Privacy Policy - Ysra Pena

Who we are

At Ysra Pena, (hereinafter, “the Brand”, “we”, or “our”), we deeply value the privacy of our users (hereinafter, “the User” or “you”). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you interact with our website, automated communication channels, marketing campaigns, and services related to life insurance, annuities.

By using the Site, providing your data through forms, agreeing to scheduled calls, or interacting with our automated assistants, you accept the practices described in this Policy.

Our website is: https://site.ysrapenainsurance.com/home-page-ki

1. Data Controller

The controller responsible for the processing of your personal data is:

       Brand: Ysra Pena

       Operation: United States of America

       Contact: [email protected]

2. Information We Collect

We collect personal information in different ways and at different stages of the relationship with the User. The categories of data we may collect include:

2.1 Information You Provide Directly

       Full name

       Phone number

       Email address

       State of residence (United States)

       Age

       Service of interest (IUL Policies, Term Life Policies, Annuities, Healthcare Insurance, Recruitment)

       Information related to qualifying questions: retirement concerns, current savings, existence of a 401(k) plan, purpose of the policy, among others

       Any additional information you voluntarily share during automated or human conversations

2.2 Information Collected Automatically

       IP address and approximate geographic location

       Type of device, browser, and operating system

       Pages visited, navigation time, and interaction patterns

       Source of traffic (Meta Ads, organic, referral, etc.)

       Cookies and similar tracking technologies

2.3 Information from Third Parties

We may receive data from third-party platforms when you interact with our advertising or content campaigns, such as:

       Meta (Facebook and Instagram lead forms)

       WhatsApp Business

       Google (analytics, calendar, reviews)

       TikTok (in the future, if applicable)

3. Purposes of Data Processing

We use the collected information for the following purposes:

       Pre-qualify your interest in life insurance, retirement plans, Medicare, or any health care programs

       Schedule and confirm Discovery calls, quote calls, interviews, and mentorship sessions

       Send automated reminders and follow-up messages through email, SMS, WhatsApp, phone calls, Instagram DM, and Facebook Messenger

       Connect you with the appropriate Brand team member based on the service of interest

       Provide educational and informational content related to financial protection and retirement planning

       Run lead nurturing campaigns and re-engagement of inactive contacts

       Improve our website, processes, and the experience offered

       Comply with applicable legal, regulatory, and contractual obligations, including A2P regulations for SMS in the United States

       Prevent fraud, abuse, and inappropriate use of our channels

4. Legal Basis for Processing

We process your personal data under one or more of the following legal bases:

       Express consent provided by the User when filling out forms or accepting communications

       Execution of a pre-contractual or contractual relationship (for example, when scheduling a call to receive a quote)

       Legitimate interest of the Brand in operating, improving, and promoting its services lawfully and proportionately

       Compliance with legal and regulatory obligations applicable to the insurance industry and commercial communications

5. Automated Communications

By providing your contact details, you expressly authorize the Brand to send you communications through automated channels, including SMS, WhatsApp, phone calls, email, Facebook Messenger, and Instagram DM. These communications may be operated by automated assistants (artificial intelligence) at initial stages and routed to a human team member when required.

You may unsubscribe at any time:

       By replying “STOP” or “UNSUBSCRIBE” on SMS or WhatsApp

       By using the unsubscribe link in our emails

       By writing to [email protected]

Standard message and data rates from your carrier may apply. The frequency of messages varies depending on the stage of the relationship and the campaign in which you participate.

6. Sharing of Information

We do not sell, rent, or commercialize your personal data. We share information only with the following categories of authorized third parties, exclusively for the purposes described in this Policy:

       Insurance companies, when proceeding with a quote, application, or policy issuance

       Technology platforms providing CRM, automation, calendar, hosting, and analytics services

       Communication providers (SMS, WhatsApp Business, Email, Voice AI)

       Authorized members of the Brand’s team for the management and follow-up of leads

       Authorities or judicial bodies, when legally required

All third parties with access to your data are required to keep the information confidential and use it only for the agreed purpose.

7. International Data Transfers

Some of the technology platforms we use may store information on servers located outside your state of residence, including in other regions of the United States or third countries. In such cases, we adopt reasonable measures to ensure that your information remains protected with standards equivalent to those described in this Policy.

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Approximate retention periods include:

       Active leads in pipelines: while the commercial relationship and follow-up cycles last

       Lost or disqualified leads: up to 24 months for re-engagement campaigns, unless the User requests deletion

       Customers and program participants: while the contractual relationship lasts plus the legally required period

       Tax, accounting, or compliance records: according to the periods established by applicable regulations

After these periods, the information will be deleted, anonymized, or duly archived.

9. Data Security

We implement reasonable technical, administrative, and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, including:

       Encrypted connections (HTTPS) on our website and forms

       Access controls and authentication on the CRM and management platforms

       Continuous training of the team in privacy and cybersecurity matters

       Use of recognized providers with industry-standard security certifications

Despite these measures, no system is one hundred percent secure. The User acknowledges and accepts this risk inherent to digital communications.

10. User Rights

Subject to applicable legislation — including, where relevant, the California Consumer Privacy Act (CCPA / CPRA) and other applicable U.S. state laws — you have the right to:

       Access the personal information we hold about you

       Request the rectification of inaccurate or incomplete data

       Request the deletion of your data, when not subject to legal retention

       Object to or restrict the processing of your data for certain purposes

       Withdraw your consent at any time, without affecting the lawfulness of prior processing

       Request the portability of your data, where technically feasible

       Submit a complaint to the competent authority in your jurisdiction

To exercise any of these rights, write to [email protected] indicating your full name, request, and contact information. We will respond within the timeframes established by applicable law.

11. Cookies and Similar Technologies

Our website uses cookies and similar technologies to ensure correct operation, analyze traffic, personalize the experience, and measure the effectiveness of advertising campaigns. The categories of cookies we use include:

       Essential cookies, necessary for the operation of the Site

       Performance and analytics cookies (e.g., Google Analytics)

       Advertising and remarketing cookies (e.g., Meta Pixel, TikTok Pixel)

       Functional cookies that remember your preferences

You can manage cookies from your browser settings. Disabling certain cookies may affect the functionality of the Site.

12. Minors

Our services are aimed at adults of legal age. We do not knowingly collect personal information from minors under 18 years of age. If we identify that we have received data from a minor without authorization from their legal guardian, we will delete it as soon as possible.

13. Links to Third Parties

Our Site and channels may contain links to external pages or platforms. This Policy does not apply to such third parties, and we recommend that you review their respective privacy policies before providing your data.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, or applicable legislation. The most recent version will always be available on our website with the corresponding update date. Continued use of our services after such updates constitutes acceptance of the changes.

15. Contact

If you have questions, comments, or wish to exercise any of your privacy rights, please contact us through:

       Email: [email protected]

       Official Facebook, Instagram, and WhatsApp channels published on the Site

16. Acknowledgment

By providing your personal information through any of our channels, you acknowledge that you have read, understood, and accepted this Privacy Policy in its entirety.