Privacy Policy
Last updated September 2026 · v0926_5
How Inteveo EcoLink, LLC handles personal information, both as a business and as a service provider to insurance agencies.
Version v0926_5 · Effective Date: September 2026 · Last Updated: September 2026
1. Who We Are and What This Policy Covers
Inteveo EcoLink, LLC (“EcoLink,” “we,” “us,” or “our”) provides integrated business communications services — including voice, messaging, call recording, AI-assisted call transcription and summaries, and integrations with agency management systems — primarily to insurance agencies, brokers, and other business customers.
This Privacy Policy explains how we handle personal information in two different roles:
As a business (a “controller”). When you visit our website, request a quote, sign an agreement, or interact with our sales and support teams, we decide how and why your information is used. Sections 2 through 10 apply.
As a service provider (a “processor”). When our business customers use our Services, we process communications, recordings, transcriptions, summaries, and records belonging to that customer and to their clients. We act on our customer’s instructions and do not decide how that information is used. Section 11 explains this and is the most important section for anyone whose call was recorded by one of our customers.
If you are an individual whose call was recorded or transcribed by an insurance agency or other business that uses EcoLink, that business — not EcoLink — is responsible for your information. Please contact them directly. See Section 11.
This policy does not cover the privacy practices of third parties whose services you may use alongside ours, including RingCentral, your agency management system, or any other integrated application. Those providers maintain their own policies.
2. Information We Collect
2.1 Information you give us. Contact and business information (name, title, company name, business address, business email, telephone number); account and billing information (billing contact, service addresses, bank account and routing numbers submitted on an ACH authorization form, payment card information processed by our payment processors — we do not store full card numbers — and tax identification information); contract and transaction records (signed service agreements, proposals, change orders, signature audit certificates, correspondence); credit information used to evaluate creditworthiness, including information from consumer and commercial credit reporting agencies and any guaranty documentation; and support communications, including the content of support tickets, emails, chats, and calls with our team.
2.2 Information we collect automatically. Website and application usage (IP address, browser type and version, operating system, device identifiers, pages viewed, referring URL, timestamps, and similar diagnostic data); service usage and telemetry (login records, feature usage, administrative actions, API calls, error and performance logs); call detail records (calling and called numbers, date, time, duration, direction, routing, and disposition of calls carried through the Services); and cookies and similar technologies (see Section 8).
2.3 Information we receive from others. Provisioning, porting, activation, and billing information from RingCentral, telecommunications carriers, and equipment vendors; data exchanged with agency management systems and other applications you authorize us to connect to (for example, QQCatalyst, AMS360, Applied Epic, ImageRight, Salesforce); and business credit and verification data from credit reporting agencies and public sources.
2.4 Information processed on behalf of our customers. When our customers use the Services, our systems process customer content, which may include: audio recordings of telephone calls; AI-generated transcriptions of those recordings; AI-generated summaries of calls; voicemail messages and transcriptions; SMS and MMS message content; contact records synchronized from an agency management system; and files or notes a customer’s users upload. Customer content is controlled by our customer, not by us. We process it only to deliver, secure, support, and improve the Services as described in Section 11 and in our Master Terms & Conditions.
3. Call Recording, Voice Data, and AI Transcription & Summaries
Because these features raise questions that a general privacy policy does not answer, we address them directly.
Recording is a customer-controlled feature. Our customers decide whether to enable call recording, which calls are recorded, whether an announcement or periodic tone is played, and how long recordings are kept. Our customers are solely responsible for obtaining any consents and providing any notices required by law. Federal law and the laws of many states govern the recording of telephone conversations, and several states — including Connecticut, California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington — require the consent of all parties. Our Master Terms & Conditions place this responsibility on the customer and require the customer to indemnify us for claims arising from their recording practices.
AI transcription and summaries. Where enabled, we use automated speech-recognition and artificial-intelligence technology to generate written transcriptions of call recordings and concise summaries of those calls. Transcriptions and summaries are produced by automated means without human review unless expressly stated otherwise. Transcriptions and summaries may contain errors, and summaries are derived from transcriptions and may compound any inaccuracy in them. The original audio recording — not the transcription or summary — is the authoritative record of any call, and in the event of any discrepancy the recording governs.
Aggregated and de-identified data. As permitted by our Master Terms & Conditions, we may generate aggregated and de-identified statistics from use of the Services for analytics, benchmarking, capacity planning, and product improvement. Such data does not identify any customer, individual, or call, and we do not attempt to re-identify it.
4. How We Use Information
We use information to provide the Services (provisioning, routing calls and messages, delivering recordings, transcriptions, and summaries, maintaining integrations); for billing and collections (invoicing, processing ACH and card payments, dunning, credit evaluation, recovering amounts owed); for support (diagnosing faults, responding to tickets, training our support staff); for security and abuse prevention (fraud and toll-fraud monitoring, authentication, logging, incident investigation); for service improvement (performance monitoring, capacity planning, and product development using aggregated and de-identified data); for communications (service notices, maintenance and outage notifications, renewal reminders, policy updates); for marketing to business contacts, subject to your right to opt out; and for legal and compliance purposes (meeting telecommunications, tax, and recordkeeping obligations, responding to lawful requests, and establishing, exercising, or defending legal claims).
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
5. Gramm-Leach-Bliley Act and Insurance Industry Customers
Many of our customers are insurance agencies and brokers that qualify as “financial institutions” under the Gramm-Leach-Bliley Act (GLBA) and are subject to state insurance data security laws. Where we process nonpublic personal information on behalf of such a customer, we act as that customer’s service provider. We use nonpublic personal information solely to provide the Services to that customer and for no independent purpose; do not disclose it except as permitted by our agreement with the customer or as required by law; maintain administrative, technical, and physical safeguards designed to protect its security, confidentiality, and integrity, as described in Section 10; and will enter into a written agreement addressing these obligations where a customer requires one. The customer remains responsible for its own GLBA and state insurance data security obligations, including providing privacy notices to its clients and honoring opt-out rights.
6. How We Share Information
We disclose information only as described here. We do not sell personal information.
Service providers and subprocessors. We use vendors who process information on our behalf under written contracts limiting their use of it, including our telephony provider (RingCentral) and underlying carriers, cloud hosting and storage providers, an AI transcription and summarization provider, payment processors, our e-signature provider (PandaDoc), and CRM, support, email, and analytics providers. A current list of subprocessors is available on request at [email protected].
Integration partners. Where a customer authorizes an integration, we exchange data with that application at the customer’s direction.
Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred, subject to the acquirer’s obligation to honor this policy for previously collected information.
Legal and safety. We may disclose information to comply with applicable law, subpoena, court order, or lawful request from a regulator, law enforcement, or telecommunications authority; to enforce our agreements; or to protect the rights, property, or safety of EcoLink, our customers, or others. Where legally permitted, we will notify the affected customer before disclosing customer content so they may seek protective relief.
With your direction. We share information at your direction or with your consent.
7. Data Retention
We keep information only as long as necessary for the purposes described in this policy or as required by law. Call recordings, transcriptions, and summaries are retained according to the customer’s configured retention setting and are deleted within a commercially reasonable period after account termination, unless the customer requests earlier deletion or export. Call detail records are retained as needed to meet billing, dispute, and regulatory obligations. Account, contract, and billing records are retained for the duration of the relationship and for a period afterward as needed for tax, audit, and limitations purposes. Support communications, security and access logs, and website analytics are retained for reasonable periods. Marketing contact data is retained until you opt out, plus a suppression record retained to honor your opt-out.
Customers control retention of their own content. Customers may configure retention periods where the Services support it and may request export or deletion of their content in accordance with our Master Terms & Conditions. We may retain information where necessary to comply with law, resolve disputes, or enforce our agreements, and we retain backup copies for a limited period consistent with our backup cycle.
8. Cookies and Tracking
Our website uses cookies and similar technologies for strictly necessary purposes (security, session management, load balancing, which cannot be disabled), functional purposes (remembering preferences), analytics (understanding how the site is used), and marketing (measuring campaign effectiveness). You can control cookies through your browser settings; blocking strictly necessary cookies may prevent parts of the site from working. We honor the Global Privacy Control (GPC) signal where required by applicable law.
9. Your Privacy Rights
9.1 Rights under U.S. state privacy laws. Depending on where you live, you may have the right to know what personal information we have collected, used, and disclosed about you; to access a copy of that information; to correct inaccurate personal information; to delete your personal information; to obtain a portable copy of information you provided; to opt out of sale, sharing for targeted advertising, or profiling with legal or similarly significant effects (we do not engage in any of these); and to appeal a denial of a request. These rights apply in states including California (CCPA/CPRA), Texas (Texas Data Privacy and Security Act), Connecticut (CTDPA), Colorado, Virginia, Utah, Oregon, Montana, and others as their laws take effect. We will not discriminate against you for exercising any of these rights. Most U.S. state privacy laws do not apply to information collected in a purely business-to-business context; we will still honor requests where we can reasonably do so.
9.2 How to exercise your rights. Email [email protected] or write to us at the address in Section 14. We will acknowledge your request and verify your identity, which may require additional information; respond within 45 days, extendable once by an additional 45 days with notice; and tell you the reason if we deny your request, and how to appeal. Authorized agents may submit requests with proof of authorization. If we deny your request, you may appeal by replying to our decision or writing to [email protected] with “Privacy Appeal” in the subject line; we will respond within 60 days, and if your appeal is denied you may contact your state attorney general.
9.3 If your information came to us through one of our customers. We cannot honor access or deletion requests for customer content directly. If you were a caller to an insurance agency or other business that uses EcoLink, that business controls your information — contact them. If you contact us, we will refer your request to the relevant customer and support their response, but we will not disclose or delete their data without their instruction.
9.4 Marketing opt-out. Every marketing email includes an unsubscribe link. You may also email [email protected]. Service, billing, security, and legal notices are not marketing and will continue.
10. Security
We maintain a written information security program with administrative, technical, and physical safeguards appropriate to the nature of the information we process, including role-based and least-privilege access controls, encryption of data in transit and at rest, logging, monitoring, and alerting, vulnerability management and periodic assessments, documented incident response procedures, background screening and security training for personnel, and vendor security review for subprocessors.
If we confirm a security incident affecting customer content or personal information, we will notify affected customers without undue delay and cooperate reasonably in their own notification obligations, as set out in our Master Terms & Conditions. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur. Customers are responsible for safeguarding their own credentials, managing their administrative users, and configuring the Services appropriately.
11. Our Role as a Service Provider
For most information flowing through the Services, our customer is the controller and EcoLink is the processor or service provider. This means we process customer content only on the customer’s documented instructions, set out in our Master Terms & Conditions and any signed data processing addendum; we do not use customer content for our own purposes, except to provide, secure, and support the Services and to produce aggregated, de-identified analytics; we do not sell customer content or disclose it to third parties except as described in Section 6; our customer — not EcoLink — is responsible for the lawfulness of the data it collects, for obtaining recording consents, for providing privacy notices to its own clients, and for responding to privacy rights requests from its own clients; and on termination, we make customer content available for export and then delete it in accordance with our Master Terms & Conditions and Section 7. Customers who require a formal Data Processing Addendum (DPA) may request one at [email protected].
12. Data Location and International Transfers
We process and store information in the United States. We do not guarantee that data will remain within any particular jurisdiction, and our subprocessors may process data in the United States or other locations. Our Services are directed to businesses in the United States, and we do not market to individuals in the European Economic Area, United Kingdom, or Switzerland. If you access our Services from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
13. Children’s Privacy
Our Services are business tools not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn we have collected such information other than incidentally as part of a recorded call placed to one of our customers, we will delete it.
14. Changes to This Policy and How to Reach Us
Changes. We may update this policy. We will post the revised version with a new “Last Updated” date and maintain a dated archive of prior versions. If we make a material change that reduces the protections applicable to information we already hold, we will provide at least 30 days’ advance notice to affected customers by email or through the Services. Your continued use of the Services after the effective date constitutes acceptance.
Relationship to our other terms. This policy is incorporated by reference into our Master Terms & Conditions. In the event of a conflict between this policy and a signed agreement, the signed agreement controls.
Contact us. Inteveo EcoLink, LLC, Attn: Privacy, 500 E 4th Street, Suite 132, Austin, TX 78701. Email: [email protected].
Companion documents.
- Master Terms & Conditions — /terms-conditions
- Acceptable Use Policy — /acceptable-use-policy
- Service Level Agreement — /service-level-agreement
- Legal hub — /legal