Evrcad Insurance Suite — Evrcad LLC | Version privacy-2026-07-25 | Last Updated: 2026-07-25

Privacy Policy

This Privacy Policy explains how Evrcad LLC collects, uses, and protects your information when you use the Evrcad Insurance Suite (the "Service").

01Scope and Relationship to HIPAA

What this Policy covers. This Privacy Policy applies to the Evrcad Insurance Suite, the Evrcad website, and related support and communications (collectively, the "Service"). It describes how Evrcad LLC ("Evrcad," "we") handles two different categories of information:

Customer information — information about the licensed agents, agencies, and their personnel who hold Evrcad accounts (account, billing, device, and usage information). Evrcad determines how this information is used, and this Policy governs it.

Client information — information about Medicare beneficiaries and prospects that customers enter into, generate in, or transmit through the Service. Evrcad handles this information only on the customer's behalf and on the customer's instructions, and does not use it for its own purposes.

Our HIPAA role. Protected Health Information ("PHI") has the meaning given in 45 C.F.R. § 160.103. Where a customer is a HIPAA covered entity, Evrcad acts as that customer's business associate. Where a customer is itself a business associate of a health plan, carrier, or other covered entity, Evrcad acts as a subcontractor business associate and is bound by the same obligations. In either case, Evrcad's handling of PHI is governed by the executed Business Associate Agreement ("BAA") described in Section 6. Evrcad applies the same safeguards to client information regardless of a customer's regulatory characterization.

Your role. You — the agent or agency — determine what client information is collected, what is entered into the Service, how long it is kept beyond our minimums, and who within your organization may access it. You are responsible for your own HIPAA, CMS, carrier, and state-law obligations, including any notice of privacy practices, consents, or authorizations you owe your clients.

Order of precedence. If any term of this Policy conflicts with the BAA with respect to PHI, the BAA controls. This Policy does not modify, limit, or substitute for a BAA.

Information outside HIPAA. Not everything the Service handles is PHI. Account, billing, marketing, device, and usage information about you is not PHI and is governed by this Policy and applicable state privacy, telecommunications, and consumer protection law. Some information is also subject to CMS Medicare marketing rules and record-retention requirements independent of HIPAA (see Section 7).

Beneficiaries and end clients. Evrcad has no direct relationship with your clients. If you are a Medicare beneficiary whose information is stored in the Service, direct requests for access, correction, or deletion to the agent or agency you worked with, or to your plan. See Section 9.

02Information We Collect

Account and Profile Information. Name, email address, business address, phone number, organization/agency name and role, and login credentials and authentication information.

Client and PHI Data. Agents and agencies may store client information including beneficiary name and contact information, demographic information such as date of birth and address, Medicare-related data such as plan type, plan name, and enrollment dates, notes and documentation, SOA forms and related documents, call recordings of marketing and enrollment calls, and SMS content sent via the platform subject to PHI restrictions in the Terms of Service. These data may be PHI under HIPAA when associated with a beneficiary.

AI Voice Secretary Recordings and Transcripts. If you enable the optional AI Voice Secretary, inbound calls that the feature handles (for example, missed or after-hours calls) are recorded and converted to text transcripts, along with call metadata such as caller number, time, and duration and a short summary generated for your review. Recordings and transcripts are processed and stored using Evrcad's HIPAA-eligible AWS services under the AWS BAA. See Section 4 (AI Features and Your Data) for how this feature works, its caller disclosure, and its limitations.

Geolocation and Device Data. IP address and approximate location inferred from IP; GPS coordinates at specific compliance events (SOA signing, appointment completion, clock-in/clock-out); and device identifiers, browser type, and operating system. Evrcad does not perform continuous background tracking; geolocation is captured only at discrete compliance-related events.

Usage Data. Access times and dates, pages and features accessed, clickstream data, and error logs and performance metrics.

Payment Information. Subscription payments are processed by a third-party payment processor. Evrcad receives only limited billing information from the processor, such as card brand, the last four digits of the card, expiration date, and payment status. Evrcad does not collect or store full payment card numbers or card security codes. The payment processor handles your payment card information under its own privacy policy and applicable payment-card industry security standards. Our current payment processor is identified in Section 5 (How We Share Information) and on our subprocessor list.

03How We Use Information

Providing and Operating the Service. To create and authenticate accounts, deliver the CRM, calendar, document, telephony, and reporting features you enable, store and retrieve your client records, and maintain the availability and performance of the Service.

Acting on Your Instructions. Client information and PHI are used only to perform the Service for you and on your behalf, as described in the Business Associate Agreement. Evrcad does not use client information for its own independent purposes.

Communications with You. To send transactional and service messages, including account, security, billing, and support notices, product and feature announcements, and responses to your inquiries. Service and security messages are not optional while you hold an account.

Billing and Account Administration. To process subscription payments, manage trials, seats, and plan changes, and maintain financial and tax records.

Support and Troubleshooting. To diagnose errors, respond to support requests, and investigate reported problems. Support personnel access client data only as necessary to resolve an issue, subject to access controls and audit logging.

Security, Fraud Prevention, and Integrity. To authenticate users, detect and investigate unauthorized access, abuse, or fraud, maintain audit logs, enforce our Terms and Acceptable Use Policy, and protect the rights and safety of users and third parties.

Compliance and Recordkeeping. To meet Evrcad's obligations and to support yours under HIPAA, CMS Medicare marketing and enrollment requirements, carrier and FMO agreements, and other applicable law — including retaining Scope of Appointment forms, call recordings and transcripts, and audit logs as described in Section 7.

AI Features. To provide the optional AI features you enable, subject to the limits, PHI minimization, and compliance guardrails described in Section 4.

Service Improvement. To understand how the Service is used and to improve reliability, performance, and functionality. For this purpose, Evrcad uses account and usage information and aggregated or de-identified data; PHI is not used to develop or improve the Service except as permitted by the Business Associate Agreement.

Legal Obligations. To comply with law, respond to lawful requests, and establish, exercise, or defend legal claims, as further described in Section 5.

What We Do Not Do. Evrcad does not sell client information or PHI, and does not use PHI for advertising, marketing to beneficiaries, or building advertising profiles. Disclosures to service providers and subprocessors are described in Section 5.

04AI Features and Your Data

AI Providers and Scope. Evrcad uses AWS Bedrock to provide AI functionality such as drafting suggested responses, summarizing interactions, and operating the AI Voice Secretary. PHI used in AI prompts is limited to what is necessary for the feature (e.g., first name, context of prior messages, agent/agency name). We do not include Medicare Beneficiary ID numbers, dates of birth, diagnoses, or specific plan identifiers in AI prompts.

No Model Training on Your Data. Under AWS Bedrock's policy, prompts and outputs sent through Bedrock are not used to train or improve the underlying foundation models used by other customers. Your AI usage is logically isolated to Evrcad's AWS account.

AI Is Optional and Assistive. AI outputs are suggestions only. You retain control and responsibility for reviewing, editing, and approving all AI-generated content before sending it to clients. Further detail is in the AI Features & Disclosure Notice.

AI Voice Secretary (Recorded and Transcribed Calls).

The AI Voice Secretary is an optional feature that an agent may turn on to answer inbound calls on the agent's behalf — for example, calls that would otherwise be missed, busy, or received after hours. When it handles a call, the AI Voice Secretary records the call and creates a written transcript so that you have an accurate record of the conversation and any message the caller leaves.

  • Caller disclosure. At the start of a call it handles, the AI Voice Secretary plays an automated announcement telling the caller that they are speaking with an automated assistant and that the call is being recorded, before the conversation continues.
  • How it is processed. Call audio is transcribed and handled using Evrcad's HIPAA-eligible AWS services (including transcription and the Bedrock AI model) under the AWS BAA. Telnyx carries the call as a conduit only (see Section 6). Recordings and transcripts are stored in Evrcad's encrypted AWS storage.
  • PHI minimization. The AI model receives only the limited information needed to handle the call. Where the feature is used to help service a known client, any identity check returns only a yes/no result to the system; the AI model is not given raw identifiers such as full dates of birth or Medicare Beneficiary IDs.
  • Compliance guardrails. Consistent with CMS rules for third-party marketing organizations, the AI Voice Secretary does not recommend plans, quote premiums, or discuss specific plan benefits.
  • Your responsibility for consent. Call-recording consent laws vary by state, and some states require the consent of all parties. Although Evrcad provides the automated recording announcement described above, you (the agent or agency) are responsible for ensuring that recording and its use comply with the laws that apply to you and your callers.
  • Recordings and transcripts created by the AI Voice Secretary are retained under the schedule in Section 7 (Data Retention).

    05How We Share Information

    The following are Evrcad's current subprocessors as of the date of this Policy. This list is a snapshot; the authoritative current list is maintained at https://insurance.evrcad.com/subprocessors, and subprocessors may change as described under "Changes to Subprocessors" below.

  • Amazon Web Services (AWS) for cloud hosting, databases (RDS), storage (S3), authentication (Cognito), logging (CloudWatch/CloudTrail), and AI inference (Bedrock) — covered by an executed BAA for HIPAA-eligible services.
  • Telnyx for voice and SMS delivery as a communications conduit — Evrcad relies on the HIPAA conduit exception rather than a BAA with Telnyx. Call recordings are written directly to Evrcad's AWS S3 bucket. Telnyx stores SMS message body text for a limited period (up to 10 days per Telnyx's documentation) before wiping it; because Evrcad prohibits PHI in SMS, the content Telnyx temporarily stores is non-PHI. Telnyx retains limited call/message metadata such as timestamps and phone numbers. MMS is disabled.
  • A third-party payment processor for subscription billing and payment card processing. Evrcad's current payment processor is Stripe. The payment processor does not receive PHI. AWS SES for transactional email (covered under AWS BAA), configured to avoid PHI.
  • Google and Apple for OAuth authentication if you choose to log in with those accounts.
  • Within Your Organization. If you are an agent within an agency, your data including client records, call recordings, and logs may be accessible to your agency administrators for supervision, compliance, and management.

    Legal and Safety. We may disclose information as necessary to comply with law, protect rights or safety, address security or fraud issues, and enforce our Terms.

    Business Transfers. If Evrcad is involved in a merger, acquisition, financing, or sale, information may be transferred subject to obligations no less protective of PHI and regulatory records than those described here, and any acquiring entity will be bound by the same CMS and HIPAA retention obligations. We will provide notice consistent with applicable law.

    Aggregated and De-identified Data. We may share aggregated or de-identified data that does not reasonably identify you or any individual.

    06HIPAA and PHI

    BAA with Customers. Evrcad will enter into Business Associate Agreements with eligible covered entities and business associates. The BAA is presented for acceptance during onboarding and is available at https://insurance.evrcad.com/baa or from legal@evrcad.com. This Privacy Policy does not modify any BAA and is not a substitute for a BAA.

    PHI Storage Locations. Evrcad stores PHI only in HIPAA-eligible AWS services under the AWS BAA, including RDS and S3. Call recordings, transcripts, and SOA documents are stored in encrypted S3 buckets. SMS content is stored in RDS. Logging systems may contain PHI as necessary for audit and security purposes.

    Telnyx as Telephony Conduit. Telnyx is used solely to transmit voice calls and SMS messages. Call recordings are written directly to Evrcad's S3 bucket via Telnyx's external storage configuration and are not retained by Telnyx after transfer. Telnyx stores SMS message body text for a limited period (up to 10 days per Telnyx's documentation) before wiping it; because Evrcad prohibits PHI in SMS by policy and platform controls, the content Telnyx temporarily stores is non-PHI, and Evrcad's conduit posture does not depend on Telnyx retaining no content. Telnyx retains limited metadata such as from/to numbers and timestamps. Evrcad additionally disables MMS. Evrcad relies on the HIPAA conduit exception (45 CFR §164.502(e)(1)(ii)) for Telnyx's limited, transient handling of information in transit; Telnyx is not Evrcad's Business Associate.

    Breach Notification. Where Evrcad acts as a Business Associate, and consistent with the Business Associate Agreement, Evrcad will notify affected customers of a breach of unsecured PHI without unreasonable delay and no later than [thirty (30)] days after discovery, providing the information the customer needs to meet its own notification obligations.

    Multi-Tenant Data Isolation. Evrcad implements logical separation of customer data through tenant identifiers, Row-Level Security (RLS) in the database, and strict access controls in application logic. Users from one organization cannot access another organization's data.

    07Data Retention and Service Continuity

    SOA Forms: at least ten (10) years to comply with CMS requirements.

    Call Recordings and AI Voice Secretary Transcripts: Effective October 1, 2026, Medicare marketing and sales call recordings (including recordings and transcripts created by the AI Voice Secretary) are retained for at least six (6) years (audio for years 1–3; audio or a complete and accurate transcript for years 4–6), and Medicare enrollment records — including the enrollment portion of any call — are retained for at least ten (10) years, unless a longer period is required by law, carrier contract, or FMO agreement.

    HIPAA Audit Logs: at least six (6) years, consistent with HIPAA documentation retention requirements.

    Client and PHI Data: for the duration of your subscription and any applicable retention period required by law or carrier contract. PHI is deactivated but not deleted while retention obligations remain active.

    Payment and Billing Records: as required by tax, accounting, and financial regulations and Stripe's retention policies.

    Retention Following Service Discontinuation. CMS and HIPAA record-retention obligations for Scope of Appointment forms, call recordings and transcripts, and related compliance records rest with the agent or agency of record, not with Evrcad as a software vendor. If Evrcad discontinues the Service, we will provide reasonable advance notice and a defined export period — not less than [sixty (60)] days — during which you may retrieve your records in a usable electronic format, and we will assist in delivering those records to you or to a custodian you designate. Following delivery and expiration of the export period, Evrcad's retention responsibility ends, and you remain responsible for retaining your records for the full periods required by law, carrier contract, or FMO agreement. Evrcad's handling and return or destruction of PHI on termination is governed by the Business Associate Agreement. You should always maintain your own copies of compliance records, independent of the Service.

    08Data Security

    Evrcad maintains administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure, consistent with the HIPAA Security Rule.

    Encryption. Data is encrypted in transit using TLS and at rest using encryption provided by our cloud infrastructure provider, including database and file storage encryption.

    Access Controls. Access to production systems and customer data is restricted to authorized personnel on a least-privilege basis. Application and database access is enforced through role-based controls, and customer data is logically isolated between organizations through tenant identifiers and database row-level security.

    Authentication. Accounts are protected by credential-based authentication, and Evrcad supports authentication through third-party identity providers. You are responsible for maintaining the confidentiality of your login credentials and for the activity of users you authorize.

    Logging and Monitoring. Evrcad maintains audit logs of access to systems containing PHI and monitors for security-relevant events, as further described in Section 7.

    Infrastructure. The Service runs on HIPAA-eligible cloud services covered by an executed Business Associate Agreement, in data centers maintained by the infrastructure provider with their own physical and environmental controls.

    Incident Response. Evrcad maintains a written incident and breach response plan and will notify affected customers of a breach of unsecured PHI as described in Section 6.

    No Guarantee. No method of transmission or storage is completely secure. While Evrcad works to protect your information, we cannot guarantee absolute security, and you use the Service with that understanding.

    09Your Choices and Rights

    Access and Correction. If you have an account, you may access and update profile information through the Service. End clients of an agency should direct requests for access or correction to the agency; Evrcad acts as a processor on the agency's behalf.

    Data Export and Portability. Agency administrators may request a comprehensive export of their organization's data at any time through account settings or by contacting support@evrcad.com.

    Deletion. Because Evrcad must comply with regulatory retention requirements (CMS and HIPAA), we cannot delete PHI or regulated records on request while mandatory retention periods remain active. Where deletion is legally permissible, we will honor requests from authorized account owners or administrators.

    Marketing Communications. Evrcad does not use PHI for marketing. For non-transactional product communications, you may opt out via unsubscribe links.

    State Privacy Rights. Several U.S. states have enacted consumer privacy laws that give residents rights to know what personal information is collected about them, to access, correct, or delete it, to obtain a copy, and to opt out of its sale or of targeted advertising. Whether these rights apply depends on your state of residence and on whether the law applies to Evrcad and to the information at issue.

    Health information is generally excluded. Most state privacy laws exclude protected health information handled under HIPAA, and many exclude covered entities and business associates altogether. Client information that Evrcad processes on behalf of an agent or agency is generally governed by HIPAA and the Business Associate Agreement rather than by state consumer privacy law.

    Our role determines where to send a request. Evrcad acts as a service provider or processor for client information. If you are a Medicare beneficiary or other end client, the agent or agency you worked with — not Evrcad — is responsible for responding to your privacy rights request. Please direct your request to them, or to your plan. If we receive a request directly, we will refer it to the applicable customer and assist that customer in responding, as required by our agreements.

    Account holders. If you hold an Evrcad account, you may access and update your profile information in the Service, request a copy of your organization's data as described above, or contact us at privacy@evrcad.com.

    What we do not do. Evrcad does not sell personal information, does not share personal information for cross-context behavioral or targeted advertising, and does not use personal information for automated decision-making that produces legal or similarly significant effects. See Section 10.

    Submitting a request and appeals. To exercise a right, contact privacy@evrcad.com with "Privacy Request" in the subject line. We will verify your identity before responding and will respond within the time period required by applicable law. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome and, where applicable law provides one, of your right to contact your state attorney general.

    10Cookies, Tracking, and Similar Technologies

    We use cookies and similar technologies only for essential purposes such as authentication, session management, load balancing, and security. You may adjust your browser settings to manage cookies, but disabling essential cookies may limit functionality.

    No third-party advertising or analytics trackers on authenticated or PHI-bearing pages. We do not deploy third-party advertising or marketing tracking technologies — such as the Meta (Facebook) Pixel, Google Ads or advertising tags, TikTok, LinkedIn, or similar pixels, tags, or software development kits — on any authenticated area of the Service or on any page that accesses, displays, or processes PHI or client data. We do not use these technologies to build advertising profiles of you or your clients, and we do not permit third parties to place such trackers within the Service.

    No disclosure of identifiers to advertising vendors in connection with PHI. We do not transmit IP addresses, device identifiers, cookie identifiers, or page-activity information to advertising or marketing vendors in connection with PHI or the healthcare context of the Service.

    11Children's Privacy

    The Service is a business tool intended solely for licensed insurance agents, agencies, and their authorized personnel. Users must be at least 18 years of age and legally able to enter into a contract. The Service is not directed to children, and Evrcad does not knowingly permit children to create accounts or use the Service.

    Evrcad does not knowingly collect personal information directly from children. If we become aware that a child has created an account or submitted information to us directly, we will delete that account and information promptly.

    Information about clients. Client information in the Service is entered by agents and agencies about their own clients and prospects, and Evrcad processes that information on their behalf. Medicare beneficiaries are predominantly adults, but eligibility is not limited by age in all circumstances. Where a customer's client records include information about a minor, that information is handled as client information under this Policy and, where applicable, as PHI under the Business Associate Agreement — not as information collected by Evrcad from a child. The agent or agency is responsible for obtaining any consent required to collect and share that information and for its accuracy and lawful use.

    Requests concerning a minor's information stored in the Service should be directed to the agent or agency that maintains the record. See Section 9.

    If you believe a child has provided information to Evrcad directly, contact privacy@evrcad.com.

    12International Users

    The Service is intended for use in the United States by licensed insurance agents and agencies serving U.S. Medicare beneficiaries. Evrcad does not offer or market the Service outside the United States and does not target users in other countries.

    Evrcad stores and processes information on cloud infrastructure located in the United States. If you access the Service from outside the United States, you do so on your own initiative, you are responsible for compliance with any local laws that apply to you, and you understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those of your location.

    Evrcad does not offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and does not undertake obligations under the EU or UK General Data Protection Regulation.

    13Changes to This Privacy Policy

    Evrcad may update this Privacy Policy from time to time to reflect changes in our practices, our subprocessors, the features we offer, or applicable law. When we make changes, we will revise the "Last Updated" date and version identifier at the top of this Policy.

    Notice of material changes. If we make a material change to how we handle client information or PHI, we will provide notice to account holders by email or within the Service at least [ten (10)] days before the change takes effect, except where a shorter period is required to comply with law. Changes to our subprocessors are handled as described in Section 5.

    Your continued use. Your continued use of the Service after a revised Policy takes effect constitutes your acknowledgment of the revised Policy. If you do not agree to a revised Policy, you should stop using the Service and may terminate your subscription as provided in the Terms of Service.

    Relationship to other agreements. This Policy does not amend the Terms of Service or the Business Associate Agreement. The Business Associate Agreement may be amended only as that agreement provides, and a change to this Policy does not by itself change Evrcad's obligations under it.

    Prior versions. Prior versions of this Policy are available on request at privacy@evrcad.com.

    If any provision of this Policy is or becomes inconsistent with HIPAA, CMS requirements, or other applicable federal or state law, the requirements of applicable law control, and the inconsistent provision will be interpreted and applied to the minimum extent necessary to conform to law. The remaining provisions remain in effect. Evrcad may revise this Policy at any time to correct errors, resolve inconsistencies, or conform to legal requirements, and will do so promptly upon becoming aware of the need. No such revision is an admission of any violation.

    14Contact Us

    Email (legal) legal@evrcad.com – Email (support): support@evrcad.com