BrokerageLoop
Book a demo

Privacy Policy

BrokerageLoop — website, web application and mobile application. Last updated: .

Who this is for

BrokerageLoop is a work tool for the staff of insurance brokerages. It is not a consumer application: there is no public sign-up, and an account only exists because the brokerage that employs you created one. If you are reading this as a member of the public, there is nothing here for you to sign in to.

BrokerageLoop is operated by Deecoding SAL (Offshore), BDD 1082 — Patriarch Street, Beirut, Lebanon.

Whose data is in it, and who decides

Two different sets of people appear in this policy, and the difference matters.

Brokerage staff use the applications. Everything below about accounts, permissions and device access is about you.

The brokerage's own clients do not. They never sign in and have no account, but their details are recorded in the system by the staff who serve them, which is most of the personal information it holds.

For that client information, the brokerage decides what is collected and why; we hold and process it on their instructions and do not use it for anything of our own. A client who wants to know what is held about them, or wants it corrected or erased, should ask their brokerage. That is the party with the relationship and the authority to answer, and we support them in doing so.

What the applications handle

  • Account information for the brokerage staff who sign in: name, work email, and the role their brokerage assigned. Sign-in is handled by an identity provider; we do not store passwords.
  • Business records your brokerage enters: clients and their contact details, policies, claims, documents, payments and commissions. Depending on the brokerage and the market, this can include identification numbers and other sensitive personal information about their clients.
  • Documents and photographs uploaded or captured in the app: policy paperwork, receipts, cheque images.
  • Audit records. Every change to a business record is logged with who made it and when. These records are append-only by design: they cannot be edited or deleted, because their purpose is to show what happened.

The assistants, and what happens to what you say

The applications include an assistant that can answer questions about your brokerage's own records and, on the mobile app, hold a spoken conversation. While a spoken conversation is running, audio is streamed to Microsoft Azure's speech and language services to be understood and answered.

The conversation itself is not stored. Transcripts exist only for the length of the session and are discarded when it ends. What is kept is a record that a session started and ended, its duration and its language, never its content.

The assistant can look up your brokerage's own records to answer a question. It reads only what the signed-in user is already permitted to see, and every action it takes is written to the same audit trail as a human action, marked as made by the assistant on that user's behalf.

Connecting your own AI assistant

A brokerage may choose to connect BrokerageLoop to an AI assistant it already uses, such as Claude or ChatGPT, through a secure connector that the brokerage's administrator sets up. When that is done, the records that assistant requests are sent to that assistant's provider under the brokerage's own account with that provider, and that provider's terms and privacy policy apply to them. The connector only ever answers within the permissions of the signed-in user, and every request is logged in the audit trail. This connection is off unless a brokerage turns it on.

Where the data is held

BrokerageLoop runs a separate deployment for each country, so that a brokerage's records are held in its own market and each market's residency rules are met on their own terms.

For brokerages in the United Arab Emirates, no data leaves the UAE. This is enforced by the system, not left to configuration.

TODO(human) name the Azure region behind each country's deployment, and state the backup arrangement for each. This section previously described a single UAE North deployment with backups replicated to a paired European region; that is superseded, and the replacement needs the same verification against the product's source that produced the earlier text.

Some processing — the voice assistant in particular — runs in a different region from where records are stored. Whether that is permitted depends on the country the brokerage operates in, not on a setting anyone can change: where that country's rules do not allow it, the request is refused rather than sent out of region.

We use Microsoft Azure to run the service — hosting, the database, document storage, the email that sends invitations, and the speech and language services behind the assistant. We do not use analytics or advertising services, and the applications contain neither.

Permissions the mobile app asks for

  • Microphone: only to talk with the assistant, and only while a conversation is open.
  • Camera: to scan a code on a receipt, photograph a cheque, or capture a document for a policy or claim.
  • Photo library: to attach an existing photo to a policy, claim or task.

Each is requested when the feature is first used, and each can be declined or later withdrawn in your device settings. Declining disables that feature and nothing else.

What we do not do

  • We do not sell personal information.
  • We do not use it for advertising, and the applications carry no advertising.
  • We do not track users across other companies' apps or websites.

How long it is kept

Business records are kept for as long as the brokerage keeps them, and for as long as the law requires the brokerage to retain them. Audit records are retained for the life of the account, because they are the record of what happened.

Retention is configurable per brokerage, and defaults to ten years.

Accounts

Accounts exist only for brokerage staff, and are created and removed by the brokerage rather than by the individual, the same way a work email account is. There is no self-registration. If you no longer need access, ask your brokerage administrator to remove it.

Removing a user's access does not erase the audit record of work they already did, in the same way that a departed employee's past transactions stay in the books.

This website

This public website (brokerageloop.com) is separate from the applications and holds no brokerage records.

  • It sets no cookies. It stores one value in your browser's local storage: your chosen language, so the site opens in Arabic or English next time. Clearing your browser storage removes it.
  • It contains no analytics, advertising or tracking scripts.
  • If you contact us or request a demo, by email or through the demo form, we use what you send only to reply to you and to arrange the demo.
  • TODO(human) name the services that receive a demo-form submission (the form's notification email is sent through Resend; say whether submissions are also stored, and where) and how long they are kept.
  • TODO(human) name the hosting provider and region for the website itself once it is deployed.

Contact

For privacy questions or a data request, write to info@deecoding.com.

This policy is governed by the laws of Lebanon.

Ready to run your book from one register?

Book a walkthrough with our team, in English or Arabic.