Privacy Policy
This Privacy Policy explains how Polca LLC ("Polca," "we") handles personal information in connection with polca.ai and the Polca platform, including its two branded editions, Polca and LifePros (together, the "Service"). One privacy policy governs both editions. The Service is built for life insurance agencies ("Agencies"). Two roles matter: for Agency account and website data, Polca is the controller; for Consumer data an Agency submits or generates through the Service (leads, clients, recordings, application information), the Agency is the controller and Polca is a processor/service provider acting under the Data Processing Addendum. Consumers should direct requests to the Agency that contacted them, and we support Agencies in fulfilling them.
1. Information we collect
From Agencies and their users
- Account data: names, business email and phone, agency details, seat assignments, roles, authentication data.
- Billing data: processed by Stripe; we store subscription status and invoice metadata, never full card numbers.
- Platform activity: logins, feature usage, configuration, audit logs, and logged acceptances of our legal documents (versions accepted, timestamp, IP address, browser).
- Support communications.
Processed for Agencies (Agency controlled Consumer data)
- CRM data synced from the Agency's CRM (such as GoHighLevel): contact names, phone numbers, tags, notes, appointment records.
- Call data: recordings (where the Agency's recording setting is on; see Section 4), transcripts, summaries, dispositions, caller ID, timestamps. Agencies are responsible for any recording notices or consents their jurisdictions require.
- Opt-out data: each Agency's permanent do-not-call ledger of Consumers who must not be contacted, including entries the Agency uploads.
- Uploaded materials: scripts, guides, presentations, and application related documents, which may include health related answers and banking details the Agency collects from its clients.
From website visitors
- First party, cookie free website analytics measuring page views and interactions. We do not use advertising identifiers, cross-site tracking, or analytics data intended to identify individual visitors; any technical network information processed to deliver or secure the site is not used for advertising or cross-site profiling.
- Access requests you submit (name, agency, email, phone, team details).
- Functional cookies only: the platform sets a session cookie to keep signed-in users signed in. We do not use advertising or third party analytics cookies, and we do not respond differently to "Do Not Track" because we do not track.
2. How we use information
To provide and secure the Service (placing and answering calls, transcription and summarization, CRM sync, dashboards, provisioning); to bill; to provide support; to prevent fraud and abuse and protect network reputation; to comply with law; to communicate service and account notices; and, for website leads, to respond to your request. We use de-identified, aggregated data for service operation and improvement, and we may publish anonymized cross agency benchmarks in marketing, always disclosed as aggregated and anonymized and never identifying an Agency, user, or Consumer. When we use or disclose de-identified or aggregated information, we take reasonable measures to prevent it from being associated with an individual, do not attempt to reidentify it, and require any recipients to preserve its de-identified status. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use Agency controlled Consumer content to train generalized AI models.
Staff access and the firewall. Polca staff access to Agency data is limited to support, maintenance, security, billing, and compliance purposes, and every access is audit logged. Information learned from an Agency's data is never used by any agency affiliated with Polca's owner to compete with that Agency, solicit its clients, or recruit its people (see Terms Section 15).
3. How information is shared
- Sub-processors that run the Service: payment processing (Stripe), cloud hosting (DigitalOcean), telephony carrier and caller identity partners, and AI speech and language providers used to conduct and transcribe calls. Each is bound to confidentiality and use limited to providing services to us; the current list of sub-processor categories is published at polca.ai/subprocessors, and named identities are available on request as described there.
- The Agency you interact with: if you are a Consumer, your information is processed within and under the control of the applicable Agency's account.
- Legal: to comply with law, enforceable requests, or to protect rights, safety, and the Service. When we receive a government or legal request for data, we review it for legal validity, seek to narrow overbroad requests, disclose only what we are legally required to disclose, and, where lawful, notify the affected Agency before disclosure.
- Business transfers: in a merger, acquisition, or asset sale, data may transfer subject to this policy's commitments.
4. Call recording
Recording is controlled by an Agency level setting that is on by default; the Agency owner can turn it off. As a protective courtesy, the platform automatically suppresses recording on calls to numbers associated with California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, Vermont, and Washington. This safeguard is based on the number's associated location and does not remove the Agency's own responsibility for recording law compliance.
5. Retention
- Call recordings: one platform wide policy: 90 days from creation, then permanently deleted. Agencies can export recordings at any time before deletion. A legal hold can require longer retention.
- Leads, appointments, notes, call logs, transcripts, summaries: retained while the Agency account is active.
- The Agency's do-not-call ledger: permanent. It survives CRM disconnection and may be retained after account closure solely to honor do-not-call obligations.
- Account and billing records: life of account plus the period required for tax, accounting, and legal obligations.
- Raw website analytics events: up to 90 days; aggregate counts may be retained longer.
- Backups: encrypted and deleted or overwritten within 35 days.
- After cancellation: a one-click full export is available (leads, appointments, notes, call log, and always the do-not-call ledger); data is frozen for 60 days for export, then deleted from production systems, subject to the backup schedule above and any legal holds.
6. Security
Every Agency's data is isolated with database enforced row level security; access is least privilege and logged; data is encrypted in transit; credentials are hashed with modern algorithms; production access is restricted to authorized personnel. No system is perfectly secure; we notify affected Agencies of qualifying incidents without undue delay (see the DPA).
7. Your rights
Consumers: contact the Agency that contacted you, including to opt out of further calls; opt-outs are enforced automatically across the platform and recorded in the Agency's permanent do-not-call ledger. If you contact us, we will route your request to the responsible Agency and assist in its fulfillment.
Agency users and website visitors: depending on your state of residence and subject to applicable exemptions, you may have rights to confirm whether we process your personal data; access, correct, delete, or obtain a portable copy of it; and opt out of targeted advertising, the sale of personal data, or profiling used to make decisions producing legal or similarly significant effects. Polca does not currently sell personal data, use it for cross-context behavioral advertising, or engage in such profiling.
Submit requests to privacy@polca.ai. We generally respond within 45 days, subject to any extension permitted by law, and we do not discriminate against anyone for exercising privacy rights. Authorized agents may submit requests with proof of authority. If we deny your request, our response will explain the reason and how to appeal: reply to the denial or email privacy@polca.ai with "Privacy Appeal" in the subject line, and we will respond to your appeal within the period required by applicable law.
8. State privacy notices (including California)
For applicable state laws (including CCPA/CPRA): the categories collected are identifiers, commercial information, internet activity, professional information, audio (call recordings), and, within Agency controlled content, data that may reveal health or financial information. Sources: you, your Agency, and your use of the Service. Purposes: as in Section 2. Disclosures: to the service providers in Section 3 for business purposes only. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. We act as a "service provider" for Agency controlled data. California residents may exercise rights via privacy@polca.ai.
9. Financial and health information
Agencies may be subject to the Gramm-Leach-Bliley Act and state insurance data security laws for Consumer financial and health information; Polca processes such information solely as the Agency's service provider under the DPA's safeguards. Polca is not a HIPAA business associate by default (see DPA Section 4), and Agencies remain responsible for assessing state consumer health data and insurance privacy laws applicable to their own workflows. Agencies may upload application related materials containing health related or financial information when necessary for supported workflows, but must not upload full payment card data, account credentials, or other sensitive information the Service is not designed and authorized to process.
10. Children; international
The Service is for businesses and not directed to children under 18. The Service is operated from the United States and intended for U.S. Agencies; data is stored in the U.S.
11. Changes and contact
We will post updates here with a new effective date, notify account owners of material changes, and ask users to re-accept at their next login when the legal set changes. Contact: privacy@polca.ai · Polca LLC, Nebraska, USA.