Cowork Recon

Privacy Policy

Effective: 2026-06-09 · Pilot-phase posture. Reflects the actual controls in place, not aspirational language.
Plain-English summary. Your commission statements and AMS export sit in an encrypted folder on a US server in Chicago. Only you and the founder can see them. We never share with carriers or other agencies. We delete everything 30 days after you cancel — sooner if you ask. We have not had a breach. We use GLBA Safeguards Rule practices because every state-licensed agency is covered. We are not SOC 2 certified yet (targeting Type I within 6 months of pilot #10); if your E&O carrier requires SOC 2 today, this isn't for you yet. The detail below is what an IT or E&O reviewer will want to read.

What we collect

Where data lives

Third-party processors

Retention

Your rights

Children's data

Cowork Recon is B2B-only. We do not knowingly collect data from anyone under 18.

Security incidents

In the event of suspected unauthorized access to your data, we notify your primary contact within 72 hours of discovery with a written summary of scope and remediation.

Regulatory posture

Cowork Recon processes Nonpublic Personal Information (NPI) on behalf of state-licensed insurance agencies. We act as a service provider under the GLBA Safeguards Rule (16 CFR Part 314); the pilot agency remains the data controller. A written information security program (WISP) covering qualified-individual designation, risk assessment, access control, encryption, sub-processor oversight, incident response, and annual self-attestation is maintained per §314.4. The WISP (version 1.0, last reviewed 2026-06-09) is available on request via info@coworkrecon.com; expect a copy within one business day. Where agencies are subject to state-specific insurance data laws (NY DFS 23 NYCRR Part 500, California Insurance Code data regulations, etc.), we cooperate with documentation reasonably required for the agency's own compliance.

Certifications

We do not currently hold SOC 2 Type I or Type II. SOC 2 Type I is targeted within 6 months of reaching 10 paying customers. Agencies that require SOC 2 today should consider this a known gap.

Changes

We update this policy when controls change. Material changes notified by email; minor changes published here with the effective date updated.

Contact

Privacy questions: info@coworkrecon.com.