# AceAgent Privacy Policy Status: Owner-approved implementation draft dated 2026-08-23. Obtain qualified legal and privacy review before external Marketplace publication. This Privacy Policy describes how Axiom Equity LLC, doing business as AceAgent (**AceAgent**, **we**, **us**, or **our**), collects, uses, protects, and retains information when an organization and its authorized users use AceAgent. AceAgent is a business operations workspace that connects to customer-selected CRM, advertising, email, calendar, enrollment, statement, billing, and related services. The customer controls which provider accounts it connects. When a customer uses HighLevel, HighLevel remains the CRM system of record. ## 1. Information we process Depending on the features a customer enables, AceAgent may process: - account information, such as organization name, authorized user name, verified email address, role, authentication identifier, and acceptance records; - connected-account information, such as provider account identifiers, authorization scopes, connection status, and protected OAuth credentials; - CRM and operations information, such as contacts, opportunities, appointment information, communications metadata, tags, custom fields, and user/team information; - insurance operations information, such as enrollment, policy, carrier, statement, commission, reconciliation, and onboarding records; - files or media submitted to an enabled workflow, such as enrollment PDFs, statement files, welcome-letter assets, call recordings, or dictated audio; - billing and subscription status received from our payment processor; and - security and diagnostic information, such as timestamps, application release, bounded audit events, request identifiers, IP-derived security metadata, and error classifications. AceAgent does not request or store a user's HighLevel, Microsoft, Google, Meta, carrier, or other connected-provider password or MFA code. OAuth access and refresh tokens are stored only in protected server-side credential storage and are not returned to the browser. ## 2. Why we process information We process information only as reasonably necessary to: - provide, configure, secure, support, and maintain the AceAgent services; - connect the customer's selected provider accounts and perform the reads or separately confirmed writes the customer requests; - create only missing CRM fields or tags after setup review and verify the provider's resulting state; - provide tenant-scoped reporting, onboarding, reconciliation, communications, and other enabled operational workflows; - authenticate users, enforce organization roles and subscriptions, prevent cross-tenant access, and preserve audit evidence; - process payments and administer subscriptions; and - comply with law, enforce applicable agreements, and investigate security or privacy incidents. AceAgent does not sell customer or client data. We do not use it for advertising, model training, cross-customer benchmarking, public examples, or unrelated product analytics. ## 3. Connected providers and service providers AceAgent shares information only as needed for an enabled feature or a lawful operational purpose. Recipients may include: - customer-selected connected providers, including CRM, email, calendar, advertising, enrollment, statement, and communications services; - Microsoft Azure services used for hosting, databases, protected credential storage, encrypted file storage, monitoring, identity, and approved AI or speech processing; - payment and fulfillment providers used for subscriptions, postage, or other customer-requested purchases; and - professional advisers, incident responders, or authorities when permitted or required by law. Where Protected Health Information is involved, the AceAgent HIPAA Business Associate Agreement applies when required and accepted by an authorized customer representative. Service providers that create, receive, maintain, or transmit PHI for AceAgent must be subject to applicable written privacy and security duties. AceAgent does not authorize a connected provider to use information outside that provider's own terms, the customer's instructions, or the purpose of the enabled connection. Customers remain responsible for their provider accounts and provider terms. ## 4. Security AceAgent uses tenant-scoped authorization, role checks, encrypted transport, protected server-side credential storage, controlled write confirmations, idempotency protections, provider read-back, audit events, and restricted logs. Production endpoints use HTTPS. Credentials, customer documents, transcripts, audio, and sensitive row contents are prohibited from ordinary application logs. No system can guarantee absolute security. Customers must protect their accounts, use least-privilege provider access, maintain appropriate MFA, and report suspected unauthorized access promptly. ## 5. Retention and deletion Retention depends on the information and enabled workflow: - provider credentials are retained only while the connection is active. They are revoked or scrubbed when the Marketplace connection is disconnected, uninstalled, replaced, or removed through an approved account-removal process; - disconnecting HighLevel removes AceAgent's API access but does not delete the customer's HighLevel contacts, opportunities, fields, tags, or other CRM data; - temporary source files are deleted after the applicable ingestion or review lifecycle. Hosted onboarding source PDFs and generated onboarding artifacts currently use a seven-day operational retention period; - normalized product records, audit evidence, reconciliation state, and other customer workspace records are retained while the organization is active and until removed through the verified account-removal process; - operational logs currently use a 30-day retention period and must not contain customer document contents, credentials, transcripts, audio, or sensitive row values; and - deleted data may remain encrypted and inaccessible in backups until the normal backup-expiration period ends. Individual backup images are not edited. Legal holds or binding legal, regulatory, or contractual requirements may delay normal deletion after a documented decision. They do not authorize unrelated use. An organization owner may request export or account removal by contacting support@aceagenttoolbox.com. For security, AceAgent will verify the requester's identity and organizational authority. A request is not treated as complete until the supervised process returns the required tenant-scoped verification. ## 6. Individual and customer choices Authorized organization administrators can choose which provider accounts to connect and can disconnect the HighLevel Marketplace app from AceAgent. A customer may also uninstall the app from HighLevel. Disconnecting a provider does not by itself cancel an AceAgent subscription; billing changes must be completed through the separate subscription controls. Requests concerning a client's insurance or CRM record generally must be directed to the customer organization that controls that record. AceAgent will assist the customer as required by applicable law and the accepted agreements. ## 7. Cookies and authentication AceAgent uses security and session technologies necessary to authenticate users, maintain tenant boundaries, protect requests, and remember essential interface preferences. AceAgent does not use customer or client data for behavioral advertising. ## 8. Children's privacy AceAgent is a business service for authorized insurance professionals and their organizations. It is not directed to children and is not intended for independent use by anyone under 18. ## 9. Changes to this policy We may update this policy to reflect service, legal, or security changes. We will publish the updated version and effective date. Material changes that alter a customer's rights or PHI handling may require updated notice or organizational acceptance. ## 10. Contact Privacy, security, access, and deletion questions may be sent to: Axiom Equity LLC, d/b/a AceAgent 5384 S Cardinal St Gilbert, AZ 85298 support@aceagenttoolbox.com Do not send passwords, MFA codes, provider sessions, enrollment PDFs, commission statements, call audio, transcripts, or screenshots containing client data to the support mailbox unless AceAgent provides a specifically approved secure intake method.