Privacy Policy
This Privacy Policy explains how BoB HQ™ collects, uses, shares, protects, and retains information associated with our website, application, integrations, support services, and related features.
Effective date: September 12, 2026
This Privacy Policy is being prepared for legal review. It describes BoB HQ™’s intended data practices and must be reviewed against the platform’s final production configuration before publication.
1. Scope and roles
This Privacy Policy applies to the BoB HQ™ website, hosted application, dashboards, campaign tools, integrations, support services, and related features collectively referred to as the “Services.”
BoB HQ™ is operated by Ballestra Group, LLC, doing business as BoB HQ™ (“BoB HQ™,” “we,” “us,” or “our”).
When we process information about account holders, website visitors, prospective customers, and business contacts for our own operational purposes, BoB HQ™ determines why and how that information is used.
When a customer uploads, synchronizes, or otherwise submits information about its clients, prospects, policyholders, employees, producers, or other contacts, the customer determines why that information is processed. For that Customer Data, BoB HQ™ generally acts as a service provider or processor on the customer’s behalf and follows the customer’s lawful instructions.
Customers are responsible for providing legally required privacy notices, obtaining necessary permissions and consents, responding to individuals’ requests, and ensuring that their use of the Services complies with applicable privacy, communications, insurance, and consumer-protection laws.
This Policy does not govern third-party websites, products, or services that have their own privacy notices, even when they connect to or are accessible through BoB HQ™.
2. Information we collect
Account and business information
We may collect names, business names, job titles, producer or agency information, email addresses, telephone numbers, account identifiers, login information, communication preferences, and other information provided during registration, onboarding, verification, or account management.
Customer Data
Customers may upload, enter, synchronize, or generate records through the Services. Depending on the customer’s configuration, these records may include:
- Client or contact names;
- Telephone numbers and email addresses;
- Birth months or birth dates;
- Assigned producers or account owners;
- Policy categories, relationship status, and account status;
- Communication preferences and suppression status;
- Campaign eligibility, scheduling, and activity information;
- Notes and other customer-selected data fields; and
- Information imported from connected CRM or business systems.
Customers must not submit information prohibited by the Terms of Service, including Social Security numbers, Medicare Beneficiary Identifiers, full payment-card or financial-account numbers, account passwords, detailed medical or claims information, biometric identifiers, or government identity documents unless BoB HQ™ has expressly authorized a specific field or workflow in writing.
Campaign content and communications
We may process recordings, scripts, message templates, campaign instructions, delivery information, call or message status, timestamps, suppression records, and related communication data submitted or generated through the Services.
BoB HQ™ is not intended to record the contents of live telephone conversations unless a particular feature expressly states otherwise and all legally required notices and consents have been obtained.
Connected-service information
When a customer connects a CRM, communications provider, payment service, or other third-party system, we may receive account identifiers, authorization tokens, configuration settings, synchronized records, event information, and other data permitted by the customer and the connected service.
Customers should not provide their third-party account passwords directly to BoB HQ™ unless an approved connection process expressly requires it. Where available, BoB HQ™ uses authorization tokens or similar connection methods.
Billing and transaction information
We may collect subscription tier, billing status, transaction identifiers, invoice information, payment dates, and limited payment-method details supplied by our payment processor, such as card brand, expiration date, and the last four digits.
Full payment-card numbers and security codes are processed by the payment processor and are not intended to be stored by BoB HQ™.
Website, device, and usage information
When someone visits or uses the Services, we may automatically collect IP address, browser type, device type, operating system, approximate location derived from IP address, referring pages, pages or features viewed, actions performed, session timestamps, error information, diagnostic logs, and security events.
Support and correspondence
We collect information submitted through support requests, forms, surveys, demonstrations, emails, and other communications, including the message content and any files or screenshots provided.
3. Sources of information
We may receive information:
- Directly from customers, users, and website visitors;
- From an employer, agency, administrator, or account owner that authorizes a user;
- From CRM platforms and other services connected at the customer’s direction;
- From payment processors, communications providers, hosting services, security providers, and other service providers;
- Automatically through browsers, devices, cookies, logs, and similar technologies; and
- From public sources or business partners when legally permitted.
4. How we use information
We may use information to:
- Create, authenticate, and administer accounts;
- Provide, operate, maintain, and improve the Services;
- Import, organize, synchronize, and display Customer Data according to customer instructions;
- Schedule, initiate, monitor, and report on customer-directed campaigns;
- Process subscriptions, payments, renewals, and refunds;
- Provide customer service and technical support;
- Communicate about accounts, transactions, security, product changes, and service availability;
- Personalize onboarding, settings, documentation, and user experience;
- Monitor performance, diagnose errors, and develop new features;
- Detect, investigate, and prevent fraud, abuse, security incidents, and unlawful activity;
- Enforce our Terms of Service and Acceptable Use Policy;
- Comply with legal and regulatory obligations;
- Establish, exercise, or defend legal claims and protect rights, safety, property, and systems; and
- Create aggregated or de-identified information for analytics, security, research, and service improvement.
BoB HQ™ does not determine which individuals a customer should contact or whether a particular campaign is lawful. Customers remain responsible for their audiences, messages, consent determinations, suppression lists, and campaign instructions.
5. Legal bases for processing
Where applicable law requires a legal basis, we process personal information:
- To perform a contract or take requested steps before entering a contract;
- Based on legitimate interests such as operating, securing, supporting, and improving the Services;
- With consent, when consent is required or requested;
- To comply with legal obligations; and
- To protect vital interests, rights, safety, property, and systems when necessary.
When BoB HQ™ processes Customer Data on a customer’s behalf, the customer is responsible for identifying and documenting the legal basis for that processing.
6. How we disclose information
We may disclose information to the following categories of recipients:
Service providers
We use service providers to support hosting, databases, authentication, communications, payment processing, analytics, security, customer support, software development, and other business operations. These providers may process information only as necessary to perform services for BoB HQ™ and subject to appropriate contractual restrictions.
Customer-authorized integrations
We disclose information to CRM platforms, communications providers, and other third-party services when a customer connects, enables, or directs us to use those services. The third party’s own privacy policy governs its independent handling of information.
Customers and account administrators
Information associated with a business account may be visible to the customer, account owner, agency administrator, or other authorized users. Administrators may manage users, permissions, integrations, campaigns, billing, and Customer Data.
Business transactions
We may disclose information in connection with an actual or proposed merger, financing, acquisition, reorganization, sale of assets, bankruptcy, or similar business transaction. Any recipient will be subject to appropriate confidentiality and data-protection obligations.
Legal, safety, and enforcement purposes
We may preserve or disclose information when we reasonably believe it is necessary to:
- Comply with law, legal process, or governmental requests;
- Protect the rights, safety, property, or security of BoB HQ™, customers, recipients, service providers, or the public;
- Detect, investigate, or prevent fraud, abuse, or unlawful activity;
- Enforce our Terms of Service, Acceptable Use Policy, and other agreements; or
- Establish, exercise, or defend legal claims.
At the customer’s direction or with consent
We may disclose information for another purpose when the customer or individual directs us to do so or provides legally valid consent.
Aggregated or de-identified information
We may disclose aggregated or de-identified information that does not reasonably identify a customer, user, recipient, or other individual. We will not attempt to re-identify properly de-identified information except as permitted by law.
BoB HQ™ does not sell Customer Data. As of the effective date of this Policy, BoB HQ™ does not sell personal information for monetary consideration or share personal information for cross-context behavioral advertising as those terms are defined under applicable state privacy laws.
7. Service providers and subprocessors
BoB HQ™ relies on third-party service providers and subprocessors to operate the Services. Depending on the features used, these providers may support:
- Cloud hosting, application deployment, and content delivery;
- Database storage, authentication, and account security;
- Payment processing, subscriptions, and invoicing;
- Voicemail, telephone, email, and other communications;
- CRM connections and data synchronization;
- Error monitoring, analytics, and performance diagnostics;
- Customer support and business communications; and
- Legal, accounting, security, and professional services.
The providers used may change as the Services develop. BoB HQ™ will evaluate providers based on the nature of the information processed, the service performed, contractual protections, security practices, and applicable legal requirements.
Customers may request current information about material subprocessors by contacting privacy@getbobhq.app.
8. Customer-directed communications
Customers may use the Services to prepare, schedule, and initiate communications to recipients. To perform those instructions, BoB HQ™ and its communications providers may process telephone numbers, recordings, scripts, campaign timing, caller-identification information, delivery status, error responses, and related campaign data.
Communications providers, telephone carriers, voicemail systems, and recipient devices may independently process communication data under their own legal obligations, terms, and privacy practices.
Customers—not BoB HQ™—select the recipients, determine the purpose of each campaign, supply or approve the message, and decide when a campaign is initiated. Customers are responsible for maintaining legally sufficient consent, permission-to-contact records, do-not-call screening, suppression records, revocations, and required disclosures.
Recipients who want to stop communications should contact the business identified in the message. BoB HQ™ may also assist with a suppression or privacy request when sufficient information is provided to identify the responsible customer and applicable campaign.
9. Cookies and similar technologies
BoB HQ™ and its service providers may use cookies, local storage, pixels, logs, and similar technologies to operate and secure the Services, remember settings, maintain sessions, understand usage, diagnose problems, and improve performance.
These technologies may include:
- Essential technologies required for authentication, security, fraud prevention, session management, and core functionality;
- Preference technologies that remember selections and settings; and
- Analytics technologies that help us understand how the website and Services are used and where errors occur.
Browser and device settings may allow users to block or delete cookies. Blocking essential technologies may prevent portions of the Services from functioning correctly.
Where required by law, BoB HQ™ will request consent before using nonessential cookies or similar technologies. We will also recognize legally required browser-based opt-out preference signals when they apply to our processing.
10. Data retention
We retain information for as long as reasonably necessary to provide the Services, maintain accounts, complete transactions, comply with customer instructions, resolve disputes, enforce agreements, protect security, and meet legal, regulatory, tax, accounting, and recordkeeping obligations.
Retention periods vary depending on the type of information, the purpose for which it is used, customer configuration, contractual commitments, legal requirements, and technical considerations.
Customer Data is generally retained while an account is active and for a limited period after termination to allow account closure, export, restoration, security review, and compliance with legal obligations. Customers should export information they need before closing an account whenever export tools are available.
Information may remain temporarily in backups, archives, logs, fraud prevention systems, and disaster-recovery systems until it is deleted or overwritten through ordinary retention cycles.
We may retain limited suppression, consent, transaction, security, and compliance records after other information is deleted when necessary to honor opt-outs, document compliance, prevent abuse, or establish or defend legal claims.
Aggregated or de-identified information may be retained for longer periods when it cannot reasonably be used to identify an individual.
11. Health, insurance, and regulated information
The Services are designed to support business relationship management and retention workflows. They are not intended to serve as an electronic medical-record system, claims system, clinical platform, or repository for detailed health information.
BoB HQ™ is not represented as HIPAA-compliant and is not intended to create a business-associate relationship under HIPAA unless BoB HQ™ signs a separate Business Associate Agreement that expressly covers the relevant Services and information.
Customers must not upload Medicare Beneficiary Identifiers, Social Security numbers, medical records, diagnoses, treatment information, detailed claims information, or other specially regulated information unless BoB HQ™ has expressly authorized a specific field or workflow in writing.
Information such as a name, telephone number, email address, birth month or birth date, policy category, assigned producer, and relationship status may still be personal information protected by privacy, insurance, communications, and consumer-protection laws. Customers are responsible for determining whether they may lawfully collect and use that information.
12. Information security
BoB HQ™ uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Safeguards may include:
- Access controls and authentication measures;
- Encryption in transit and, where appropriate, at rest;
- Logging, monitoring, and security-event review;
- Role-based restrictions and least-privilege practices;
- Vendor and service-provider review;
- Backup and recovery procedures; and
- Incident response and account-protection measures.
Customers are responsible for maintaining secure passwords, protecting devices, limiting user permissions, securing connected accounts, reviewing authorized users, and notifying BoB HQ™ promptly of suspected unauthorized access.
No internet transmission, telecommunications network, or electronic storage system can be guaranteed completely secure. BoB HQ™ cannot promise that information will never be accessed, disclosed, altered, lost, or destroyed without authorization.
If BoB HQ™ becomes aware of a security incident affecting personal information, we will investigate and provide notifications as required by applicable law and contractual obligations.
Suspected security issues may be reported to support@getbobhq.app.
13. Privacy rights and choices
Depending on where an individual lives and the nature of the information, applicable law may provide rights to:
- Confirm whether personal information is being processed;
- Access or obtain a copy of personal information;
- Correct inaccurate personal information;
- Delete personal information;
- Restrict or object to certain processing;
- Withdraw consent when processing is based on consent;
- Receive information in a portable format;
- Opt out of certain sales, targeted advertising, sharing, or profiling;
- Appeal a denied privacy request; and
- Receive equal service and pricing without unlawful discrimination for exercising privacy rights.
Privacy requests may be submitted to privacy@getbobhq.app. The request should describe the right being exercised and provide enough information for us to identify the relevant account or records.
We may need to verify the requester’s identity, authority, account, jurisdiction, or relationship to the information before completing a request. Authorized agents may be required to provide written proof of authority, and we may confirm the request directly with the individual.
When BoB HQ™ processes Customer Data on behalf of a customer, individuals should ordinarily submit requests directly to the business or agency that collected their information. If BoB HQ™ receives such a request, we may refer it to the responsible customer and assist that customer as required by law or contract.
Certain information may be exempt from a request or retained when necessary to complete transactions, maintain security, prevent fraud, honor suppression requests, comply with law, or establish or defend legal claims.
Communication choices
Users may unsubscribe from promotional BoB HQ™ emails by using the unsubscribe link in the message or contacting us. We may continue to send transactional, account, billing, security, and service-related communications when necessary.
Requests to stop a customer’s campaign communications should be directed to the business identified in the message. BoB HQ™ may assist when sufficient information is provided to identify the responsible customer and campaign.
14. United States state privacy disclosures
Depending on how the Services are used, BoB HQ™ may process the following categories of personal information described by United States state privacy laws:
- Identifiers, such as names, email addresses, telephone numbers, account identifiers, IP addresses, and business contact information;
- Customer-record information, such as contact, subscription, and billing details;
- Commercial information, such as subscription plans, transaction history, and service usage;
- Internet or electronic-network activity, such as device, browser, login, session, feature-use, and diagnostic information;
- Approximate location information derived from an IP address;
- Professional or employment-related information, such as agency, business, job-title, and producer information;
- Audio information, such as customer-provided campaign recordings;
- Inferences derived from activity or account information for security, support, and service improvement; and
- Sensitive personal information processed only when necessary for authentication, security, payment processing, or a customer-directed and legally permitted workflow.
The sources, business purposes, and categories of recipients associated with this information are described throughout this Policy.
BoB HQ™ does not use sensitive personal information to infer characteristics about individuals. BoB HQ™ does not sell Customer Data. As of the effective date, BoB HQ™ does not sell personal information for monetary consideration or share personal information for cross-context behavioral advertising as those terms are defined under applicable state privacy laws.
If these practices change, BoB HQ™ will update this Policy and provide any legally required opt-out method before beginning the new processing.
15. Children’s privacy
The Services are intended for business and professional use and are not directed to children under 18. BoB HQ™ does not knowingly permit children to create accounts or knowingly collect personal information directly from children through the Services.
If a parent or guardian believes a child has provided personal information directly to BoB HQ™, they may contact privacy@getbobhq.app. We will investigate and delete the information when required by law.
Customers must not use the Services to target minors or submit information about minors unless they have a lawful, documented business purpose and every legally required authorization.
16. International processing
BoB HQ™ is operated from the United States. Information may be stored and processed in the United States and other locations where BoB HQ™ or its service providers operate.
Privacy and data-protection laws in those locations may differ from the laws where an individual lives. When required, BoB HQ™ will use appropriate contractual or legal safeguards for international transfers.
Customers are responsible for determining whether their use of the Services involves international transfers and whether additional notices, agreements, assessments, or safeguards are required.
17. Changes and contact information
BoB HQ™ may update this Privacy Policy to reflect changes in the Services, data practices, vendors, security measures, or legal requirements.
When changes are material, we will provide reasonable notice through the Services, by email, on the website, or through another appropriate method before the updated Policy takes effect. The effective date at the top of this page identifies the current version.
Questions, requests, or concerns about this Privacy Policy may be directed to:
Ballestra Group, LLC, doing business as BoB HQ™
Privacy: privacy@getbobhq.app
Support: support@getbobhq.app
Website: https://getbobhq.com
