Arentis Core

Privacy Policy

This Privacy Policy explains what information Arentis Core collects, how we use and protect it, how our Google and Microsoft integrations work, and the rights you have over your data.

Last Updated: August 7, 2026

1. Information We Collect

Arentis LLC, operating as Arentis Core (“Arentis,” “we,” “us”), is a cloud-based operating system for insurance agencies. We collect information in three ways: information you provide directly, information generated as you use the platform, and information we receive from third-party services you choose to connect.

  • Information you provide: account and agency registration details, billing contacts, support requests, documents you upload, and records you create in the CRM.
  • Information generated by use: log data, IP address, browser and device type, pages viewed, feature usage, audit events, and timestamps for security and troubleshooting.
  • Information from connected services: data returned by integrations you authorize, such as calendar events, lead forms, call and messaging metadata, or files, limited to the scopes you approve.

We do not require or request sensitive personal information beyond what is necessary to operate the features an agency enables.

2. Account Information

When you create an Arentis Core account we collect your name, work email address, password credentials (stored only as a salted hash by our authentication provider), agency name, role, and optional profile details such as phone number, time zone and photo.

Agency administrators can view membership, role assignments and audit activity for users in their own agency. Account information is used to authenticate you, enforce role-based access control, provide support, send service notices, and administer billing.

3. Customer Data

“Customer Data” means the records your agency stores in Arentis Core: leads, clients, applications, policies, quotes, commissions, documents, notes, tasks, call and message history, and related metadata about the consumers your agency serves.

Your agency is the controller of Customer Data. Arentis Core processes it as a service provider and processor, solely to deliver and support the platform under your instructions. Every record is scoped to a single agency tenant and enforced at the database layer through row-level security so that one agency can never read or write another agency’s data.

We do not sell Customer Data, we do not use it for advertising, and we do not use it to train general-purpose AI models.

4. Google Workspace Integrations

Arentis Core offers optional Google Workspace integrations. These are never enabled by default. Google user data is only accessed after you complete Google’s OAuth consent screen and explicitly authorize access.

  • Arentis only requests the permissions required for the features you enable.
  • OAuth access and refresh tokens are encrypted at rest and stored server-side only; they are never exposed to the browser or to other agencies.
  • Google user data is never sold, rented, or shared for advertising purposes.
  • Google user data is not used to train, retrain, or improve generalized artificial intelligence or machine learning models.
  • You can disconnect a Google integration at any time from Settings → Integrations, or by revoking access at myaccount.google.com/permissions. Revocation stops all future access immediately.

Arentis Core’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Google Calendar Integration

If you connect Google Calendar, Arentis Core reads availability and writes appointments so your booking pages, reminders and agent calendars stay in sync.

  • What we access: calendar list, busy/free windows, and the events Arentis creates or is asked to manage on your behalf.
  • Why: to prevent double-booking, publish accurate booking slots, create appointments from the CRM, and send confirmations and reminders.
  • What we store: event identifiers, start and end times, attendee email addresses for appointments booked through Arentis, and sync state. We do not copy your entire calendar history into the CRM.

Disconnecting the integration stops all calendar reads and writes.

6. Google Drive Integration

If you connect Google Drive, Arentis Core can attach documents to CRM records and store agency documents in folders you designate.

  • What we access: only files and folders you select or that Arentis Core creates. We request the narrowest available scope for the enabled feature and do not request broad read access to your entire Drive when a per-file scope is sufficient.
  • Why: to upload, retrieve and link policy documents, applications, illustrations and carrier paperwork to the correct client record.
  • What we store: file identifiers, names, MIME types, sizes and the CRM record each file is linked to. File contents are retrieved on demand and are not duplicated into our systems except where you explicitly import a copy.

7. Gmail Integration

If you connect Gmail, Arentis Core can send email from your address and log agency-relevant correspondence to the unified client timeline.

  • What we access: the ability to send messages on your behalf and, where you enable timeline logging, message metadata and content for threads involving contacts that exist in your CRM.
  • Why: to deliver follow-ups, appointment confirmations and agent correspondence, and to give your team a complete communication history for each client.
  • What we do not do: we do not scan your mailbox for advertising, do not read messages unrelated to your CRM contacts when logging is scoped, do not sell Gmail data, and do not use Gmail content for AI model training.

Human access to Gmail data is prohibited except with your explicit consent for a support request, where required for security investigations, or where required by law.

8. Microsoft 365 Integrations

Arentis Core offers equivalent optional integrations with Microsoft 365 (Outlook Calendar, Outlook Mail and OneDrive/SharePoint) through Microsoft Entra ID OAuth.

The same principles apply: access occurs only after explicit administrator or user consent, Arentis requests only the Microsoft Graph scopes required by the enabled feature, tokens are encrypted at rest, data is never sold, and you can revoke access at any time from Settings → Integrations or from your Microsoft account’s app permissions page.

9. AI Features

Arentis Core includes AI-assisted features such as lead scoring, call and message summaries, next-best-action suggestions, document extraction and underwriting assistance.

  • AI features process only the records needed to generate the requested output, scoped to your agency tenant.
  • We use enterprise AI providers under agreements that prohibit using your inputs or outputs to train their foundation models.
  • AI output is decision support, not professional, legal, underwriting or financial advice. A licensed human must review any AI-assisted recommendation before it is acted on.
  • Data obtained from Google or Microsoft integrations is never used to train generalized AI models.
  • Agency administrators can disable AI features for their tenant.

10. Cookies

We use a small number of cookies and equivalent browser storage mechanisms. Strictly necessary cookies keep you signed in, maintain your session and tenant context, and protect against cross-site request forgery. Preference storage remembers settings such as light or dark theme.

We do not use advertising cookies or third-party ad-network trackers. You can block or delete cookies in your browser, but the application will not function correctly without strictly necessary cookies.

11. Analytics

We collect aggregated product analytics — feature usage counts, performance timings and error reports — to diagnose problems and improve the platform. Analytics data is tied to account and agency identifiers rather than to the consumers in your CRM, and we do not send Customer Data or data obtained from Google or Microsoft APIs to analytics providers.

12. Security

Security is enforced at every layer of Arentis Core:

  • Encryption in transit: all communication with Arentis Core and with third-party providers occurs over HTTPS/TLS. Plain HTTP is not supported.
  • Encryption at rest: databases, file storage and backups are encrypted. OAuth credentials, API keys and provider secrets are additionally encrypted with application-layer keys held server-side.
  • Tenant isolation: row-level security policies enforce agency scoping on every table so data cannot cross tenant boundaries.
  • Access control: role-based permissions, least-privilege service credentials and signed, expiring URLs for private documents and call recordings.
  • Auditability: administrative and data-changing actions are recorded in an immutable audit log.
  • Webhooks: inbound provider webhooks are signature-verified before any data is processed.

No system can be guaranteed perfectly secure. If we become aware of a breach affecting your data, we will notify affected agencies without undue delay and as required by law.

13. Data Retention

We retain Customer Data for as long as your agency maintains an active subscription. After termination, Customer Data remains available for export for thirty (30) days, after which it is deleted or irreversibly anonymized within ninety (90) days, excluding encrypted backups that expire on their normal rotation schedule.

Audit logs, billing records and other records we are legally required to keep are retained for the applicable statutory period. Tokens for a disconnected integration are deleted when the connection is removed.

14. Data Sharing

We do not sell personal information or Customer Data. We share information only in these circumstances:

  • Subprocessors: vetted infrastructure, communications, payment and AI providers acting under contract and on our instructions.
  • At your direction: with integrations, carriers or recipients you choose to connect or send data to.
  • Within your agency: with users your administrators authorize, according to their assigned roles.
  • Legal and safety: where required by law, subpoena or valid legal process, or to protect the rights, property or safety of Arentis Core, our customers or the public.
  • Business transfer: in connection with a merger, acquisition or asset sale, subject to this Policy and with notice to affected customers.

15. User Rights

Subject to applicable law, you may request access to the personal information we hold about you, correction of inaccurate information, deletion, a portable copy, restriction of or objection to certain processing, and withdrawal of consent where processing relies on consent.

Consumers whose data appears in an agency’s CRM should contact that agency, which controls the data. Arentis Core will support its customers in responding to such requests. Requests to us can be sent to arianet.herrera.insurance@gmail.com; we will respond within the timeframe required by applicable law. We will not discriminate against you for exercising these rights.

16. California Privacy Rights

Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know what personal information is collected, used, disclosed and (if applicable) sold or shared; the right to delete; the right to correct; the right to opt out of sale or sharing; the right to limit the use of sensitive personal information; and the right to non-discrimination.

Arentis Core does not sell or share personal information as those terms are defined by the CCPA/CPRA, and has not done so in the preceding twelve months. With respect to Customer Data, Arentis Core acts as a service provider and processes personal information only for the business purpose of providing the platform. To exercise a right, email arianet.herrera.insurance@gmail.com with “California Privacy Request” in the subject line. Authorized agents may submit requests with proof of authorization.

17. GDPR Rights

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority.

For account information, Arentis Core is the controller. For Customer Data, your agency is the controller and Arentis Core is the processor under Article 28; a Data Processing Addendum is available on request. Our lawful bases include performance of a contract, legitimate interests in operating and securing the platform, consent where required (for example, for optional integrations), and compliance with legal obligations.

18. Children's Privacy

Arentis Core is a business tool intended solely for licensed insurance professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under 16 years of age. If we learn that we have collected such information without an appropriate legal basis, we will delete it promptly. Contact arianet.herrera.insurance@gmail.com if you believe a child has provided us information.

19. International Data Transfers

Arentis Core is operated from the United States and information may be processed in the United States and in other countries where our subprocessors operate. Where personal information is transferred out of the EEA, the United Kingdom or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical measures such as encryption in transit and at rest.

20. Third-Party Services

Arentis Core interoperates with third-party services you choose to connect, which may include Google, Microsoft, Meta, Twilio, WAVV, Calendly, Cal.com, Stripe, Dropbox and QuickBooks, as well as our hosting, database and AI infrastructure providers.

When you connect a service, that provider’s own privacy policy and terms govern its handling of your data. We are not responsible for the practices of third-party providers. A current list of subprocessors is available on request at arianet.herrera.insurance@gmail.com.

21. Contact Information

Questions, privacy requests or security reports can be directed to our team. We aim to acknowledge every request within five business days.

We may update this Privacy Policy from time to time. Material changes will be announced in the application or by email, and the “Last Updated” date above will be revised.