Privacy Policy

VRM Office · Version 1.0 · Effective September 28, 2026 · Last updated September 28, 2026

1. Scope

This Privacy Policy explains how VRM Office collects, uses, discloses, retains, and protects personal information when individuals use an agent-branded client application, educational artificial intelligence assistant, website, Progressive Web Application, or related service powered by VRM Office (collectively, the "App"). It also applies to related onboarding, approval, support, security, and administrative activities.

This Policy does not govern an Agent's independent business practices, records, websites, communications, product recommendations, or professional services. The Agent should provide any separate privacy notice required for those activities. A third-party website or service linked from the App is governed by its own privacy terms.

2. Who We Are and Our Role

VRM Office provides and owns the software platform used to deliver the App. Your assigned Agent owns and manages the Agent's client relationship with you and may make the App available under the Agent's branding. Depending on the activity and applicable law, VRM Office may process information on the Agent's instructions, for VRM Office's own legitimate platform operations, or in another legally recognized role.

The Agent and VRM Office are independent parties. This Policy does not change ownership of the Agent's client relationship and does not authorize VRM Office to market directly to the Agent's Clients based on their App conversations.

3. Information We Collect

3.1 Information You or the Agent Provide

• Identity and contact information, such as name, email address, telephone number, and state of residence.

• Onboarding and access information, such as invitation, approval, denial, acknowledgment, consent, or authorization status and related timestamps.

• Questions, prompts, messages, AI responses, source links, feedback, and other conversation content.

• Information you choose to provide about insurance, benefits, household needs, preferences, or health-related topics.

• Support requests, troubleshooting details, complaints, and communications with the Agent or authorized support personnel.

• Records of your acceptance of legal terms, privacy notices, educational-AI disclosures, and separate authorizations.

3.2 Information Collected Automatically

• Device, browser, operating-system, language, and general configuration information.

• Internet Protocol address, approximate location derived from it, timestamps, referring pages, and network information.

• App interactions, feature usage, error logs, performance information, security events, and diagnostic data.

• Identifiers or tokens used to maintain access, remember preferences, prevent abuse, or connect activity to the correct Agent and Client record.

The App is not designed to require precise geolocation, address-book access, payment-card information, account passwords, or Social Security numbers for ordinary educational use. Do not enter those items into an AI conversation unless the App expressly requests them for a disclosed and legitimate purpose.

4. Sources of Information

We may receive information directly from you; from the Agent and the Agent's authorized staff; automatically from your browser, device, and use of the App; from customer-relationship-management and communications systems used to operate the App; and from vendors that provide hosting, artificial-intelligence, security, email, messaging, analytics, or technical support services.

5. How We Use Information

VRM Office may use personal information to:

• create, configure, approve, authenticate, and administer access;

• deliver educational AI responses and retrieve relevant approved source material;

• store conversations and related activity with the correct Client record in the Agent's CRM environment;

• provide the Agent with continuity and context for support and follow-up;

• communicate service, onboarding, security, support, or legal information;

• maintain, troubleshoot, test, protect, and improve the reliability and safety of the Platform;

• detect, investigate, and prevent fraud, misuse, security incidents, and violations of applicable terms;

• comply with law, valid legal process, audits, preservation duties, and regulatory obligations; and

• create aggregated or de-identified information that is not reasonably linkable to an individual and use it for lawful business, analytical, security, or product-development purposes.

VRM Office does not use the Agent's client list or Client conversation content to market VRM Office products directly to the Agent's Clients.

6. AI and Conversation Data

When you use the educational AI assistant, your prompt and relevant conversation context are transmitted to systems needed to generate and deliver a response. Those systems may include VRM Office's knowledge and workflow services and contracted artificial-intelligence, hosting, logging, or security providers. Responses and related metadata may be stored under your Client record in the Agent's CRM environment.

Authorized VRM Office administrators may access conversation information only when reasonably necessary for support or troubleshooting, maintenance or restoration, security or incident response, fraud or misuse investigation, legal or regulatory compliance, or enforcement and protection of the Platform and its users. Access is role-based and logged where reasonably available.

AI providers and other vendors process data under their applicable contracts and configured service settings. VRM Office evaluates and configures those services to limit retention and secondary use consistent with the service's purpose. This Policy does not promise that information is anonymous or that every provider uses identical settings.

7. How We Disclose Information

We may disclose personal information in the following circumstances:

• To your Agent and the Agent's authorized staff, because the App supports the Agent's relationship with you.

• To service providers and contractors that perform hosting, CRM, AI processing, communications, security, analytics, support, or other platform functions, subject to appropriate contractual restrictions.

• To regulators, courts, law enforcement, auditors, or other persons when required by law, valid process, or a reasonable need to protect rights, safety, security, or the integrity of the Platform.

• In connection with a merger, financing, reorganization, bankruptcy, sale of assets, or transfer of some or all of the Platform, subject to applicable notice and legal requirements.

• With your direction, authorization, or consent.

VRM Office does not sell Client personal information for money. VRM Office does not use or disclose sensitive or health-related Client information for cross-context behavioral advertising. If future practices materially change, VRM Office will update this Policy and provide any notice or choice required by law.

Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Text-message opt-in data and consent will not be shared with any third parties.

8. Cookies, Local Storage, and Similar Technology

The App may use browser storage, cookies, session tokens, pixels, or similar technology to keep the App working, maintain access, remember preferences, measure performance, diagnose errors, and protect against abuse. Some technology is essential to the service. If VRM Office later uses non-essential advertising or tracking technology, it will provide any notice and consent mechanism required by applicable law.

Browser controls can limit some storage or cookies, but doing so may prevent the App from working correctly. A locally saved PWA icon or cached resource may remain on your device until you remove it through your device or browser settings.

9. Data Retention and Deletion

VRM Office retains personal information for as long as reasonably necessary to provide and secure the App, support the Agent's relationship with you, comply with legal and contractual requirements, resolve disputes, and enforce agreements. Retention periods depend on the type of record, the Agent's instructions and obligations, system design, legal requirements, and risk.

When an Agent's platform relationship ends, VRM Office may deactivate the Agent and Client access and delete or de-identify associated information from active systems within a commercially reasonable period. Information may remain for a limited period in backups or be preserved for legal, fraud, security, audit, dispute, litigation-hold, or enforcement reasons. Backup copies are removed according to the applicable backup lifecycle unless preservation is required.

The App is not intended to be the Agent's permanent system of record. The Agent is responsible for maintaining records the Agent must retain outside the Platform. Deleting the App from a device does not submit a deletion request or delete records stored by the Agent or VRM Office.

10. Data Security

VRM Office uses administrative, technical, and physical safeguards designed to protect personal information in light of its nature and the risks of processing. Safeguards may include access controls, logging, vendor management, encryption where appropriate, backups, monitoring, and incident-response procedures. No system, transmission, or storage method is completely secure, and VRM Office cannot guarantee absolute security.

You can help by securing your device, using screen-lock and software updates, limiting who can access your device or access link, and promptly reporting suspected unauthorized access to your Agent.

11. Health Information and HIPAA

Some App conversations may include health-related or insurance information. Health-related information is not automatically subject to HIPAA. HIPAA applies only when the relevant entity and activity fall within the law's scope. An Agent may or may not be a HIPAA covered entity, and VRM Office may or may not act as a business associate for a particular service arrangement.

When VRM Office is legally acting as a business associate, a required business associate agreement and applicable HIPAA rules govern the relevant protected health information. When HIPAA does not apply, other privacy, data-security, consumer-protection, breach-notification, insurance, and state laws may still apply. A separate HIPAA authorization or other consent may also govern a disclosure; review that document for its scope, expiration, revocation process, and recipients.

12. Your Choices and Privacy Rights

Depending on your relationship with the Agent, the information involved, and applicable law, you may be able to request access, correction, deletion, or a copy of personal information; withdraw a consent where processing depends on consent; limit certain disclosures; or appeal a denied privacy request. Some information may be exempt, and a request may be denied or limited when retention or processing is required by law, needed to protect security or rights, or subject to another valid exception.

Submit a request by email to privacy@vrmoffice.com or contact your Agent, who can route it to VRM Office. We may verify your identity and authority before acting. An authorized agent making a request on your behalf may need to provide proof of authorization. VRM Office will not unlawfully discriminate against you for exercising an applicable privacy right.

Requests concerning the Agent's independent records or professional services must be directed to the Agent. VRM Office may coordinate with the Agent when the Agent controls the relevant record or must determine the appropriate response.

13. State-Specific Privacy Rights

Residents of certain states may have additional rights under comprehensive consumer privacy laws, medical-information laws, insurance privacy laws, data-broker laws, biometric laws, or other state statutes. The scope of those rights and whether they apply to VRM Office depend on statutory thresholds, exemptions, the type of information, and the parties' roles.

Where an applicable law grants a right to know, access, correct, delete, obtain portability, opt out, limit sensitive-data processing, or appeal, VRM Office will honor a verified request as required. VRM Office does not sell Client information for money and does not use sensitive or health-related Client information for targeted or cross-context behavioral advertising.

14. Children's Privacy

The App is not directed to children under thirteen, and VRM Office does not knowingly collect personal information online from a child under thirteen through the App without legally valid parental consent. The ordinary Client experience is intended for adults. If you believe a child provided information improperly, contact the Agent or use the privacy contact method so the information can be investigated and, when appropriate, deleted.

15. United States Use

The App is designed for use in the United States. If you access it from another jurisdiction, information may be transferred to, stored in, or processed in the United States, where laws may differ from those in your location. Do not use the App where doing so would violate applicable law.

16. Third-Party Services

Third-party websites, official resources, telephone carriers, browsers, device platforms, and other external services have their own privacy practices. A link or integration does not mean VRM Office controls that third party. Review the third party's privacy notice before providing information directly to it.

17. Changes to This Policy

VRM Office may update this Policy to reflect changes in technology, services, vendors, practices, or law. The revised Policy will show a new “Last Updated” date. When this Policy is updated, VRM Office will show a notice in the App, and will obtain your consent where the law requires it.

18. Contact Us

For privacy questions or requests, contact your assigned Agent and ask that the request be routed to VRM Office, or contact VRM Office directly at privacy@vrmoffice.com or by mail at VRM Office, 601 21st St Ste. 300, Vero Beach, FL 32960.

Back to top