Okiova
Okiova.comPrivacyTermsSign in
OKIOVA PLATFORM

Privacy & Data Use

How Okiova handles agency, customer, integration, communication, document, and operational data inside the application.

Last updated: September 20, 2026

This notice supplements the public Okiova Privacy Policy at okiova.com/privacy-policy/ and describes data handling inside app.okiova.com. Okiova is software for insurance agencies. The insurance agency using Okiova remains responsible for its insurance activities, customer relationships, lawful data collection, communications, and access decisions.

1. Multi-agency tenant data

Okiova is designed as a multi-tenant insurance operating platform. Agency-owned records are associated with an explicit agency identifier. This includes customers, policies, households, businesses, referral activity, commissions, service and retention work, documents, tasks, messages, automations, marketing activity, education content, usage records, and related operational information. Access controls are designed so an ordinary user of one agency cannot use another agency's records.

Okiova Platform staff may use explicit, auditable support or assist-mode access when needed to troubleshoot or support an agency. Platform administration does not make platform staff ordinary employees of the agency.

2. Google connected mailboxes

When an agency administrator connects a Gmail or Google Workspace mailbox, Okiova uses Google's OAuth process. The current connection requests basic identity information together with Gmail permissions needed to send, synchronize, mark read/unread, archive, move to spam, and move to trash from inside the agency's Okiova workspace.

Connected-mailbox data is tenant-scoped. Okiova uses the agency's authorized mailbox to ingest business communications into that agency's Communications Center, then separately attempts to associate a message with the correct customer, partner, or other CRM record. A message does not need to match a customer in order to belong to the agency inbox.

OAuth access and refresh tokens are stored as protected tenant-specific secrets. They are not displayed back to ordinary agency users. An agency can disconnect its mailbox in Okiova and can also revoke access through its Google account. Google controls OAuth app publishing, verification, and any security-assessment requirements that apply to restricted Gmail scopes.

Google Limited Use: Okiova's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Okiova does not sell Google user data or use Google user data for advertising.

3. Microsoft and other email connections

When an agency connects Microsoft 365, Okiova uses delegated authorization to identify the exact business mailbox and, when granted, send, synchronize, and manage mailbox state from inside Okiova. Okiova may also support custom SMTP connections. Credentials and authorization material are stored as tenant-specific protected settings where supported.

OAuth-connected Microsoft and Google mailboxes synchronize directly through the provider APIs. Custom SMTP or other providers may use a separately configured inbound-capture method when direct mailbox synchronization is unavailable.

4. Inbound email capture

For connected Microsoft and Google mailboxes, Okiova may process authorized incoming messages so they appear in the correct agency's Communications Center. Okiova uses the mailbox connection to establish tenant ownership first, then uses sender, recipient, headers, subject, and conversation context to attempt CRM matching.

If Okiova cannot safely determine the related customer or record, the message remains visible to the authorized agency as unmatched instead of being attached to an unrelated customer. Agencies remain responsible for deciding which business mailbox should be connected and for reviewing consequential customer instructions before acting on them.

5. Files, documents, protected identity and payment data

Okiova may store or process customer uploads, images, policy documents, agency media, generated documents, document requests, Okiova Sign records, driver-license or identification information, and other information the agency reasonably needs for insurance operations. Protected customer files are intended to be served only through authenticated or otherwise authorized Okiova routes.

For supported high-risk values, Okiova provides Secure Vault storage that encrypts the value at rest, binds access to the owning agency/customer, masks values by default, and audits full-value reveals. The long-term payment-card vault can protect the card number, cardholder, expiration information, and billing ZIP; it does not store CVV/card security codes. A separate short-lived payment handoff may be used for authorized policy-binding workflows and is designed for one-time retrieval and automatic destruction. Agencies remain responsible for deciding what information is appropriate and lawful to collect and retain.

6. Messages, automations, marketing, and education

Okiova can store secure portal messages, agency email activity, workflow automation history, marketing drafts and campaigns, review requests, and educational content. Agencies are responsible for lawful recipients, content, consent, suppression, frequency, and marketing practices. Okiova may provide safeguards such as suppression lists, role permissions, approval steps, cooldowns, and audit logs, but those safeguards do not replace the agency's legal responsibilities.

7. Oki, analytics, and operational logs

Oki and other Okiova assistance features may store conversation or workflow context inside Okiova so users can continue work. Okiova may also record sign-in, support, feature usage, automation, integration, security, billing, and audit events to operate, secure, troubleshoot, and improve the service.

8. Data sharing and service providers

Okiova may use hosting, email, authentication, storage, security, monitoring, and other service providers as necessary to operate the platform. Information may also be disclosed when directed by an authorized agency user, required by law, necessary to protect the service or users, or in connection with a business transaction subject to appropriate protections. Okiova does not sell agency or customer data to advertisers.

9. Retention, export, deletion, and account changes

Retention depends on the type of record, subscription status, legal obligations, backup practices, agency instructions, and Okiova's operational needs. Plan downgrades may disable functionality without deleting historical records. Agencies may use available export and lifecycle tools, subject to role permissions and applicable agreement terms.

10. Security and user responsibility

Okiova uses technical and organizational safeguards designed for a multi-tenant service, including tenant scoping, role/permission checks, protected secrets, audit records, and controlled support access. No online system can guarantee absolute security. Agencies remain responsible for their users, devices, connected accounts, passwords, email forwarding rules, and decisions about sensitive information.

11. Privacy requests and contact

Depending on applicable law, individuals may have rights concerning their personal information. If Okiova processes information on behalf of an agency, the agency may be the appropriate party to contact first. Privacy and connected-account questions may also be sent to admin@okiova.com.

© 2026 Okiova. Insurance operations, connected.admin@okiova.com okiova.com