NextAgency Privacy Policy

For NextAgency, NextCommission Solo, and related add-ons, products, and services

Last Modified: September 1, 2026

Take 44, Inc. (“Take 44,” “we,” “us,” or “our”) provides the NextAgency platform, including NextAgency, NextCommission Solo, mobile applications, and related hosted add-ons, products, and services (collectively, the “Platform”). This Privacy Policy describes how we collect, use, disclose, and retain information in connection with the Platform. It does not govern Take 44’s public marketing websites, which are subject to the privacy notice presented on those sites.

The insurance agency or other business subscribing to the Platform is the “Agency.” Individuals whom Agency authorizes to use it are “Users.” Information submitted to or maintained in the Platform by or for Agency is “Agency Data.”

1. Core Principles and Scope

As between Agency and Take 44, Agency owns Agency Data. Agency controls its Users and their permissions. Take 44 does not use Agency Data to market or solicit products or services directly to Agency’s clients or prospects for Take 44’s own account. Take 44 processes Agency Data to provide, maintain, improve, protect, bill for, and administer the Platform; comply with law; and carry out Agency’s instructions.

This Policy applies to Platform accounts, mobile applications, support, onboarding, email and calendar features, and similar Platform extensions. The Terms of Service (“TOS”), Mutual Non-Disclosure Agreement (“NDA”), and, where applicable, Business Associate Agreement (“BAA”) also govern. The BAA controls PHI to the extent of a direct conflict. The TOS’s governing-law, arbitration, venue, jury and class waivers, one-year claim period, liability limitations, and other applicable protections apply to this Policy and to disputes concerning Take 44’s handling of information. Nothing in this Policy expands Agency’s or a User’s rights or remedies, limits a defense or protection available to Take 44, or creates a contractual obligation beyond those expressly stated.

2. Information We Collect

2.1 Account and User Information

We may collect names, business and email addresses, telephone numbers, account roles, credentials, authentication information, preferences, support communications, and other information supplied when an account is created or administered.

2.2 Agency Data

Agency Data may include information about Agency, its Users, prospects, clients, policies, benefits, employees, contacts, carriers, commissions, general agents, sub-agents, communications, notes, tasks, documents, and other records. Agency determines what Agency Data it submits and is responsible for having the rights and permissions necessary to do so.

2.3 Payment Information

We and our payment service providers may process credit-card and debit-card information, ACH and bank-draft information, other electronic-payment details, billing addresses, full or partial account numbers, expiration dates, authorization information, and transaction records. Information may be entered through Take 44’s administrative portal or, when a customer requests assistance, provided directly to authorized Take 44 personnel for entry or transmission to a payment processor. We seek to limit our handling to what is reasonably necessary to administer payment, prevent fraud, maintain records, and comply with law.

2.4 Integrations and Connected Accounts

When Agency or a User connects an email account, calendar, enrollment platform, carrier, communications system, payment service, or other application, we may receive credentials or tokens, messages, attachments, metadata, contacts, calendar information, configuration information, and other data needed to provide the requested integration.

2.5 Usage, Device, and Log Information

We may collect IP addresses, device and browser information, dates and times, authentication events, pages or features used, actions taken, errors, diagnostic information, and approximate location derived from IP address. We use this information to operate, secure, troubleshoot, support, analyze, and improve the Platform and to maintain audit records.

2.6 Cookies and Similar Technologies

The Platform may use session and persistent cookies and similar technologies for authentication, preferences, security, performance, and Platform analytics. Blocking cookies may limit functionality. We do not sell Platform information or use it for third-party cross-context behavioral advertising.

3. How We Use Information

We may use information to: provide and administer accounts and features; authenticate Users; process payments; deliver messages and notifications; provide support, onboarding, migration, and training; maintain, test, secure, troubleshoot, and improve the Platform; develop new features; analyze use in aggregated or de-identified form; prevent fraud, abuse, and security incidents; enforce agreements; comply with legal obligations; and communicate about the Platform, maintenance, services, and account matters.

Take 44 may create and use aggregated or de-identified information that does not reasonably identify Agency, a User, client, or prospect for lawful business, research, security, analytics, and product-improvement purposes. PHI will be de-identified or aggregated only as permitted by the BAA and applicable law.

4. Email, Calendar, and Provider-Specific Requirements

When Agency enables an email or calendar feature, Agency authorizes Take 44 and the providers facilitating that feature to process connected-account data as necessary to provide, secure, maintain, and support the feature. Take 44 may change the provider facilitating the feature and need not identify that provider in the user-facing feature name. Each provider is responsible for its own services, systems, acts, omissions, security, availability, and compliance with the obligations applicable to its role. Take 44 is not responsible for a provider’s acts, omissions, outages, security incidents, or other failures, except to the extent responsibility cannot lawfully be disclaimed or is expressly imposed on Take 44 by an applicable BAA.

If Agency authorizes transmission of data from the Platform to a third-party account or service selected by Agency, the recipient’s terms and privacy practices govern the recipient’s subsequent handling.

Where Take 44 receives data originating from Google APIs, Take 44 will handle that data as required by the Google API Services User Data Policy, including its applicable Limited Use requirements. Such data will be used only to provide or improve the applicable user-facing feature, protect the feature or its users, comply with law, or for another purpose permitted by that policy. Take 44 does not use connected Google data for advertising or permit human access except with the user’s affirmative permission for specific data, when necessary for security or abuse investigation, when required by law, or as otherwise permitted by the applicable Google policy. If an applicable Google policy requires affirmative consent before a new or changed use of Google-originating data, Take 44 will obtain that consent before beginning the use. These provider-specific requirements apply only to data originating from Google APIs and do not create additional restrictions on other Agency Data.

5. How We Disclose Information

5.1 Agency and Authorized Users

We disclose information within Agency according to the roles and permissions established through the Platform. Agency’s designation of Agency Administrators, their authority to act for and bind Agency, and Agency’s responsibility for their actions are governed by Section 2.3 of the TOS.

5.2 Take 44 Service Providers

We may disclose information to hosting, communications, payment, integration infrastructure, analytics, support, security, artificial-intelligence, professional, insurance, and other service providers that perform functions for Take 44. Depending on the Platform features enabled and the information submitted, connected, or made available by Agency and its Users, these providers may process information reasonably related to the functions they perform. Take 44 authorizes providers acting on its behalf to process information to perform those functions and for related security, support, administration, legal-compliance, and other purposes permitted by their applicable agreements and law. Each provider is responsible for its own services, systems, acts, omissions, security, and compliance with the obligations applicable to its role. We may change providers as the Platform evolves. For PHI, the BAA’s subcontractor requirements apply.

5.3 Agency-Authorized Third Parties

We may disclose Agency Data when Agency or a User with appropriate authority enables an integration, requests a transmission, or otherwise directs the disclosure. Agency’s direction constitutes its instruction and authorization for Take 44 to make the disclosure. If the disclosure includes PHI, Take 44 will handle the disclosure in accordance with the applicable BAA. Agency is responsible for determining that the disclosure is lawful, that the recipient is authorized to receive the information, and that Agency has any agreement required with an Agency-selected recipient. An Agency-selected recipient does not become Take 44’s service provider or subcontractor merely because Take 44 transmits information at Agency’s direction. Take 44 is not responsible for the recipient’s acts, omissions, security, availability, or information practices after the information leaves Take 44’s control.

5.4 Legal, Safety, and Enforcement Reasons

We may preserve or disclose information when we reasonably believe doing so is necessary to comply with law, regulation, legal process, or governmental request; protect the rights, safety, or property of Take 44, Agency, Users, or others; investigate or prevent fraud, abuse, security threats, or technical problems; enforce agreements; or establish or defend legal claims. Except to the extent preservation or a different retention period is required or reasonably necessary for one of those purposes, the applicable access, retention, and deletion provisions of the TOS control Agency Data. More specific requirements in an applicable BAA or other controlling legal obligation govern PHI and other specially regulated information.

5.5 Corporate Transactions

We may disclose or transfer information in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, change of control, or similar transaction, subject to applicable contractual, confidentiality, and legal requirements.

Take 44 does not sell Agency Data or sell or share personal information for cross-context behavioral advertising, as “sell,” “share,” and “cross-context behavioral advertising” are defined under applicable privacy law.

6. Access by Take 44 Personnel

Take 44 support personnel may request access to Agency’s Platform instance for support, training, onboarding, migration, or troubleshooting. An Agency Administrator or another User delegated appropriate authority may grant access and, where functionality permits, limit its duration. Once granted, authorized personnel may have access reasonably necessary to perform the requested work, and activity may be logged.

Take 44 technical and security personnel and authorized contractors may access systems and Agency Data when reasonably necessary to maintain, update, test, secure, repair, migrate, or improve the Platform; investigate an incident; comply with law; or perform another permitted operational function. Take 44 may act without prior Agency authorization where reasonably necessary for security, legal compliance, emergency response, or Platform integrity.

7. Data Access, Export, Retention, and Deletion

Agency controls User access through roles and permissions. Authorized Users may export information through available reports and download tools. Agency is responsible for its Users and for their access to, export, disclosure, storage, security, retention, and use of Agency Data. Agency and its Users are solely responsible for information exported, downloaded, transmitted, copied, or otherwise removed from Take 44’s control. Agency is solely responsible for preserving records required for its business, insurance, tax, legal, regulatory, or professional obligations and for exporting Agency Data before termination.

Upon termination, Agency’s access ends immediately. Take 44 has no obligation thereafter to retain, return, export, recover, or provide Agency Data. Take 44 may maintain Agency Data in active production systems for up to sixty (60) days, without guaranteeing availability or recoverability. If data remains available, access may require subscription reactivation and payment of Take 44’s then-current fee for at least one User seat and other applicable charges.

No later than sixty (60) days after termination, Agency Data will be deleted from active production systems and will no longer be available to Agency. Limited copies may remain temporarily in routine backups or archives, legal holds, fraud-prevention records, financial records, or other records Take 44 is legally or reasonably required to retain. Those copies will not be restored or made available to Agency, except as required by law, and backup or archive copies will be removed or overwritten through ordinary cycles. Any retained information remains protected and may be used only for the purpose permitting retention. More specific BAA requirements control PHI.

8. Security and HIPAA

Take 44 maintains reasonable administrative, technical, and physical safeguards appropriate to the nature of the Platform and information processed. Safeguards may change as technology, providers, threats, and the Platform evolve. No internet transmission, email system, integration, or electronic storage method is completely secure or error-free, and Take 44 cannot guarantee absolute security.

Agency is responsible for User permissions, credentials, devices, networks, security settings, exported information, and disclosures it authorizes. Once information is transmitted to Agency or an Agency-authorized third party, the recipient is responsible for protecting it.

Where Take 44 acts as Agency’s business associate under HIPAA, the BAA governs the Parties’ PHI obligations. References to HIPAA support or HIPAA-appropriate functionality do not make Take 44 responsible for Agency’s compliance obligations or for information outside Take 44’s control.

9. United States–Only Platform

The Platform is offered and marketed only to agencies located and conducting business in the United States. Take 44 does not offer or market the Platform outside the United States and does not intend through the Platform to monitor the behavior of individuals located outside the United States. Take 44 does not represent that the Platform or its practices comply with the GDPR, UK GDPR, or any other non-U.S. privacy or data-protection law. Agency may not use the Platform in a manner that subjects Take 44 to a non-U.S. law without Take 44’s prior written approval. This Section does not limit an obligation imposed by a law that applies notwithstanding the Parties’ agreement.

10. Amendments and Acceptance

Take 44 may amend this Policy at any time by posting the revised Policy. Take 44 will determine whether an amendment is material and the date on which it becomes effective. Take 44 will provide notice of a material amendment by a method permitted under Section 14.1 of the TOS. A nonmaterial amendment may become effective when posted without additional notice.

Agency’s or any User’s continued access to or use of the Platform on or after the effective date constitutes Agency’s acceptance of the amended Policy. If Agency does not agree to an amendment, Agency must discontinue use of the Platform before the amendment becomes effective.

11. Contact

Questions or notices concerning this Policy may be emailed to nextagencyadmin@take44.com. Support requests may be sent to support@nextagency.com.

Changelog

Changelog

September 1, 2026: Moved the privacy policy page to its current URL. Reduced the retention of cancelled agency’s data from one year to 60 days. Added reference to AI accessed through NextAgency.

July 1, 2024: Clarified that NextAgency is for use in the United States and may not comply with laws and regulations of other nations.

June 1, 2024: Modified to expand this privacy policy applicability to NextCommission Solo. This required additional non-substantive changes for to enhance clarity.

June 15, 2023: Modified to expand coverage to privacy in connection with the NextAgency Email Add-In for Outlook. Also fixed grammatical errors that did not alter the substance of this Privacy Policy.

January 15, 2021: Modified to reflect new feature enabling you to grant and terminate customer NextAgency customer service representative’s access to your data. We also added references to NextAgency’s two-factor authorization and automatic sign-off features. Made minor, non-substantive text changes to improve clarity