Version 2026-09-15Effective 15 de septiembre de 2026

Effective 2026-09-15 · replaces version 2026-04-24-draft · published at /legal/privacy

1. Who we are and our role

Desk Plus LLC, a Florida limited liability company doing business as WYN Studio ("WYN Studio", "we", "us"), provides the WYN Agent Portal, software used by insurance agencies to manage their clients, communications and operations, and the wynstudio.io website.

We act in two roles. For information about visitors to our website and about the people who create and use agency accounts, we decide how the information is used and are the business or controller. For information that an agency stores in the Service about its own clients, insureds, prospects and leads ("Agency Client Data"), the agency decides how the information is used and we process it only on the agency's instructions as a service provider or processor. If you are a client of an insurance agency that uses our software, your agency's privacy notice governs its use of your information, and you should direct requests to your agency. Section 9 explains how we help agencies respond.

2. Privacy contact

privacy@wynstudio.io. Desk Plus LLC d/b/a WYN Studio, 3750 NW 87th Ave Suite 700, Doral, FL 33178.

3. Information we collect, by context

Website and waitlist. When you visit wynstudio.io we receive standard server information such as browser type, pages viewed and timestamps. For waitlist signups we store only a hashed form of your IP address. Elsewhere in the Service we record IP addresses in security, audit and e-signature logs. If you join a waitlist or book a demo, we collect your email address and any optional profile details you provide, such as agency name, size, role and current software. Demo bookings are scheduled through a third-party calendar service.

Account signup. We collect the name, email address, phone number, agency name and address, license information and any profile details provided by the person who creates the account and by each Authorized User, plus your acceptance of our legal documents with the time, version, IP address and browser used. We use a bot-detection service on signup forms.

Use of the Service by agency staff. We collect activity logs (sign-ins, actions taken, records changed), device and browser information, support tickets and feedback. We use these to operate, secure and improve the Service.

Agency Client Data. Agencies store information about their clients and prospects, which can include names, contact details, dates of birth, addresses, driver and vehicle information, property details, policy numbers, premiums and coverage, claims and service history, health and life risk information collected for insurance purposes, government identifiers provided on forms, documents and uploaded files, signatures, and notes. We process this data only to provide the Service to the agency.

Calls, texts and voicemail. When an agency uses the Service to call or text, we process phone numbers, message content, call metadata and, where the agency enables it, call recordings, voicemail, transcripts and AI-generated summaries. Recording is a per-agency setting. When recording is enabled, the Service plays a recording notice on every recorded call.

Connected email and calendar. If an Authorized User connects a Google or Microsoft mailbox or calendar, we access it with the permissions granted at connection: reading messages to link them to client records, sending messages the user composes, and reading and writing calendar events. We store message content and metadata needed to display and link it in the Service. See section 6.

AI features and document processing. When an agency uses AI features, the relevant text, documents, call audio and context are sent to our AI providers to produce the requested Output. Uploaded documents submitted for data extraction are processed and unconfirmed extraction drafts are deleted when the agency confirms or discards them, and in any case within 7 days; the values the agency accepts are saved to the agency's records. AI providers are bound by contract not to use this data to train models.

Client portal. Agencies may invite their clients to a portal where clients view policies and documents, exchange messages with the agency, upload documents, and submit privacy requests. Clients sign in with a link sent to their email address. We collect the client's email address, sign-in events, messages and uploads on the agency's behalf.

Payments. Our payment processor collects your payment card and billing details. We receive and store the card brand, last four digits and transaction records. Your billing address is held by our payment processor.

4. How we use information

  • To provide, operate, secure and support the Service and the website.
  • To process Agency Client Data on the agency's instructions.
  • To bill, meter usage and prevent fraud and abuse.
  • To communicate with account holders about the Service, security, billing and product changes, and, with consent where required, about our products.
  • To comply with law, enforce our terms and protect rights and safety.
  • To produce aggregated, de-identified statistics that do not identify any person.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use Agency Client Data for our own marketing.

5. Who we share information with

  • Service providers that host, store, transmit, monitor, bill and provide AI capabilities for the Service, bound by contract to process data only for us. They are listed by category at /legal/subprocessors.
  • Services the agency connects, such as email, calendar, telephony, e-signature, automation and AI provider accounts, which receive data as the agency configures and under their own terms.
  • Carriers and other recipients the agency chooses when it uses the Service to transmit information.
  • Legal and safety recipients when required by law, subpoena or court order, or to protect rights, safety and the integrity of the Service; we notify the affected agency where the law allows.
  • A successor in a merger, acquisition or sale of assets, subject to this policy.

6. Google and Microsoft account data

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail and Google Calendar data only to provide the features the user enables: displaying and linking messages to client records, sending messages the user composes, and syncing calendar events. We do not use this data for advertising, do not sell it, do not use it to train models, and allow human access only with the user's consent, for security purposes, or as required by law. Our use of Microsoft account data is limited in the same way and complies with the Microsoft APIs Terms of Use. Users can disconnect an account at any time from their settings, which stops further access; previously linked messages remain in the agency's records until the agency removes them.

7. Cookies and local storage

We use cookies and browser storage that are strictly necessary to keep you signed in, protect against fraud and remember your preferences. Our website uses an analytics service to measure visits and conversions. Analytics that use cookies or similar identifiers load only after you accept them in the cookie banner; declining keeps only the strictly necessary cookies. The Service itself uses a cookieless performance tool. Our error-monitoring service collects technical diagnostics with personal data filtered out, and when an error occurs may capture a replay of the affected screen with text and inputs masked.

8. Security

We protect information with measures that include encryption in transit, encryption of sensitive fields at rest using keys managed in a cloud key-management service and unique to each agency, searchable encryption that avoids storing plaintext for sensitive fields, role-based access limited to the agency's own data, tamper-evident audit logs, multi-factor authentication for privileged roles, rate limiting and IP restrictions for API access, and monitoring. No system is perfectly secure, and we cannot guarantee absolute security.

9. Your rights and choices

Agency account holders and staff can access and update most information in the Service, and may contact us to access, correct or delete personal information we hold about them, subject to our obligations to the agency and to law.

Clients of an agency should direct requests to their agency, which controls their information. Where an agency offers the client portal, clients can submit export and deletion requests there and the agency responds. We assist agencies in fulfilling requests and will refer a request we receive directly to the relevant agency.

State privacy laws. Residents of California and other states with privacy laws may have rights to know, access, correct, delete and port their information, to opt out of sale or sharing, and not to be discriminated against for exercising rights. We do not sell or share personal information. To exercise rights, email privacy@wynstudio.io; we will verify your request and respond within the time the law requires. You may use an authorized agent as the law permits. Where a law applies to us only above certain thresholds, we honor these rights where required.

GDPR and UK GDPR. If you are in the European Economic Area or the United Kingdom, you have the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right to complain to a supervisory authority. Our legal bases are performance of a contract, legitimate interests in operating and securing the Service, consent where we ask for it, and legal obligations.

Marketing email. You can unsubscribe using the link in any marketing email. We will still send service and billing messages.

10. Retention

We keep account information for as long as the account is open and for a period afterwards to meet legal, accounting and security obligations. Agency Client Data is retained according to the retention schedule each agency configures, which defaults to periods commonly required for insurance records: 10 years for policies, 7 years for client and account records, 5 years for quotes and service requests, and 3 years for tasks and leads, measured from the relevant record event. Agencies may place legal holds that suspend deletion. Audit logs are kept for at least 2 years. When an agency closes its account, its data is scheduled for deletion after the 30-day closure period, except data subject to a retention requirement or hold. Backups expire on their normal schedule.

11. Children

The Service and website are for adults. We do not knowingly collect personal information from anyone under 18 as a user. Agencies may store information about minors as dependents on insurance records, which we process only on the agency's instructions.

12. Where information is processed

We host and process information in the United States. If you access the Service from outside the United States, your information is transferred to and processed in the United States. Where a data transfer law applies, we rely on the safeguards described in our Data Processing Addendum.

13. Changes and contact

We will post changes here with a new effective date and notify account owners of material changes. This policy is written in English; the English text controls. Questions: privacy@wynstudio.io or hello@wynstudio.io.

Questions about this document? hello@wynstudio.io