This Privacy Policy explains how Everborn Operations LLC (“Everborn,” “we,” “us”) handles personal information in connection with this website (everbornops.com) and the Everborn licensing and onboarding platform (the “Platform”).
Two different roles. Everborn wears two hats:
- For the personal information that a subscribing organization (a “Customer”) loads into or generates within its Platform tenant — including the records of the individuals the Customer manages — the Customer is the controller and Everborn is a service provider/processor acting on the Customer’s behalf. If you are one of those managed individuals, please direct privacy requests to the organization whose program you are enrolled in; we will support their response. Our handling of that data is governed by our Data Processing Agreement with the Customer.
- For information about visitors to this website and the authorized users who administer a tenant, Everborn acts as the controller, as described below.
1. Information we collect
1.1 Customer Data (processed on the Customer’s behalf)
When a Customer uses the Platform, the Platform stores and processes:
- Managed-individual records — name and contact details; licensing/contracting status and progression; onboarding and training/quiz progress; uploaded documents; scheduling entries; and communication logs. Today this is handled in an insurance-licensing context.
- Communication metadata — records of emails, messages, and calendar events coordinated through the Platform on the Customer’s behalf.
We process this data only to provide the Platform to the Customer, per their instructions and our Data Processing Agreement. We do not use it for our own marketing and we do not sell it.
1.2 Authorized-user account data (we are the controller)
For the coordinators and administrators who log in to operate a tenant, we process: name, work email, role and permissions, authentication data (such as a salted password hash or a login token), and audit/usage logs of actions taken in the Platform.
1.3 Usage and technical data
When the website or Platform is accessed, our infrastructure logs technical data such as IP address, request paths, timestamps, and error diagnostics. We use this data to operate, secure, and troubleshoot the service.
1.4 Website and inquiry data
This website is informational. It does not use analytics trackers, advertising cookies, or embedded third-party scripts other than the delivery of web fonts. If you contact us by email, we collect the details you choose to provide (your name, email address, and message) and use them to respond to your inquiry.
2. Why we process it
| Purpose | Data used | Basis |
|---|---|---|
| Provide and operate the Platform for the Customer | Customer Data, authorized-user data | Performance of a contract; our legitimate interest in delivering the service; for Customer Data, the Customer’s chosen basis |
| Authenticate and secure accounts | Authorized-user data, usage/technical data | Legitimate interest in security; contract |
| Support, troubleshoot, and improve reliability | Usage/technical data, limited Customer Data as needed | Legitimate interest; contract |
| Send transactional/service communications | Contact details | Contract; legitimate interest |
| Respond to inquiries from this website | Inquiry data | Legitimate interest; your request |
| Comply with legal obligations | As required | Legal obligation |
For Customer Data, the Customer determines the purposes and legal bases; we act on their instructions.
3. How we share information
We share personal information only:
- With sub-processors that help us run the Platform, under contract and only as needed. Our current sub-processors are Cloudflare (compute, database, document storage, caching, CDN/TLS), Google (connected email/calendar and document-storage fallback, only where a Customer enables it), Resend (transactional email), and Twilio (SMS/voice, only when a Customer enables it).
- With the Customer whose tenant the data belongs to.
- For legal reasons — to comply with law, respond to lawful requests, or protect rights, safety, and the integrity of the Platform.
- In a business transfer — as part of a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell personal information and do not use it for cross-context behavioral advertising.
4. Retention
We retain Customer Data for as long as the Customer’s subscription is active and then per the return-and-deletion terms of the applicable Data Processing Agreement. Authorized-user and technical data are retained as long as needed for the purposes above and then deleted or de-identified. Website inquiry emails are retained for as long as needed to handle the inquiry and any resulting relationship.
5. Your rights
Depending on where you live and applicable law (including US state privacy laws such as the CCPA/CPRA and comparable statutes, and, where applicable, GDPR/UK GDPR), you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- restrict or object to certain processing;
- receive a portable copy; and
- not be discriminated against for exercising these rights.
If you are a managed individual in a Customer’s program, exercise these rights with that organization; we will assist them in responding. If you are an authorized user or website visitor, contact us at admin@everbornops.com. We may need to verify your identity before acting. You may also have the right to lodge a complaint with a supervisory authority.
6. Insurance-sector and US-state-law context
Because the Platform is used in an insurance context, Customer Data may be subject to sector rules including the Gramm-Leach-Bliley Act (GLBA) and NAIC model privacy and data-security regulations, as well as US state privacy laws. Everborn processes Customer Data as a service provider/processor consistent with those frameworks and does not sell it or use it outside the Customer’s instructions. Customers remain responsible for their own regulatory notices to the individuals they manage.
7. Security
We use technical and organizational measures to protect personal information, including build-enforced multi-tenant isolation, encryption in transit and at rest, secret-store-based secret handling with constant-time secret comparison, salted password hashing, and audit logging. See our Security overview for detail. No system is perfectly secure; we cannot guarantee absolute security.
8. Text messaging (SMS)
Where a Customer enables text messaging, enrolled participants receive program-related texts — study and exam reminders, scheduling, and two-way support conversations with their assigned coordinator — at the mobile number they provided during program onboarding. We may send up to ten messages per week. Message and data rates may apply, depending on the recipient’s mobile plan. Reply STOP to any message to opt out at any time, or HELP for help.
Mobile phone numbers and text-messaging opt-in consent are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. SMS data is processed by our sub-processor Twilio solely to deliver the service. How participants opt in and what they receive is described on our SMS Program & consent page; full program terms are in the SMS program terms.
Separately, if you contact us through this website and actively opt in on the contact form (an unchecked box that is never required to submit the form), you consent to receive texts from Everborn about your inquiry at the number you provide. Message frequency varies; message and data rates may apply; reply STOP to opt out or HELP for help. The same protection applies — your number and opt-in consent are never sold or shared — and the exact consent language and time are recorded with your submission. This program is described on the SMS Program & consent page.
9. Cookies and sessions
This website does not set advertising or analytics cookies. The Platform uses strictly necessary session and authentication mechanisms to keep authorized users logged in and to operate securely; it does not use third-party advertising cookies.
10. International transfers
We and our sub-processors process data primarily in the United States. Where a transfer requires a safeguard (for example, Standard Contractual Clauses), we put one in place.
11. Children
The website and Platform are business tools not directed to children, and we do not knowingly collect children’s personal information.
12. Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date above and, for material changes, provide reasonable notice.
13. Contact
Privacy questions: admin@everbornops.com.
Everborn Operations LLC is a Maryland limited liability company operating throughout the United States. Our mailing address is available on request.