Privacy Policy
Last updated
This policy explains how Wakim Works LLC, a Florida limited liability company, handles personal information in The Arsenal — a platform sold to licensed insurance producers and agencies.
Two different kinds of data, two different roles. This is the most important thing to understand about this policy.
Your account data — your name, email, producer number, and how you use the platform. We decide how this is handled, and this policy governs it directly.
Your client data — everything you enter about the people you serve. That belongs to you. We hold and process it on your behalf, under your instructions, and only to run the platform for you. We do not sell it, mine it, or use it for our own purposes.
If you are someone's client and you're reading this: we are not the business that collected your information. Contact your insurance agent — see "If you are a client".
1. Our two roles
When you sign up and use The Arsenal, we act as a controller (or "business") for your own account and usage information. We decide what to collect and why, and this policy is our notice to you.
When you enter information about your clients, we act as a processor (or "service provider") for you. You are the controller. You decide what to collect, from whom, and why; you provide the privacy notice your clients are entitled to; and we act only on your instructions. Our commitments in that role are set out in Section 6 of the Terms of Service.
2. Information we collect
Account information you give us
When you create an account we collect your email address, password (stored only as a hash by our identity provider — we never see it), full name, National Producer Number, and optionally your phone number, a professional profile URL, and a profile photo. If you enrol multi-factor authentication we store the associated secret.
Billing information
If and when paid subscriptions are enabled, payment card details are collected and processed by our payment processor. We receive only a token, the last four digits, and the transaction status. We do not store full card numbers for your subscription.
Client Data you enter
The platform is built to hold detailed records about your clients and prospects. Depending on what you enter, that can include:
- Identity and contact
- Name, address, phone, email, date of birth, gender, marital status, country of birth, driver's licence number
- Government identifiers
- Social Security number
- Financial
- Bank name, routing and account numbers, account type, payment card number, expiry, and security code, income, existing coverage
- Health
- Height, weight, tobacco use, medical conditions, medications, diagnosis and treatment timing, surgeries, hospitalisations, and underwriting questionnaire answers
- Other people
- Names, relationships, and allocation splits for beneficiaries — who are usually not your client
- Interaction
- Call notes, scripts, appointments, messages, uploaded documents, and status history
You choose what to enter. The platform does not require any particular field, and it does not acquire client information from any source other than you.
Information collected automatically
Our infrastructure and application logs record IP address, browser and device information, timestamps, and the requests made — the ordinary operational record any web service keeps. We also record errors and diagnostic information when something breaks, and changes to client records are written to an internal change log (see Section 6).
We do not use third-party analytics, advertising, or tracking services, and there are no advertising cookies on the platform. The cookies and local browser storage we use are strictly functional: keeping you signed in, remembering your layout and display preferences, and caching your own data for fast loading. There is nothing to opt out of because there is no tracking to opt out of. If that ever changes, this policy changes with it and we will tell you.
Data from services you connect
If you choose to connect a calendar or scheduling account, we receive the event information needed to display your schedule — and only what you authorised. We request read-only access where the feature allows it. You can disconnect at any time, which stops future syncing.
3. How we use information
- To provide the platform — authenticate you, store and return your records, run the underwriting rules engine, sync your calendar, send the notifications you asked for, and process payments.
- To support you — respond to the tickets and feedback you send. When you submit support requests or bug reports, what you write reaches us.
- To keep it working and secure — monitor availability, diagnose errors, investigate abuse, and prevent fraud.
- To improve the product — using aggregated, de-identified usage statistics, and using the feedback you choose to send. We do not mine your Client Data for product development, and we do not use it to train machine-learning models. The underwriting engine is a deterministic rule set; it does not learn from your records.
- To meet legal obligations — comply with law, respond to lawful requests, and enforce our Terms.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
4. Who we share information with
We share personal information only with the service providers that make the platform work, each under contract and only for the purpose listed:
- Amazon Web Services
- Hosting, database, file storage, encryption key management, identity, and email delivery. Client Data is stored here. United States.
- Slack
- Internal delivery of support tickets, feedback, and operational alerts you or the system generate. Not used for Client Data.
- Calendar synchronisation, only if you connect a Google account. Read-only.
- Calendly
- Booking import, only if you connect a Calendly account. Read-only.
- Twilio
- Voice and messaging features, where enabled. Handles phone numbers and message content for calls and texts you initiate.
- Stripe
- Subscription payment processing, once paid plans are enabled. Handles card details directly; we do not receive them.
We may also disclose information:
- to comply with law, legal process, or a lawful government request — and, where we are permitted to, we will notify you first so you can object;
- to enforce our Terms or protect the rights, safety, and property of anyone, including investigating suspected fraud or a security incident; and
- to an acquirer in a merger, acquisition, financing, or sale of assets — under confidentiality, with this policy continuing to apply to the transferred information until superseded by notice to you.
Your Client Data is never shared with other users of the platform. Every account sees only its own records, enforced on the server rather than in the browser.
5. How we protect information
The measures below are the ones actually in place today:
- Field-level encryption. Sensitive fields — Social Security number, banking details, payment card details, driver's licence number, date of birth, medical conditions, medications, and the underwriting questionnaire answers — are encrypted with envelope encryption backed by AWS Key Management Service before they are stored, and decrypted only to return them to the account that owns them.
- Encryption in transit and at rest. All traffic is over TLS; the underlying storage is encrypted at rest.
- Multi-factor authentication. Accounts use an authenticator-app second factor, so a password alone does not unlock data.
- Per-account isolation. Record access is enforced server-side against the authenticated identity, not by the client.
- Change log. Changes to client records are written to a hash-chained log that makes tampering detectable, so edits and deletions can be traced.
- Encrypted export. Data exports can be produced encrypted and decrypted with a page that works entirely offline.
- Point-in-time recovery on the data stores holding client records.
No system is perfectly secure, and we cannot guarantee absolute security. Your own practices matter too — protect your password and your second-factor device, and use the encrypted export option when taking data out of the platform.
If a breach affecting your data occurs, we will notify you without undue delay and give you the information you need to meet your own notification obligations — including to state insurance regulators, which in many states must be done within 72 hours.
6. How long we keep information
We keep account information while your account is open and for a reasonable period after closure, for legal, tax, and dispute-resolution purposes.
We keep Client Data for as long as you keep it. You can delete individual records from within the platform at any time. On termination, you have 30 days to export, after which we delete or de-identify it within a reasonable period. Residual copies may remain in encrypted backups until those backups expire on their normal schedule.
Two categories are deliberately not erasable on request. Entries in the tamper-evident change log cannot be selectively removed without destroying the property that makes the log trustworthy — that is what "tamper-evident" means. Records of which version of our legal documents you accepted, and when, are kept as compliance evidence. Both are retained after account closure. Neither contains the encrypted sensitive field values themselves.
Bear in mind that you may have your own record-retention obligations as a licensee, typically several years, which are yours to meet and may outlast your use of the platform.
7. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of the personal information we hold about you as a controller; to opt out of sale, sharing, or targeted advertising (we do none of these); to limit the use of sensitive personal information; and not to be discriminated against for exercising a right.
To exercise a right, email judewakim@wakimworks.com. We will verify your identity against your account before acting, and respond within the time the applicable law requires. You may use an authorised agent where the law allows. If we decline, we will explain why and how to appeal.
Requests about Client Data go to the agent, not to us. Where a request concerns information an agent entered about their client, we will direct the requester to that agent and assist the agent in responding.
8. If you are a client of an agent using The Arsenal
We are a software vendor to your insurance agent. Your agent — not Wakim Works — decided to collect your information, chose what to collect, and is responsible for telling you how they use it and for honouring your privacy rights.
Please contact your agent directly. If you cannot reach them and you believe your information is held in The Arsenal, email us at judewakim@wakimworks.com and we will make reasonable efforts to route your request to the right agent. We are generally not permitted to access, alter, or delete an agent's records at the request of someone other than that agent.
9. Health information and HIPAA
The platform holds detailed health information, and we treat it as sensitive regardless of which statute applies to it.
Life insurance is an "excepted benefit" under HIPAA, so a producer selling only life products is generally not a covered entity, and Wakim Works is generally not a business associate. Where you are handling protected health information on behalf of a covered entity — for example if you also sell Medicare Advantage or health products — a Business Associate Agreement is required in addition to our Terms. A template is published at /legal/baa/ and we will execute it on request.
Separately, your handling of consumer financial and health information is regulated by the Gramm-Leach-Bliley Act and your state's insurance privacy and data-security rules. Meeting those is your obligation as the licensee; we support it, and we will provide the vendor information your regulator or your agency requires.
10. Where information is processed
The Arsenal is operated from and stores data in the United States. It is offered to licensed United States insurance producers. If you access it from elsewhere, you are transferring information to the United States, where privacy laws differ from those in your country.
11. Children
The Arsenal is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 as a user. Client records may contain information about minors — for example a beneficiary — which you enter and control as the agent. If you believe a child has created an account, contact us and we will remove it.
12. Changes to this policy
We may update this policy. When we make a material change we will update the "Last updated" date above and ask you to accept the new version the next time you sign in. We keep a record of which version you accepted and when.
13. Contact us
- Entity
- Wakim Works LLC, a Florida limited liability company
- judewakim@wakimworks.com
- Privacy requests
- Same address — put "Privacy request" in the subject line
© 2026 Wakim Works LLC.
Also see the Terms of Service, the Beta Supplement, and the Business Associate Agreement.