AI Chatbot Disclaimer & Privacy Policy

Effective Date:10/28/2025

Last Updated:10/28/2025

Part I: AI Chatbot Disclaimer & Terms of Use

Please read this disclaimer carefully before using the AI Chatbot service provided by Carlson Insurance Group. By accessing and using this Chatbot, you acknowledge that you have read, understood, and agree to be bound by the terms and conditions set forth below.

1. Interaction with an AI System
You are interacting with an automated system powered by artificial intelligence (AI). This Chatbot is not a human. It is designed to provide general information based on the data it has been trained on.

2. For Informational Purposes Only; Not Professional Insurance Advice
The information provided by this Chatbot is for general informational purposes only and does not constitute professional insurance, financial, or legal advice. The responses generated by the Chatbot are not a substitute for consultation with a qualified and licensed insurance agent who can assess your individual needs.

3. No Agent-Client Relationship Formed
Your use of this Chatbot does not create an agent-client, fiduciary, or any other professional relationship between you and Carlson Insurance Group or any of its agents.

4. No Guarantee of Accuracy; Potential for Errors
While we strive to provide useful information, Carlson Insurance Group makes no representations or warranties of any kind, express or implied, about the accuracy, completeness, reliability, suitability, or timeliness of the information provided by the Chatbot. The AI may produce information that is incorrect, incomplete, or outdated, a phenomenon sometimes referred to as an "AI hallucination." You should independently verify any information from the Chatbot with a licensed insurance agent before making any decisions or taking any action.

5. WARNING: Do Not Submit Sensitive or Confidential Information
This chat is not a secure or confidential method of communication.1 DO NOT submit any sensitive personal information, confidential data, or nonpublic financial or health information through this Chatbot.2 This includes, but is not limited to, Social Security numbers, driver's license numbers, bank account or credit card numbers, claims details, or personal medical information. Note: While we collect Sensitive Personal Information (SPI) via secure, encrypted applications and forms necessary for service provision (Part II, Section 2), the Chatbot function is an insecure, open-text channel. Consumers must utilize designated, secure application portals or encrypted email for SPI submission.

6. Limitation of Liability
To the fullest extent permissible by applicable law, Carlson Insurance Group, its affiliates, and its agents shall not be liable for any direct, indirect, incidental, special, consequential, or punitive damages, or any loss of profits or revenues, whether incurred directly or indirectly, resulting from your access to or use of, or inability to access or use, the Chatbot, or from any reliance placed on the information provided by the Chatbot, even if we have been advised of the possibility of such damages. Your use of the Chatbot is solely at your own risk.

7. Data Use and Privacy
Your conversations with this Chatbot may be monitored and recorded for quality assurance, training, and service improvement purposes. For detailed information on how we collect, use, and protect your personal information, please review our full Privacy Policy detailed in Part II of this document. We confirm that conversation content collected via the Chatbot is not used to develop, improve, or train generalized AI or machine learning models.

8. Escalation to a Human Agent
This Chatbot cannot handle all inquiries. For complex questions, specific policy advice, or to file a claim, please contact a licensed agent directly by calling (615) 200-7464 or emailing hello@carlsoninsgrp.com.

9. Acceptance of Terms
By continuing to use this Chatbot, you signify your acceptance of and agreement to the terms of this disclaimer. If you do not agree to these terms, please close the chat window and contact us through other means.


Part II: Privacy Policy

1. Introduction
Carlson Insurance Group ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, carlsoninsurancegroup.com (the "Site"), including when you use our services or interact with our AI Chatbot.
This policy is designed to comply with our obligations under applicable U.S. privacy laws, including the Gramm-Leach-Bliley Act (GLBA) and the California Privacy Rights Act (CPRA), as well as the General Data Protection Regulation (GDPR) for individuals in the European Economic Area (EEA).

Please contact us with any questions about this policy:
Carlson Insurance Group
166 Belinda Pkwy Ste 100
Mt. Juliet, TN 37122
privacy@carlsoninsurancegroup.com

2. The Personal Information We Collect and How We Collect It
We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household ("Personal Information").
The following chart details the categories of Personal Information we may have collected about you in the past 12 months, the sources from which we collect it, and our business purposes for collection.

Category of Personal Information

Sources of Collection

Directly from you (e.g., when you fill out a form, application, or communicate with us via phone, email, text message, or our AI Chatbot); From our business partners (e.g., other insurers or agents).

Identifiers such as your real name, alias, postal address, email address, phone number, account name, Social Security number, driver's license number, passport number, or other similar identifiers.

Directly from you.

Personal Information categories listed in the California Customer Records statute () such as your signature, insurance policy number, financial account information.

Directly from you on applications or forms.

Characteristics of protected classifications under California or federal law such as age, marital status, or gender.

Directly from you; Automatically from your interactions with our Site and services.

Commercial Information including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Automatically from your device when you visit our Site (e.g., via cookies and log files).

Internet or Other Electronic Network Activity Information including browsing history, search history, and information regarding your interaction with our Site, AI Chatbot, or advertisements.

Automatically from your device when you visit our Site.

Geolocation Data such as your IP address which may indicate your general location.

Directly from you when you interact with our customer service channels (e.g., recordings of phone calls, voicemail messages, and chat transcripts). Note on AI Call Transcription: All phone calls are subject to automated recording and transcription via our unified communications system for quality assurance and the generation of conversation summaries and notes.5 Callers are notified of this disclosure and recording automatically at the start of the call.7

Audio, electronic, or visual information such as recordings of customer service calls, voicemail messages, and chat transcripts.

Directly from you on applications or forms.

Professional or Employment-Related Information such as your employment history, if relevant to an insurance application.

Derived from our analysis of your interactions with our services.

Inferences drawn from any of the information identified above to create a profile about you reflecting your preferences, characteristics, or predispositions.

Directly from you on applications or claims forms.

Sensitive Personal Information including your Social Security number, driver's license number, financial account details in combination with required access codes, and health insurance information.

3. How and Why We Use Your Personal Information (Purposes and Lawful Bases)

We only use your Personal Information for specified, explicit, and legitimate business purposes. For individuals in the EEA, we must also have a "lawful basis" for each processing activity. The table below outlines our purposes for processing your information.

Table 1: Data Processing Activities Matrix

4. How We Share Your Personal Information
We do not sell your Personal Information for monetary consideration. However, under California law, "sharing" for cross-context behavioral advertising may be considered a "sale." We may disclose your Personal Information to the following categories of third parties for a business purpose:

  • Affiliates: With our parent companies, subsidiaries, and other companies under common control.

  • Service Providers (GLBA Compliance): With vendors, consultants, and other service providers who perform services on our behalf, such as our Agency Management Systems, communication infrastructure, email security providers, and customer support software.9 These providers are contractually obligated to keep your information confidential and use it only for the services we have engaged them for. Specifically, disclosure of Non-Public Personal Information (NPPI) to our Agency Management Systems is strictly governed by contractual prohibitions that restrict the use or disclosure of NPPI outside of providing contracted services to our Agency, thereby ensuring compliance with the Gramm-Leach-Bliley Act (GLBA) service exception.9 We confirm that our AI vendors (including those providing chatbot and transcription services) are contractually prohibited from using your data to train their generalized AI models.5

  • Business Partners: With third parties to provide, maintain, and improve our products and services, such as underwriters, claims adjusters, and reinsurance companies.

  • Marketingand Advertising Partners (CPRA Sharing): We disclose (or ‘share’ under CPRA) identifiers, network activity information, and commercial data with certain Marketing Partners (such as our lead generation and retargeting platforms) for the explicit purpose of cross-context behavioral advertising.16 You have the right to opt-out of this sharing (see Section 5).

  • Government and Law Enforcement: To comply with applicable laws, regulations, legal processes, or governmental requests.

  • In Connection with a Business Transfer: In the event of a merger, sale, or asset transfer, your information may be transferred as part of that transaction.

5. Your Privacy Rights and How to Exercise Them
Depending on your jurisdiction, you may have certain rights regarding your Personal Information. We are committed to honoring these rights.

Table 2: Summary of Key Privacy Rights by Jurisdiction

How to Exercise Your Rights:
To exercise any of the rights described above, please submit a verifiable consumer request to us by:

Only you, or a person legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. We will need to verify your identity before processing your request. We will not discriminate against you for exercising any of your privacy rights.

Exercising Your "Opt-Out" and "Limit" Rights (California Residents):
You can exercise your right to opt-out of the sale or sharing of your Personal Information and your right to limit the use of your Sensitive Personal Information by clicking the links below:

6. Data Security and Retention
We have implemented and maintain reasonable administrative, technical, and physical security measures designed to protect the security, confidentiality, and integrity of your Personal Information from unauthorized access, use, or disclosure.
Our technical safeguards include the mandatory use of enterprise-grade solutions to enforce secure TLS 1.2/1.3 encryption on all sensitive email data in transit, ensuring every message containing Non-Public Personal Information (NPPI) or SPI is encrypted by default. Furthermore, all primary data repositories (including our Agency Management System and Unified Communications System) are secured in cloud environments utilizing industry-standard encryption at rest, auditing capabilities, and disaster recovery mechanisms.
We retain your Personal Information for no longer than is reasonably necessary to fulfill the purposes for which it was collected, as outlined in the "Data Processing Activities Matrix" in Section 3, and to comply with our legal obligations.

7. International Data Transfers
Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction.
If you are located in the European Economic Area (EEA), please be aware that we transfer your Personal Information to the United States. We ensure that such transfers are lawful and that your data is adequately protected by implementing appropriate safeguards, primarily by using the Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Information About Children
Our Site and services are not directed to children under the age of 16, and we do not knowingly collect Personal Information from children under 16. If we become aware that we have collected Personal Information from a child under 16 without verification of parental consent, we will take steps to delete that information.

9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. We encourage you to review this Privacy Policy periodically for any changes.

10. "Do Not Track" Signals
Some web browsers may transmit "Do Not Track" signals to the websites with which the user communicates. Because of differences in how web browsers incorporate and activate this feature, it is not always clear whether users intend for these signals to be transmitted, or whether they even are aware of them. We currently do not take action in response to these signals.