OmniReach CRM is built for insurance agents who handle sensitive
client information every day, including Protected Health Information
under HIPAA. This policy explains what data we collect, how we use it,
who we share it with, and the rights you have over it. We've tried to
write it in plain English.
1.Who This Policy Covers
This Data Privacy Policy applies to anyone who interacts with
OmniReach CRM — whether you're visiting our website, using the
platform as a paying customer, or your information has been added to
OmniReach by one of our customers.
There are three distinct groups of people whose data we handle, and
the rules are different for each:
Website Visitors
People browsing omnireachcrm.com. We collect
minimal analytics and information they choose to give us (e.g.,
booking a demo).
Customers (Agents)
Insurance agents and agencies who pay for and use OmniReach. We
hold their account data, billing info, and platform usage data.
End Clients
The leads, prospects, and clients whose information our Customers
enter into OmniReach.
This is the group most likely to include PHI under
HIPAA.
Our Customer is the "controller" of this data; we are the
"processor" / Business Associate.
2.What Data We Collect
From Website Visitors
-
Identifying information you give us: name, email,
phone number, business name when you book a demo or contact us.
-
Technical data: IP address, browser type, device
type, pages viewed, referring URL, approximate location
(city-level).
From Customers (Agents Using the Platform)
-
Account data: name, business name, email, phone,
mailing address, login credentials.
-
Billing data: payment method information (processed
by our payment provider — we don't store full card numbers on our
servers), billing address, transaction history.
-
Licensing data: states where you're licensed, NPN,
agency affiliations (if you provide them).
-
Platform usage: logins, features used,
communications sent, automations configured, support interactions.
From End Clients (Data Customers Upload About Their Leads/Clients)
This is data about someone else that
our Customer enters into OmniReach. We process this data on
behalf of our Customer under the Business Associate Agreement.
-
Contact info: name, phone, email, mailing address.
-
Insurance-related data: date of birth, coverage
history, plan preferences, application status, policy details.
-
Communication records: SMS messages, call
recordings (if enabled), emails, notes.
-
Protected Health Information (PHI): may include
health conditions, medications, Medicare ID numbers, or other
health-related data when entered by the Customer.
3.How We Collect It
-
Directly from you when you fill out a form, book a
demo, sign up for an account, or communicate with us.
-
Through normal platform use as you log in, send
messages, configure workflows, etc.
-
From your devices via cookies, server logs, and
similar technologies (see Section 8).
-
From third parties such as our payment processor
(transaction confirmations) or carrier networks (SMS delivery
status).
-
From your own uploads when you import contact
lists, upload documents, or sync data from third-party tools.
4.How We Use Your Data
We use data only for the purposes you'd reasonably expect:
-
Provide the Service: run your account, route your
messages, store your data, deliver features.
-
Billing: charge your Subscription fees and Carrier
Fees, send invoices.
-
Support: respond when you contact us, troubleshoot
issues, train our chat support team.
-
Improve the platform: understand usage patterns in
aggregate, debug, prioritize features.
-
Communicate with you: service updates, security
notices, occasional product news (which you can unsubscribe from).
-
Legal and security: prevent fraud, comply with
subpoenas and other legal obligations, enforce our Terms.
What we don't do: We don't sell your data. We don't
sell End Client data. We don't use PHI for marketing or analytics.
We don't train AI models on your client data.
5.PHI and HIPAA
OmniReach CRM is designed to handle Protected Health Information (PHI)
in compliance with HIPAA. When a Customer enters PHI into the platform
— for example, Medicare ID numbers, health conditions, or coverage
details about their leads — we act as a
Business Associate as defined under HIPAA.
Specifically:
-
A signed Business Associate Agreement (BAA) governs our handling of
PHI. The BAA is incorporated into your Subscription.
-
We maintain administrative, physical, and technical safeguards
consistent with the HIPAA Security Rule.
- PHI is encrypted in transit (TLS) and at rest.
-
Access to PHI is restricted to authorized personnel on a
minimum-necessary basis, with access logged.
-
We do not use PHI for any purpose outside of providing the Service
to our Customer.
-
We do not sell, lease, or share PHI with any third party except as
required to deliver the Service (e.g., carriers transmitting SMS
containing health-related information at the Customer's direction)
or as required by law.
Customer responsibilities under HIPAA: our Customers
are the "Covered Entity" or "Business Associate" with respect to their
End Clients, and they remain responsible for obtaining authorizations,
training their staff, applying minimum-necessary standards, and using
the platform in a HIPAA-compliant manner. The BAA and Section 5 of our
Terms and Conditions explain this shared responsibility in more
detail.
6.Who We Share Data With
We share data only with parties necessary to operate the Service:
-
The Platform Provider (HighLevel Inc.): OmniReach
is built on HighLevel infrastructure. They process platform data
under their own security and privacy commitments.
-
Carrier networks (Twilio and similar): route SMS,
voice, and email. They see the content of messages you send through
OmniReach because they have to deliver them.
-
Payment processor: handles billing. Receives
payment information directly — we don't store full card numbers on
our servers.
-
Cloud infrastructure providers: data is hosted on
enterprise cloud infrastructure with security certifications
appropriate for HIPAA workloads.
-
Analytics providers: may receive aggregated,
non-PHI usage data to help us understand how the website is
performing. PHI is never sent to analytics tools.
-
Law enforcement and regulators when we receive a
valid legal request (subpoena, court order, etc.), and where we are
required by law to comply.
-
Acquirers in the event of a merger, acquisition, or
sale of assets, in which case any successor entity will be bound by
this policy or an equivalent.
We do not sell your personal data. We do not sell End
Client data. We do not rent it. We do not share it with advertisers
for advertising purposes.
7.SMS, Calls & A2P Records
SMS and voice traffic in the United States is governed by carrier
networks and the TCPA, CAN-SPAM Act, and A2P 10DLC rules. Some
specifics worth understanding:
-
Opt-in records: when you (the Customer) send SMS to
End Clients through OmniReach, you are legally required to maintain
documented consent. Records of opt-ins and opt-outs are retained in
the platform.
-
Carrier-required retention: carriers may require
message metadata (sender, recipient, timestamp, delivery status) be
retained for compliance purposes, separate from any deletion
request.
-
Recording disclosures: if you record calls,
applicable state law (and HIPAA, when PHI is discussed) may require
explicit consent from all parties. This is your responsibility, not
ours.
-
STOP/HELP keywords: the platform automatically
processes carrier-mandated keywords (STOP, UNSUBSCRIBE, HELP) and
updates opt-in status accordingly.
8.Cookies and Tracking
We use cookies and similar technologies for a small set of purposes:
-
Essential cookies: required for the website and
platform to function (keep you logged in, remember your account,
secure your session). These cannot be disabled.
-
Analytics cookies: help us understand which pages
are viewed, where visitors come from, and how to improve the site.
These are aggregate and do not include PHI.
-
Functional cookies: remember your preferences
(e.g., timezone, language) so you don't have to set them every
visit.
Most browsers let you disable or delete cookies. If you disable
essential cookies, parts of the platform may not work. We do not use
cookies to build advertising profiles or track you across unrelated
websites.
9.How We Protect Your Data
We take security seriously, especially given the sensitivity of
insurance and health data:
-
Encryption in transit and at rest using
industry-standard protocols.
-
Access controls: only authorized personnel have
access to systems containing customer or PHI data, and on a
minimum-necessary basis.
- Audit logging of PHI access events.
-
Firewalls, intrusion detection, and regular security
review
of our infrastructure and our Platform Provider's infrastructure.
-
Background checks and HIPAA training for personnel
with access to PHI.
No system is 100% secure. While we use commercially
reasonable safeguards, no internet-connected system can be
guaranteed against all attacks. You are responsible for keeping your
account credentials safe and notifying us immediately of any
suspected unauthorized access.
10.How Long We Keep Data
Retention periods vary by data type:
-
Active account data: retained for as long as your
Subscription is active.
-
After account termination: data is generally
retained for 30–90 days to allow for export and to handle any final
billing or disputes, after which it is deleted.
-
Billing records: retained for 7 years for tax and
accounting purposes, even after account closure.
-
Carrier compliance records (opt-in/opt-out, message
metadata):
retained for the period required by carrier rules and applicable
consumer-protection law, typically 4 years.
-
Backups: deleted data may persist in encrypted
backups for a short period before being purged from rotation.
11.Your Rights and Choices
Depending on where you live, you may have the following rights
regarding your personal data:
-
Access: request a copy of the personal data we hold
about you.
-
Correction: ask us to fix inaccurate or incomplete
data.
-
Deletion: request deletion of your personal data
(subject to legal retention requirements above).
-
Data portability: receive your data in a portable,
machine-readable format.
-
Opt out of marketing: unsubscribe from product
emails any time using the link at the bottom of those emails.
-
Withdraw consent where we rely on consent as the
basis for processing.
To exercise any of these rights, email
info@omnireachcrm.com. We
will respond within the timeframe required by applicable law.
Important: if you are an End Client whose information
was entered into OmniReach by an insurance agent (our Customer),
please contact the agent directly first. They are the controller of
your data; we process it on their behalf.
12.State Privacy Laws
Several U.S. states have enacted comprehensive privacy laws that
provide additional rights to their residents. We comply with
applicable state privacy laws including:
-
Texas Data Privacy and Security Act (TDPSA):
effective July 2024 — applicable to Texas residents.
-
California Consumer Privacy Act (CCPA) and California Privacy
Rights Act (CPRA):
applicable to California residents.
-
Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy
Act, Connecticut Data Privacy Act, Utah Consumer Privacy
Act,
and similar laws in other states.
We do not sell personal data as that term is defined under these laws.
We do not engage in "targeted advertising" or use personal information
for profiling that would produce legal or similarly significant
effects.
13.International Users
OmniReach CRM is operated from the United States and primarily serves
U.S.-licensed insurance agents. If you access the Service from outside
the U.S., your data will be transferred to and processed in the United
States, which may have different privacy protections than your home
country.
If you are located in the European Economic Area, United Kingdom, or
another jurisdiction with comprehensive privacy laws, you may have
additional rights. Contact us at
info@omnireachcrm.com to
exercise them.
14.Children's Privacy
The Service is intended for licensed insurance professionals and is
not directed to children. We do not knowingly collect personal
information from anyone under the age of 18. If you become aware that
a child has provided us with personal information, please contact us
so we can delete it.
15.Breach Notification
In the event of a data breach that compromises personal information or
PHI, we will notify affected individuals and applicable authorities in
accordance with HIPAA Breach Notification Rule timelines and
applicable state breach notification laws. Notifications will describe
the nature of the breach, the data involved, steps being taken, and
recommended actions for affected individuals.
If you suspect a breach involving your account or your End Clients'
data, contact us immediately at
info@omnireachcrm.com.
16.Changes to This Policy
We may update this Data Privacy Policy from time to time. For material
changes, we will notify you by email and/or by posting a prominent
notice on the website at least 30 days before the changes take effect.
The "Last updated" date at the top of this page will always reflect
the current version.
Continued use of the Service after the effective date of a revised
policy constitutes acceptance of the revised policy.