Privacy Policy

Version 2026.07.21-1 · The English version controls; the Chinese translation is for convenience only.

English controlling version **Operator** POM Insurance Agency Inc, doing business as POM Peace of Mind Insurance Agency, a California corporation with S corporation tax status **Domains** https://seminar.pom365.com/; https://training.pom365.com/ **Version** 2026.07.21-1 **Effective date** Effective when accepted by the user after final company approval **Contact** [email protected]; 1900 S Norfolk Street, Suite 350, San Mateo, California 94403 **PLAIN-LANGUAGE SUMMARY** We use personal information to operate a U.S.-only training platform, verify eligibility and licenses, communicate, secure accounts, support approved professional workflows, analyze and improve the service, and comply with law. We do not sell personal information or share it for cross-context behavioral advertising. Marketing communications are optional. ## 1. Scope and Controller This Privacy Policy explains how POM Insurance Agency Inc, doing business as POM Peace of Mind Insurance Agency, a California corporation with S corporation tax status collects, uses, discloses, retains, and protects personal information through POM365 and the domains listed above. California insurance agency license 0N02495. The operator determines the purposes and means of Platform processing. Marketing and platform support may be provided to the operator by Peace Of Mind Global Asset Management A Professional Corporation under service-provider and confidentiality controls. This Policy applies to visitors, account holders, candidates, consumers, licensed professionals, agency owners, employees, contractors, and other U.S. users. Separate privacy notices may apply to employment, background checks, client transactions, insurance applications, mortgage or real estate files, carrier contracting, or other regulated records. Those more specific notices control the subject they address. ## 2. Personal Information We Collect We collect information you provide, information generated through your use, information from authorized partners and public licensing sources, and information from service providers. The table describes current or enabled categories and our intended retention framework. Retention may be shorter, and legal holds or regulatory duties may require longer retention. **Category** **Examples** **Typical retention** Identifiers and Name, email, phone number, username, Account life plus 4 account data account ID, password hash, preferred years; credential language, authentication data, and security age/eligibility confirmation, and records may be account status. retained longer if needed for fraud prevention or legal claims. Profile and Optional profile or demographic Account life plus 4 relationship fields, including gender if enabled; years, or longer if data referrer or Member Code; organization, linked to role, track, agency, team, or sponsor compensation, information. contracting, or a dispute. Professional and Insurance license number and state, For the licensing data license status, appointments, relationship plus contracting status, agency or the longer of 7 hierarchy information, E&O status, years or the period producer track, and compensation required by eligibility. regulators, carriers, lenders, brokers, tax rules, or a legal hold. Training and Registrations, attendance, progress, Generally 4 years engagement data completions, quiz or exam results, after the activity; certificates, questions, chat, polls, longer if used for downloads, support activity, and licensing, content interactions. supervision, compensation, compliance, or a dispute. Communications Emails, support messages, displayed Communications and recordings name, typed questions, chat, and, only generally 4 years. when recording is activated with Operational notice, audio, video, voice, image, or recordings session recording data. generally 3 years unless published with permission, needed for compliance, or subject to a legal hold. Payment and Purchase, invoice, billing, refund, Generally 7 years transaction data subscription, tax, and transaction after the data. Stripe or another processor transaction or receives full payment credentials; we longer if required generally receive tokens, status, for tax, amount, and limited card details. chargeback, fraud, or legal purposes. Device, network, IP address, device and browser type, Security logs and usage data operating system, user agent, cookies, generally up to 24 session identifiers, login and months; aggregated security logs, referring pages, pages analytics may be viewed, and feature interactions. retained longer without direct identifiers. Geolocation data Approximate location inferred from IP Precise location is and, where a feature requests retained only as permission, precise location used for long as reasonably U.S.-only access, fraud prevention, necessary, security, regional content, or generally no more compliance. than 30 days unless needed for an incident, legal obligation, or user-requested feature. AI and inference Prompts, inputs, outputs, summaries, Generally 2 years data translations, recommendations, scores, or the related classifications, risk signals, account or learning preferences, and other compliance-record inferences generated through AI or period, whichever analytics. is reasonably necessary. ### Future sensitive or onboarding data If a future paid, licensing, contracting, compensation, identity-verification, or background-check workflow requires it, we may collect address, date of birth, Social Security or tax identification number, government ID or image, W-9 or tax forms, bank or commission-payment details, resume and work history, background-check information, or other sensitive records. We will present a supplemental notice at or before collection, use a designated secure channel, collect only what is reasonably necessary, and obtain any separate authorization required by law. A consumer report or background check will require a separate standalone disclosure and authorization. Do not send these items through live chat, open Q&A, or ordinary email. ## 3. Sources of Information - Directly from you, including registration, profile, forms, payments, communications, questions, uploads, and consent choices. - Automatically from browsers, devices, cookies, logs, analytics, location permissions, and security tools. - From a referrer, Member Code owner, agency, employer, contractor, broker, carrier, MGA, lender, training administrator, or other party involved in an authorized relationship. - From public or authorized licensing and regulatory sources, including state insurance databases, DRE, NMLS, and disciplinary or appointment records, as applicable. - From payment, communications, hosting, analytics, video, identity, fraud, and artificial-intelligence service providers acting for us. ## 4. How We Use Personal Information - Create, authenticate, administer, support, personalize, and close accounts; enforce age and U.S.-only restrictions. - Deliver courses, track attendance and progress, answer questions, issue completion records, provide replay, and manage events. - Verify licenses, appointments, affiliations, sponsorships, E&O coverage, contracting, eligibility, professional status, and compliance. - Administer Member Codes, relationship records, agency structures, leads, compensation eligibility, chargebacks, or other approved professional workflows. - Process separately authorized payments, subscriptions, refunds, tax records, and transaction support. - Send service messages and, with the required choice or consent, marketing emails, texts, calls, or other promotions. - Operate analytics and AI-assisted features, improve content and usability, detect fraud and abuse, secure systems, troubleshoot, and conduct quality assurance. - Comply with law, regulation, subpoenas, audits, licensing, tax, recordkeeping, dispute, safety, and enforcement obligations; protect users, Company, and others. - Evaluate or complete a merger, financing, restructuring, asset transfer, or sale, subject to confidentiality and applicable law. We do not use precise geolocation, government identifiers, financial credentials, or other sensitive information to infer characteristics unrelated to the disclosed purpose. We do not materially expand a purpose or collect a new sensitive category without an updated or supplemental notice when required. ## 5. How We Disclose Personal Information We may disclose information only as reasonably necessary for the purposes above, subject to contracts and access controls where appropriate, to the following categories: - Hosting and infrastructure providers, including Microsoft Azure. - Payment processors, including Stripe, for separately authorized transactions. - Communications providers, including Twilio, for enabled email, text, telephone, or verification functions. - Analytics providers, including Google Analytics, and embedded video providers such as YouTube or Vimeo. - Artificial-intelligence and technology providers, including OpenAI or other providers used for enabled AI features, under service terms and configurations intended to restrict use to our instructions. - Professional and regulated partners, such as brokers, carriers, MGAs, lenders, NMLS, licensing bodies, compliance providers, or contracting parties, when needed for a workflow you request or an existing authorized relationship. - Attorneys, auditors, insurers, investigators, regulators, law enforcement, courts, and other parties when reasonably necessary to comply with law, enforce rights, investigate misconduct, protect safety, or respond to a claim. - A successor, buyer, lender, or transaction advisor in a merger, financing, reorganization, asset transfer, or sale, subject to appropriate confidentiality and notice where required. Marketing and platform support may be provided to the operator by Peace Of Mind Global Asset Management A Professional Corporation under service-provider and confidentiality controls. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not currently use Meta Pixel, TikTok Pixel, retargeting pixels, or third-party advertising networks on the Platform. If that practice changes, we will update the notice and provide legally required choices before the change takes effect. ## 6. Cookies, Analytics, Embedded Media, Do Not Track, and GPC We use essential cookies and similar technologies for login, security, session continuity, preferences, language, and fraud prevention. Google Analytics may set analytics cookies or receive device and usage information to help us understand aggregate Platform use. Embedded YouTube or Vimeo content may allow those providers to collect device, cookie, and viewing information under their own policies. Browser settings may block or delete cookies, but essential functions may stop working. Because browsers do not provide a universally accepted Do Not Track standard, the Platform may not respond to legacy Do Not Track signals. Where applicable, we will process legally valid opt-out preference signals, including Global Privacy Control, as required by law. Because we do not sell or share personal information for cross-context behavioral advertising, such a signal generally will not change current practices but will be recorded or honored if required. ## 7. Artificial Intelligence and Automated Analysis AI and analytics may generate summaries, translations, recommendations, learning suggestions, scores, classifications, or security signals. These tools support people and do not replace required human judgment. We do not intend to make a decision that produces a significant legal or similarly significant effect solely through AI without a separate legally compliant process, notice, review, and any required right to access, correct, appeal, or opt out. Do not place client secrets, government identifiers, financial credentials, confidential carrier or lender information, or other sensitive data into an AI prompt unless the feature is expressly approved for that information. We may review or filter prompts and outputs for safety, security, compliance, and quality. ## 8. Communications Choices We send service communications needed to operate an account, such as verification, security, legal, licensing, course, schedule, and policy messages. Marketing email may be stopped through the unsubscribe link or by contacting us. Marketing text messages, automated or prerecorded calls, and artificial or AI-generated voice calls require the applicable separate consent and may be revoked by any reasonable method. Withdrawing marketing consent does not prevent account creation or continued access to otherwise available services. ## 9. Session Recordings and Media Not every session is recorded. When recording is enabled, we provide notice and obtain the applicable consent before entry. A recording may capture a displayed name, typed question, chat, poll, or other submission. Operational recordings may be used for compliance, quality assurance, replay, internal training, and dispute resolution. Identifiable public, advertising, recruiting, or social-media use requires a separate optional media release, unless the content is de-identified or another lawful basis applies. ## 10. Retention and Deletion We retain each category only as long as reasonably necessary for the disclosed purpose, the typical periods in Section 2, and applicable legal, licensing, carrier, lender, tax, accounting, security, dispute, or contractual requirements. We consider the sensitivity, volume, business need, risk of harm, availability of alternatives, and whether information can be aggregated or de-identified. We delete, de-identify, or securely destroy information when the retention purpose ends, unless a legal hold or other lawful exception applies. Deletion of an account does not require deletion of agreement versions, checkbox records, IP and device evidence, license or contracting history, compensation and chargeback records, transaction and tax records, regulatory records, opt-out suppression records, security incidents, or dispute evidence that we reasonably need to retain. ## 11. Security We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information. Measures include encrypted transmission, encryption at rest for sensitive fields, strong one-way password hashing, role-based access controls, logging, backups, vendor controls, incident response, and retention and deletion procedures. No system is completely secure. You must protect credentials, use secure devices, and promptly report suspected unauthorized access. ## 12. Your Privacy Choices and Requests Depending on your state and the law that applies, you may have rights to know or access personal information, correct inaccuracies, delete information, obtain a portable copy, opt out of sale, targeted advertising, or certain profiling, limit certain sensitive-data uses, appeal a refusal, or avoid unlawful discrimination for exercising rights. Even when a statute does not require a particular right because of Company's size or status, we generally will consider verified access, correction, and deletion requests in good faith, subject to legal and operational exceptions. Submit a request to [email protected]. State the brand, account email, request type, state of residence, and enough information for us to verify the request. We may request additional verification and may deny or limit a request where permitted, including to protect another person, preserve security, comply with law, retain required records, complete a transaction, exercise legal claims, or protect trade secrets. An authorized agent must provide proof of authority, and we may verify the request directly with the account holder. Where an appeal right applies, reply with "PRIVACY APPEAL." California residents may also request information under California's Shine the Light law regarding certain disclosures for another business's direct marketing. We do not disclose personal information to third parties for their own direct marketing in the manner covered by that law. ## 13. Sensitive Information and Data Minimization We limit sensitive-data access to people and providers with a legitimate need, use secure workflows, and seek to collect the minimum information reasonably necessary. Do not upload sensitive information unless the Platform specifically requests it through a secure field. If a field is optional, you may leave it blank. Gender or other demographic information should be optional and will not be used to make unlawful eligibility, licensing, employment, contracting, compensation, credit, housing, or insurance decisions. ## 14. Children and U.S.-Only Service The Platform is not directed to children and does not knowingly permit accounts for anyone under 18. If we learn that a minor created an account, we may close it and delete information as appropriate. The Platform is intended only for users in the United States and U.S. territories. Information is processed in the United States and may not be protected by laws of another country. ## 15. Changes to this Policy We may update this Policy to reflect legal, technology, vendor, security, data, or service changes. We will post the updated version and effective date. For a material change, we may provide email or in-platform notice and obtain new consent where law requires it. We will not use previously collected information for a materially incompatible purpose without the required notice and consent. ## 16. Contact Privacy requests and questions: [email protected]. Correspondence address: 1900 S Norfolk Street, Suite 350, San Mateo, California 94403. Please identify the POM365 account and request type. Version 2026.07.21-1.