1. Scope
This Privacy Policy describes how XVLT LLC ("XVLT," "we," "us") collects, uses, discloses, and protects personal information processed through the XVLT SaaS platform. It covers two distinct groups:
- Agents — licensed insurance producers holding accounts on the platform
- Consumers — individuals whose inbound calls are routed through the platform to Agents
This Policy does not govern the privacy practices of insurance carriers, call suppliers, or Agents, each of whom maintains independent legal obligations.
2. Information We Collect
2.1 From Agents
- Identity & Contact: Name, date of birth, business address, telephone, email.
- Professional Data:National Producer Number (NPN), state license numbers/status, carrier appointments, proof of E&O coverage.
- Financial Data: Payment method details (tokenized and processed securely via PCI-DSS compliant third-party processors like Stripe; we do not store full payment card numbers), Wallet balance, transaction history.
- Account & Technical Data: Login credentials, authentication logs, IP address, device/browser identifiers, 2FA status.
- Usage Data: Pages viewed, features used, session duration, calls accepted/declined, dispositions entered, quotes generated, availability settings.
2.2 From Consumers
When a consumer calls a number routed by XVLT, we receive and store:
- Telephone number and caller identification (ANI)
- Geographic origin (state/region)
- Age, gender, and tobacco status where captured in pre-route forms
- Information disclosed during the call (health history, financial details, coverage needs)
- Audio recordings of the call
- Transcripts and automated summaries derived from those recordings
- Call metadata: timestamps, connection duration, routing path, disposition
- Consent certificates (Jornaya LeadID / TrustedForm URLs) supplied by the originating call supplier
3. How We Use Information
Agent information: Account creation, identity and licensing verification, Wallet billing processing, call routing, support, fraud detection, and platform improvement.
Consumer information: Routing the call to a licensed Agent, delivering pre-call context, recording and transcribing the call for quality assurance/dispute resolution, complying with recordkeeping rules, and verifying billing with call suppliers.
Automated Processing & AI Training: XVLT uses de-identified call audio, transcripts, and metadata to train internal machine learning models, natural language processing algorithms, and automated intake features. Personally Identifying Information (PII) is masked or scrubbed prior to model training.
4. Call Recording & Disclosure
4.1 Calls routed through XVLT are recorded and transcribed automatically.
4.2 The platform plays an automated, audible pre-bridge disclosure ("This call is recorded for quality assurance") to both parties upon connection to satisfy federal and state wiretapping laws.
4.3 Retention: Audio recordings are retained for twelve (12) months. Transcripts and summaries are retained for twenty-four (24) months.
4.4 Consumer Requests: Consumers may request a copy or deletion of their call recording subject to statutory retention limits by emailing privacy@xvlt.io. Identity verification is required.
5. How We Share Information
- Licensed Agents: Consumer details necessary to service the specific inquiry.
- Agency Leaders / Organizational Hierarchy: Designated Agency Leaders, FMO/IMO administrators, or Team Managers may access call recordings, transcripts, and performance metrics generated by Agents operating within their organizational hierarchy for compliance monitoring and coaching.
- Service Providers: Infrastructure hosts (e.g., AWS, Vercel), telephony networks (e.g., Twilio), payment processors (e.g., Stripe), and transcription APIs under strict confidentiality contracts.
- Call Suppliers: Redacted call metadata (timestamps, duration, caller ID) shared strictly to verify dispute claims.
- Legal & Regulatory: Pursuant to valid subpoena, court order, or regulatory inquiry.
We do not sell or rent personal information or consumer data to data brokers or third-party marketers.
6. Agent Obligations & GLBA Compliance
Agents receiving consumer information through the platform act as independent data controllers and must:
- Use consumer data solely to service the specific insurance inquiry
- Comply with TCPA, state DNC rules, state insurance privacy laws, and GLBA Safeguards
- Not enter, store, or retain consumer banking credentials through unauthorized platform fields
- Delete consumer data when no longer required for legitimate business/carrier purposes
- Maintain reasonable technical and physical security safeguards
7. Retention Schedule
| Category | Retention Period | Purpose |
|---|---|---|
| Agent Account & License Logs | Account duration + 7 years | Tax, audit, regulatory defense |
| Call Audio Recordings | 12 Months | Dispute resolution, billing verification, carrier audit |
| Transcripts & Summaries | 24 Months | Platform analytics, compliance review |
| Consumer Prospect Records | 24 Months | Servicing and recordkeeping |
| Transaction & Wallet Records | 7 Years | Financial and tax recordkeeping |
| Suppression / DNC Lists | Permanent | Compliance enforcement; never deleted |
8. Your Privacy Rights & Contact
Residents of Pennsylvania, California, Texas, Virginia, and other jurisdictions with comprehensive privacy laws have rights to inspect, correct, or request deletion of personal information held by XVLT.
To exercise these rights, submit a verified request to privacy@xvlt.io.
XVLT LLC
Attn: Privacy & Legal Operations
Email: privacy@xvlt.io | support@xvlt.io