) SMS marketing messages regarding Company products, services, and promotions, where applicable consent has been obtained; and
- (f) targeted digital advertising through third-party platforms based on profile data and behavioral information.
13.2 Legal Basis for Marketing
Marketing communications to U.S.-based contacts are sent on the basis of legitimate business interest or consent as applicable. Marketing communications to individuals subject to GDPR or UK GDPR are sent on the basis of consent or legitimate interests as permitted by applicable law. SMS marketing is conducted only with prior express written consent where required by applicable law.
13.3 Opt-Out Mechanisms
You may opt out of marketing communications at any time by:
- (a) clicking the unsubscribe link in any marketing email;
- (b) replying STOP to any SMS marketing message;
- (c) contacting the Company using the information provided in Part 17; or
- (d) adjusting communication preferences in your account settings where available.
Opting out of marketing communications does not affect the delivery of transactional and operational communications related to the Services, including account notices, billing communications, security alerts, service updates, and support communications.
13.4 Interest-Based Advertising
The Company engages in interest-based advertising through digital advertising platforms. To opt out of interest-based advertising, you may use applicable industry opt-out tools, adjust advertising settings within applicable platforms, or manage cookie preferences as described in Part 3 of this Policy.
Part 14. Children's Privacy
14.1 Services Intended for Adults and Business Users Only
The Services, platforms, websites, applications, programs, and all business solutions operated by the INSUREU2 ecosystem are intended exclusively for business, professional, commercial, enterprise, and organizational use by adults. The Services are not directed to, intended for, marketed to, or designed for individuals under the age of eighteen (18). No individual under the age of eighteen (18) is permitted to access or use the Services.
14.2 No Knowing Collection from Minors
The Company does not knowingly collect, solicit, process, store, maintain, sell, share, or otherwise use personal information from any individual under the age of eighteen (18). The Company's minimum intended user age is eighteen (18) years. The Company's Services are not subject to COPPA because they are not directed to children under thirteen (13); however, the Company applies the broader age restriction of eighteen (18) consistent with the exclusively professional and commercial nature of the Services.
14.3 Discovery of Minor's Information
If the Company becomes aware that personal information has been collected from an individual under the age of eighteen (18) without appropriate legal authorization, the Company reserves the right to delete such information, suspend or terminate the applicable account, and take any other actions reasonably necessary to comply with applicable laws, regulations, contractual obligations, and Company policies.
14.4 Parental and Guardian Inquiries
Parents, guardians, or authorized representatives who believe that an individual under the age of eighteen (18) may have provided personal information to the Company may contact the Company using the information provided in Part 17 to request review, correction, restriction, or deletion of such information. The Company will respond to such requests in accordance with applicable law.
14.5 Enterprise Customer Responsibility
Enterprise customers are solely responsible for ensuring that their use of the Services does not involve the collection, processing, or submission of personal information of individuals under the age of eighteen (18) in violation of applicable law, including without limitation COPPA and applicable state minor privacy laws.
Part 15. Third-Party Websites and Integrations
15.1 Third-Party Links
Company websites, platforms, and marketing materials may contain links to third-party websites, applications, services, and resources. The Company does not control, endorse, or assume any responsibility for the content, privacy practices, or data handling of any third-party website or service. Clicking on a third-party link will direct you away from Company properties to a third-party site. Your use of any third-party website or service is entirely at your own risk and is subject to the applicable third-party privacy policy and terms of service. The Company encourages all users to review the privacy policies of every third-party website and service they access.
15.2 Third-Party Platform Integrations
The Services support and may be integrated with third-party CRM platforms, telephony platforms, marketing platforms, data platforms, analytics tools, and other business applications. When you connect a third-party integration to the Services, personal information may be transmitted to or collected by the applicable third party in accordance with that third party's privacy policy and terms. The Company does not control how third parties use information received through integrations. Enterprise customers are responsible for evaluating the privacy and security practices of any third-party integrations they enable in connection with the Services and for ensuring that such integrations comply with applicable law.
15.3 Social Media Features
Company websites and marketing properties may include social media features, share buttons, embedded content, and third-party widgets. These features may collect your IP address, information about which pages you visit, and other behavioral data, and may set cookies or use other tracking technologies. Your interactions with social media features are governed by the privacy policies of the applicable social media companies, not by this Policy.
15.4 No Endorsement
The inclusion of any third-party link, integration, or feature on Company properties does not constitute an endorsement, recommendation, or representation by the Company regarding the third party's products, services, security, or privacy practices.
Part 16. Changes to This Policy
16.1 Right to Update
The Company reserves the right to update, modify, supplement, or replace this Policy at any time, in its sole discretion, to reflect changes in the Company's data processing activities, product offerings, legal requirements, regulatory guidance, business operations, or any other factor that the Company determines warrants an update.
16.2 Notice of Material Changes
The Company will provide notice of material changes to this Policy by:
- (a) posting the updated Policy on Company websites and platforms with a revised "Last Updated" date at the top of the Policy;
- (b) sending notice to the email address associated with your account or to the primary contact email of the applicable enterprise customer; or
- (c) providing in-platform notification through applicable Company products and platforms.
16.3 Continued Use Constitutes Acceptance
Your continued access to or use of any Service following the posting of an updated Policy, or following the delivery of notice of material changes, constitutes your acceptance of the updated Policy. If you do not agree to an updated Policy, you must immediately cease using the Services and, if applicable, notify the Company of your intent to terminate your subscription or account in accordance with the terms of the applicable agreement.
16.4 Review Obligation
The Company encourages all users, enterprise customers, and partners to review this Policy periodically to stay informed of the Company's data practices. The Company is not responsible for any failure by any party to review updated Policy terms.
Part 17. Contact Information
17.1 Privacy Inquiries and Requests
For questions, concerns, privacy rights requests, or any other inquiry regarding this Policy or the Company's privacy and data protection practices, please contact:
INSUREU2 / IU2 Technology LLC
Attention: Privacy
P.O. Box 500304
San Diego, CA 92150
Email: [email protected]
Telephone: +1 (234) 564-6482
Fax: (304) 371-2362
Website: insureu2.club
17.2 Additional Contact Channels
The Company may provide additional contact forms, support portals, ticketing systems, customer portals, live chat, and other communication channels through its websites and software platforms. Users may use any available contact channel to submit privacy inquiries, provided that requests requiring identity verification may require submission through designated secure channels.
17.3 Data Protection Officer
The Company does not currently maintain a formally designated Data Protection Officer. Privacy matters are managed through designated internal personnel and authorized service providers. The Company reserves the right to designate a Data Protection Officer in the future as regulatory requirements evolve.
17.4 EU Representative
The Company does not currently maintain a designated EU representative. If the Company's processing activities reach the threshold requiring a designated EU representative under Article 27 GDPR, the Company will designate a representative and update this Policy accordingly.
17.5 UK Representative
The Company does not currently maintain a designated UK representative. If the Company's processing activities reach the threshold requiring a designated UK representative under UK GDPR, the Company will designate a representative and update this Policy accordingly.
17.6 Response Timeframes
The Company will acknowledge privacy rights requests promptly and will endeavor to respond substantively within the timeframes required by applicable law. Where requests are complex, numerous, or require additional verification, the Company may extend response timeframes as permitted by applicable law and will notify the requestor of any such extension.
This Privacy Policy governs all personal information collected, processed, used, shared, and retained by IU2 Technology LLC, INSUREU2 Corp, ScaleU2, Cbender Innovations Corp, and all brands, affiliates, subsidiaries, platforms, products, services, and future offerings operating within the INSUREU2 ecosystem.
This Privacy Policy supersedes all prior privacy policies, privacy notices, and privacy disclosures of the Company and its affiliated entities.
© 2026 IU2 Technology LLC. All rights reserved. Confidential & Proprietary — INSUREU2 Ecosystem.