OmniReach CRM is built for insurance agents who handle sensitive client information every day, including
Protected Health Information under HIPAA. This policy explains what data we collect, how we use it, who we share
it with, and the rights you have over it. We've tried to write it in plain English.
1.Who This Policy Covers
This Data Privacy Policy applies to anyone who interacts with OmniReach CRM — whether you're visiting our
website, using the platform as a paying customer, or your information has been added to OmniReach by one of our
customers.
There are three distinct groups of people whose data we handle, and the rules are different for each:
Website Visitors
People browsing omnireachcrm.com. We collect minimal analytics and
information they choose to give us (e.g., booking a demo).
Customers (Agents)
Insurance agents and agencies who pay for and use OmniReach. We hold their account
data, billing info, and platform usage data.
End Clients
The leads, prospects, and clients whose information our Customers enter into OmniReach.
This is the group most likely to include PHI under HIPAA. Our Customer is the "controller"
of this data; we are the "processor" / Business Associate.
2.What Data We Collect
From Website Visitors
- Identifying information you give us: name, email, phone number, business name when you book
a demo or contact us.
- Technical data: IP address, browser type, device type, pages viewed, referring URL,
approximate location (city-level).
From Customers (Agents Using the Platform)
- Account data: name, business name, email, phone, mailing address, login credentials.
- Billing data: payment method information (processed by our payment provider — we don't
store full card numbers on our servers), billing address, transaction history.
- Licensing data: states where you're licensed, NPN, agency affiliations (if you provide
them).
- Platform usage: logins, features used, communications sent, automations configured, support
interactions.
From End Clients (Data Customers Upload About Their Leads/Clients)
This is data about someone else that our Customer enters into OmniReach. We process this data
on behalf of our Customer under the Business Associate Agreement.
- Contact info: name, phone, email, mailing address.
- Insurance-related data: date of birth, coverage history, plan preferences, application
status, policy details.
- Communication records: SMS messages, call recordings (if enabled), emails, notes.
- Protected Health Information (PHI): may include health conditions, medications, Medicare ID
numbers, or other health-related data when entered by the Customer.
3.How We Collect It
- Directly from you when you fill out a form, book a demo, sign up for an account, or
communicate with us.
- Through normal platform use as you log in, send messages, configure workflows, etc.
- From your devices via cookies, server logs, and similar technologies (see Section 8).
- From third parties such as our payment processor (transaction confirmations) or carrier
networks (SMS delivery status).
- From your own uploads when you import contact lists, upload documents, or sync data from
third-party tools.
4.How We Use Your Data
We use data only for the purposes you'd reasonably expect:
- Provide the Service: run your account, route your messages, store your data, deliver
features.
- Billing: charge your Subscription fees and Carrier Fees, send invoices.
- Support: respond when you contact us, troubleshoot issues, train our chat support team.
- Improve the platform: understand usage patterns in aggregate, debug, prioritize features.
- Communicate with you: service updates, security notices, occasional product news (which you
can unsubscribe from).
- Legal and security: prevent fraud, comply with subpoenas and other legal obligations,
enforce our Terms.
What we don't do: We don't sell your data. We don't sell End Client data. We don't use PHI
for marketing or analytics. We don't train AI models on your client data.
5.PHI and HIPAA
OmniReach CRM is designed to handle Protected Health Information (PHI) in compliance with HIPAA. When a
Customer enters PHI into the platform — for example, Medicare ID numbers, health conditions, or coverage details
about their leads — we act as a Business Associate as defined under HIPAA.
Specifically:
- A signed Business Associate Agreement (BAA) governs our handling of PHI. The BAA is incorporated into your
Subscription.
- We maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.
- PHI is encrypted in transit (TLS) and at rest.
- Access to PHI is restricted to authorized personnel on a minimum-necessary basis, with access logged.
- We do not use PHI for any purpose outside of providing the Service to our Customer.
- We do not sell, lease, or share PHI with any third party except as required to deliver the Service (e.g.,
carriers transmitting SMS containing health-related information at the Customer's direction) or as required by
law.
Customer responsibilities under HIPAA: our Customers are the "Covered Entity" or "Business
Associate" with respect to their End Clients, and they remain responsible for obtaining authorizations, training
their staff, applying minimum-necessary standards, and using the platform in a HIPAA-compliant manner. The BAA
and Section 5 of our Terms and Conditions explain this shared responsibility in more detail.
6.Who We Share Data With
We share data only with parties necessary to operate the Service:
- The Platform Provider (HighLevel Inc.): OmniReach is built on HighLevel infrastructure.
They process platform data under their own security and privacy commitments.
- Carrier networks (Twilio and similar): route SMS, voice, and email. They see the content of
messages you send through OmniReach because they have to deliver them.
- Payment processor: handles billing. Receives payment information directly — we don't store
full card numbers on our servers.
- Cloud infrastructure providers: data is hosted on enterprise cloud infrastructure with
security certifications appropriate for HIPAA workloads.
- Analytics providers: may receive aggregated, non-PHI usage data to help us understand how
the website is performing. PHI is never sent to analytics tools.
- Law enforcement and regulators when we receive a valid legal request (subpoena, court
order, etc.), and where we are required by law to comply.
- Acquirers in the event of a merger, acquisition, or sale of assets, in which case any
successor entity will be bound by this policy or an equivalent.
We do not sell your personal data. We do not sell End Client data. We do not rent it. We do
not share it with advertisers for advertising purposes.
7.SMS, Calls & A2P Records
SMS and voice traffic in the United States is governed by carrier networks and the TCPA, CAN-SPAM Act, and A2P
10DLC rules. Some specifics worth understanding:
- Opt-in records: when you (the Customer) send SMS to End Clients through OmniReach, you are
legally required to maintain documented consent. Records of opt-ins and opt-outs are retained in the platform.
- Carrier-required retention: carriers may require message metadata (sender, recipient,
timestamp, delivery status) be retained for compliance purposes, separate from any deletion request.
- Recording disclosures: if you record calls, applicable state law (and HIPAA, when PHI is
discussed) may require explicit consent from all parties. This is your responsibility, not ours.
- STOP/HELP keywords: the platform automatically processes carrier-mandated keywords (STOP,
UNSUBSCRIBE, HELP) and updates opt-in status accordingly.
8.Cookies and Tracking
We use cookies and similar technologies for a small set of purposes:
- Essential cookies: required for the website and platform to function (keep you logged in,
remember your account, secure your session). These cannot be disabled.
- Analytics cookies: help us understand which pages are viewed, where visitors come from, and
how to improve the site. These are aggregate and do not include PHI.
- Functional cookies: remember your preferences (e.g., timezone, language) so you don't have
to set them every visit.
Most browsers let you disable or delete cookies. If you disable essential cookies, parts of the platform may
not work. We do not use cookies to build advertising profiles or track you across unrelated websites.
9.How We Protect Your Data
We take security seriously, especially given the sensitivity of insurance and health data:
- Encryption in transit and at rest using industry-standard protocols.
- Access controls: only authorized personnel have access to systems containing customer or
PHI data, and on a minimum-necessary basis.
- Audit logging of PHI access events.
- Firewalls, intrusion detection, and regular security review of our infrastructure and our
Platform Provider's infrastructure.
- Background checks and HIPAA training for personnel with access to PHI.
No system is 100% secure. While we use commercially reasonable safeguards, no
internet-connected system can be guaranteed against all attacks. You are responsible for keeping your account
credentials safe and notifying us immediately of any suspected unauthorized access.
10.How Long We Keep Data
Retention periods vary by data type:
- Active account data: retained for as long as your Subscription is active.
- After account termination: data is generally retained for 30–90 days to allow for export
and to handle any final billing or disputes, after which it is deleted.
- Billing records: retained for 7 years for tax and accounting purposes, even after account
closure.
- Carrier compliance records (opt-in/opt-out, message metadata): retained for the period
required by carrier rules and applicable consumer-protection law, typically 4 years.
- Backups: deleted data may persist in encrypted backups for a short period before being
purged from rotation.
11.Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate or incomplete data.
- Deletion: request deletion of your personal data (subject to legal retention requirements
above).
- Data portability: receive your data in a portable, machine-readable format.
- Opt out of marketing: unsubscribe from product emails any time using the link at the bottom
of those emails.
- Withdraw consent where we rely on consent as the basis for processing.
To exercise any of these rights, email info@omnireachcrm.com. We
will respond within the timeframe required by applicable law.
Important: if you are an End Client whose information was entered into OmniReach by an
insurance agent (our Customer), please contact the agent directly first. They are the controller of your data;
we process it on their behalf.
12.State Privacy Laws
Several U.S. states have enacted comprehensive privacy laws that provide additional rights to their residents.
We comply with applicable state privacy laws including:
- Texas Data Privacy and Security Act (TDPSA): effective July 2024 — applicable to Texas
residents.
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): applicable
to California residents.
- Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act, Connecticut Data Privacy Act,
Utah Consumer Privacy Act, and similar laws in other states.
We do not sell personal data as that term is defined under these laws. We do not engage in "targeted
advertising" or use personal information for profiling that would produce legal or similarly significant
effects.
13.International Users
OmniReach CRM is operated from the United States and primarily serves U.S.-licensed insurance agents. If you
access the Service from outside the U.S., your data will be transferred to and processed in the United States,
which may have different privacy protections than your home country.
If you are located in the European Economic Area, United Kingdom, or another jurisdiction with comprehensive
privacy laws, you may have additional rights. Contact us at info@omnireachcrm.com to exercise them.
14.Children's Privacy
The Service is intended for licensed insurance professionals and is not directed to children. We do not
knowingly collect personal information from anyone under the age of 18. If you become aware that a child has
provided us with personal information, please contact us so we can delete it.
15.Breach Notification
In the event of a data breach that compromises personal information or PHI, we will notify affected individuals
and applicable authorities in accordance with HIPAA Breach Notification Rule timelines and applicable state
breach notification laws. Notifications will describe the nature of the breach, the data involved, steps being
taken, and recommended actions for affected individuals.
If you suspect a breach involving your account or your End Clients' data, contact us immediately at info@omnireachcrm.com.
16.Changes to This Policy
We may update this Data Privacy Policy from time to time. For material changes, we will notify you by email
and/or by posting a prominent notice on the website at least 30 days before the changes take effect. The "Last
updated" date at the top of this page will always reflect the current version.
Continued use of the Service after the effective date of a revised policy constitutes acceptance of the revised
policy.