ANDREAS EMPIRE GROUP LLC | PRIVACY POLICY

ANDREAS EMPIRE GROUP LLC

PRIVACY POLICY AND ONLINE PRIVACY NOTICE

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Effective Date: August 9, 2026
Last Updated: August 9, 2026

COMPLETE ALL YELLOW-HIGHLIGHTED CONTACT FIELDS BEFORE PUBLICATION.

Andreas Empire Group LLC, also referred to as “Andreas Empire Group,” “AEG,” “we,” “our,” or “us,” respects the privacy of consumers, clients, applicants, policyowners, beneficiaries, insurance producers, prospective producers, contractors, business contacts, website visitors, social-media users, and other persons who interact with AEG.

This Privacy Policy and Online Privacy Notice explains the categories of personal information AEG may collect; the sources from which information may be obtained; the purposes for which information may be used; the circumstances in which information may be disclosed; the choices and privacy rights that may be available; and the measures AEG uses to protect information.

This Policy is intended to operate together with AEG’s Social Media, AI-Generated Content, Insurance Education, and Recruiting Disclaimer, any insurance information-practices notice, carrier privacy notice, consent or authorization form, text-message or telephone disclosure, media release, producer agreement, and other notice provided for a particular transaction or service. If a transaction-specific notice imposes a more protective standard or addresses a subject more specifically, that notice will control for that transaction.

1. Scope of This Policy

This Policy applies to personal information collected, received, maintained, processed, or disclosed by or on behalf of AEG in connection with AEG-controlled websites, landing pages, online portals, appointment pages, lead forms, social-media pages, advertisements, direct messages, email, telephone calls, text messages, video conferences, webinars, live events, insurance inquiries, insurance applications, policy service requests, agent recruiting, producer contracting, training, lead-generation activities, and related business operations (collectively, the “Services”).

This Policy does not govern the independent privacy practices of an insurance carrier, insurance-support organization, independent marketing organization, brokerage general agency, payment processor, social-media platform, website, application, vendor, or insurance professional acting outside AEG’s direction or control. Those parties may provide their own privacy notices, and their practices are governed by their notices and applicable law.

This Policy applies only to information relating to an identified or reasonably identifiable individual. It does not apply to information that is lawfully public, aggregated, or de-identified so that it cannot reasonably be associated with an individual, except where applicable law provides otherwise.

2. AEG’s Role and Insurance-Specific Privacy Requirements

AEG is an independent insurance brokerage and agency. AEG is not an insurance carrier and does not make final underwriting, policy-issuance, premium, claims, or benefit determinations. Insurance products are issued by the applicable insurance carrier and are subject to carrier underwriting, policy provisions, state availability, licensing, appointment, and other requirements.

Information collected in connection with an insurance inquiry, application, policy, or transaction may be subject to the Gramm-Leach-Bliley Act, applicable state insurance information-practices laws, insurance department regulations, carrier privacy notices, and other financial-privacy or insurance requirements. AEG or the applicable carrier may provide a separate privacy notice or authorization when required. This online Policy does not replace any separate notice that must be delivered in connection with an insurance transaction.

Health or medical information provided for insurance underwriting is treated as sensitive and confidential. Not all health information received in the life-insurance context is necessarily “protected health information” under the Health Insurance Portability and Accountability Act. Such information may instead be governed by insurance privacy laws, carrier requirements, authorization forms, and other applicable law.

3. Definitions

For purposes of this Policy:

“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. The term includes “personal data,” “personally identifiable information,” and similar terms used by applicable law.

“Nonpublic personal information” includes personally identifiable financial or insurance information collected in connection with providing a financial or insurance product or service, to the extent protected by applicable law.

“Sensitive personal information” includes information such as Social Security numbers, government identifiers, account credentials, financial account information, precise geolocation, medical or health information, prescription information, biometric or genetic information, information concerning racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, and personal information concerning a known child, as defined by applicable law.

“Process” or “processing” includes collecting, using, storing, organizing, analyzing, transmitting, disclosing, deleting, or otherwise handling personal information.

4. Categories of Personal Information AEG May Collect

The information AEG collects depends on how a person interacts with AEG. AEG may collect the following categories, but does not necessarily collect every category from every person:

A. Identity and Contact Information

Name, signature, mailing address, email address, telephone number, preferred language, and communication preferences.

Date of birth, age, state of residence, and other information used to determine eligibility, licensing, or jurisdiction.

Usernames, account identifiers, social-media profile information, and information voluntarily provided through public posts or direct messages.

B. Insurance Inquiry, Application, and Policy Information

Coverage interests, requested benefit amounts, premium preferences, policy type, beneficiary information, existing coverage, replacement information, and insurance objectives.

Health history, medical conditions, prescription information, tobacco or nicotine use, height and weight, family history, occupation, avocations, driving history, and other underwriting information requested by an issuing carrier.

Income, assets, liabilities, net worth, source of funds, financial justification, tax-related information, and suitability or best-interest information where required for the requested product.

Social Security number, tax identification number, driver’s-license or other government identification information, bank-account or payment information, and electronic-signature data when required for an authorized insurance or payment transaction.

Application status, underwriting status, carrier decisions, policy numbers, premium information, policy-service requests, beneficiary changes, replacement documents, delivery acknowledgments, and related correspondence.

C. Communications and Relationship Information

Emails, text messages, call notes, appointment records, chat messages, direct messages, support requests, complaints, survey responses, and other correspondence.

Audio or video recordings, call transcripts, meeting notes, and quality-assurance information where recording or transcription is disclosed and permitted by law.

Information concerning the source of an inquiry, referral, campaign, advertisement, or lead.

D. Producer, Recruiting, Contracting, and Training Information

Employment or business history, resume information, education, references, professional experience, availability, and recruiting communications.

Insurance-license information, National Producer Number, states of licensure, carrier appointments, contracting status, background-check or compliance information, training completion, production information, chargeback information, and agent-support records.

Independent-contractor, compensation, payment, tax, lead-purchase, technology-access, and performance information, where applicable.

E. Transaction and Payment Information

Invoices, purchases, payment status, refunds, lead orders, training or event registrations, and transaction history.

Payment-card or bank information may be collected directly by a payment processor. AEG may receive a token, confirmation, partial account information, or transaction status rather than complete payment credentials.

F. Device, Internet, and Usage Information

Internet Protocol address, browser type, device type, operating system, language, time zone, approximate location, pages viewed, links clicked, referring pages, session information, and website or advertisement interactions.

Cookie identifiers, mobile advertising identifiers, pixel or tag information, and analytics or attribution information.

Security logs, authentication events, access records, and information used to detect fraud, misuse, or unauthorized activity.

G. Photographs, Video, Voice, Testimonials, and Event Information

Photographs, video, voice recordings, testimonials, reviews, statements, event attendance, and likeness information when voluntarily submitted or used pursuant to an appropriate release or authorization.

Editing, translation, captioning, or production information associated with authorized media content.

H. Inferences and Derived Information

Preferences, likely interests, service needs, communication preferences, campaign attribution, training needs, or other inferences derived from information described above.

AEG does not authorize an artificial-intelligence system to make a final insurance underwriting, policy-issuance, claims, employment, or other legally significant decision on AEG’s behalf unless expressly permitted by law and subject to appropriate human oversight.

5. Sources of Personal Information

AEG may obtain personal information from the following sources:

Directly from the individual, an authorized representative, family member, beneficiary, business contact, applicant, policyowner, producer, or prospective producer.

From AEG websites, landing pages, portals, appointment tools, forms, email, phone, text, chat, social-media pages, advertisements, webinars, events, and other communications.

From insurance carriers, independent marketing organizations, brokerage general agencies, insurance-support organizations, underwriting vendors, policy-administration vendors, and other authorized insurance participants.

From licensed producers, contractors, referral sources, lead-generation vendors, marketing partners, appointment setters, and other persons involved in responding to an inquiry or providing requested services.

From social-media platforms, advertising networks, analytics providers, website hosts, customer-relationship-management providers, scheduling tools, communications providers, and other service providers.

From public records, professional-license databases, industry databases, publicly available websites, and information lawfully made available by the individual.

From consumer-reporting or investigative sources when authorized by law and required for insurance underwriting, fraud prevention, producer contracting, or another lawful purpose.

6. How AEG Uses Personal Information

AEG may use personal information for the following business, insurance, operational, legal, and compliance purposes:

To respond to questions, requests, comments, complaints, and inquiries.

To schedule and confirm appointments, identify an appropriately licensed producer, and route an inquiry to an authorized representative.

To conduct a needs discussion, prepare or obtain insurance information, request carrier-approved illustrations or quotes, complete and submit applications, and support underwriting or policy issuance.

To provide policy delivery, follow-up, service, beneficiary, payment, replacement, and other post-application assistance.

To verify identity, authority, licensing, appointment, eligibility, and transaction information.

To recruit, interview, contract, appoint, onboard, train, supervise, support, compensate, and communicate with producers, contractors, and other business personnel.

To administer lead programs, marketing services, training programs, events, websites, portals, subscriptions, billing, payments, and customer support.

To send requested, transactional, service, educational, recruiting, or marketing communications, subject to applicable consent and opt-out requirements.

To personalize content, measure advertising performance, understand website and campaign activity, improve the Services, and develop business insights.

To maintain records, conduct audits, monitor quality, investigate complaints, prevent fraud, protect consumers, enforce contracts, and secure AEG systems and accounts.

To comply with insurance laws, privacy laws, licensing requirements, carrier obligations, subpoenas, court orders, regulatory requests, record-retention duties, and other legal requirements.

To establish, exercise, or defend legal rights and to protect the rights, safety, property, and operations of AEG, consumers, producers, carriers, and others.

For another purpose disclosed at or before collection, or with the individual’s authorization or consent.

7. Consumer Leads, Inquiry Routing, and Licensed Producer Contact

When a person submits an insurance inquiry, appointment request, instant form, landing-page form, referral, or other lead, AEG may assign or route the person’s contact and inquiry information to one or more appropriately licensed and authorized AEG producers, contracted producers, agency personnel, carrier partners, or service providers for the limited purpose of responding to the request, confirming an appointment, determining the appropriate licensed contact, or assisting with requested insurance services.

AEG may charge producers or business partners for lead-generation, appointment, marketing, technology, or administrative services. Such a business arrangement does not authorize the recipient to resell consumer information, use it for unrelated purposes, contact the consumer unlawfully, or disclose it except as permitted by contract, this Policy, the consumer’s authorization, and applicable law.

AEG’s policy is not to sell or license personal information to data brokers. AEG does not sell or license sensitive personal information, medical information, insurance application information, government identifiers, financial account credentials, or precise geolocation information for unrelated advertising or independent commercial use.

Some privacy laws define “sale” or “sharing” broadly and may treat certain advertising disclosures or compensated transfers as a sale or sharing even when no traditional sale occurs. Where such a law applies, AEG will provide the notice and privacy choices required by that law.

8. How AEG Discloses Personal Information

AEG may disclose personal information to the following categories of recipients for the purposes described in this Policy:

A. Insurance Participants

Issuing insurance carriers and their affiliates.

Independent marketing organizations, brokerage general agencies, field marketing organizations, third-party administrators, and carrier-authorized service providers.

Licensed and, where required, appointed producers assigned to respond to the individual or support the transaction.

Insurance-support organizations, underwriting vendors, medical-information vendors, consumer-reporting agencies, inspection services, and fraud-prevention services, where permitted and authorized.

B. Service Providers and Processors

Website hosting, cloud storage, customer-relationship management, scheduling, email, telephone, text messaging, call routing, call recording, transcription, electronic signature, document management, payment processing, accounting, analytics, advertising, cybersecurity, technical support, compliance, printing, mailing, and media-production providers.

Artificial-intelligence, translation, captioning, editing, automation, and content-production tools used under AEG direction for approved business purposes.

Consultants, auditors, accountants, attorneys, compliance professionals, and other professional advisers.

C. Legal, Regulatory, and Protective Disclosures

Federal and state insurance departments, licensing authorities, regulators, law-enforcement agencies, courts, governmental bodies, and other persons when required or permitted by law.

Persons necessary to investigate fraud, cybersecurity incidents, threats, unlawful activity, consumer complaints, contractual violations, or potential harm.

Parties to litigation, arbitration, regulatory examinations, audits, subpoenas, court orders, or other lawful proceedings.

D. Business Transactions and Authorized Disclosures

A prospective or actual purchaser, successor, lender, investor, affiliate, or transaction adviser in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.

Another person at the individual’s direction, with the individual’s consent, or as otherwise disclosed at the time information is collected.

9. Cookies, Analytics, Advertising, and Social-Media Technologies

AEG websites and online services may use cookies, pixels, tags, software-development kits, local storage, analytics tools, and similar technologies. These technologies may be operated by AEG or by third parties and may collect device, browser, usage, referral, campaign, and interaction information.

These technologies may be used for the following purposes:

Essential operations, security, authentication, load balancing, fraud prevention, and form functionality.

Remembering preferences, language, settings, or prior interactions.

Measuring website traffic, form completion, advertising attribution, content performance, and user experience.

Delivering, limiting, measuring, or personalizing advertising on AEG services or third-party platforms.

Connecting social-media features, embedded videos, scheduling tools, chat functions, or other integrated services.

Third parties such as social-media platforms, analytics providers, and advertising partners may use the information they receive according to their own privacy policies. Depending on the jurisdiction and the technology used, certain advertising-related disclosures may be considered a “sale,” “sharing,” or use for targeted advertising under applicable law.

Individuals may control many cookies through browser settings, device settings, platform advertising controls, or a cookie-preference tool made available on the applicable AEG website. Blocking certain cookies may affect website functionality. AEG will honor legally required opt-out preference signals where applicable and technically supported.

Because there is not a single universally accepted standard for browser “Do Not Track” signals, AEG may not respond to every such signal. This does not limit any right available under applicable law.

10. Telephone, Text Message, Email, and Call-Recording Practices

AEG may communicate by telephone, text message, email, direct message, or other channel when a person requests contact, provides consent, has an existing business relationship, or when communication is otherwise permitted by law. Any specific consent language presented on a form, advertisement, application, or communication controls over this general Policy. This Policy itself does not create consent to receive marketing calls or text messages.

Where applicable, message frequency may vary and message and data rates may apply. A recipient may reply “STOP” to opt out of marketing text messages and “HELP” for assistance, or use the unsubscribe mechanism in an email. Opting out of marketing communications will not necessarily prevent transactional, service, security, legal, or policy-related communications that AEG is permitted or required to send.

Telephone or video communications may be recorded or transcribed for training, quality assurance, documentation, fraud prevention, or compliance when notice and consent are provided as required by applicable law. AEG does not authorize undisclosed recording in violation of law.

11. Artificial Intelligence, Automation, and Digital Content

AEG may use artificial intelligence, automation, transcription, translation, scheduling, customer-relationship management, digital-avatar, and content-production tools to support approved business activities. Examples may include drafting or editing general content, translating or captioning media, organizing communications, scheduling appointments, routing inquiries, creating training materials, or presenting an authorized digital twin of Andreas Andreanidis.

AEG personnel and contractors are not authorized to place Social Security numbers, bank-account credentials, complete insurance applications, medical records, prescription details, or other highly sensitive consumer information into a general-purpose public artificial-intelligence tool unless the tool and use have been specifically approved for that information, appropriate contractual and security safeguards are in place, and the processing is permitted by law and carrier requirements.

Public-facing AI-generated or automated content is not a substitute for individualized review by an appropriately licensed insurance professional. An AI avatar, chatbot, or automated response cannot bind coverage, approve an application, issue a policy, make a carrier underwriting decision, guarantee a premium or benefit, or provide a final individualized insurance recommendation.

Additional disclosures concerning AEG’s use of AI-generated media, digital twins, stock media, synthetic voice, and digitally altered content appear in AEG’s Social Media, AI-Generated Content, Insurance Education, and Recruiting Disclaimer.

12. Testimonials, Photographs, Video, Voice, and Public Content

AEG may publish a testimonial, photograph, video, voice recording, success story, recognition post, or similar content only when AEG has an appropriate legal basis, which may include the individual’s written authorization, release, consent, or another basis permitted by law.

Once authorized content is posted publicly, other users may view, copy, share, comment on, or redistribute it outside AEG’s control. A request to withdraw consent will be considered prospectively and in accordance with the applicable release, contract, platform functionality, record-retention obligations, and law. AEG may not be able to retrieve copies previously shared or retained by third parties.

AEG will not knowingly use an AI-generated person or fabricated identity to create a false consumer testimonial, policyholder endorsement, agent testimonial, or business result.

13. Data Security and Confidentiality

AEG uses administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of personal information. Safeguards may include access controls, authentication, role-based permissions, secure transmission, vendor due diligence, confidentiality obligations, personnel training, monitoring, backup procedures, secure disposal, and incident-response practices appropriate to AEG’s size, operations, and the sensitivity of the information.

No system, website, transmission method, or storage environment can be guaranteed to be completely secure. Individuals should use caution, protect passwords and devices, and notify AEG promptly if they suspect unauthorized access, impersonation, fraud, or misuse of information.

Do not post or send Social Security numbers, dates of birth, medical information, prescription information, insurance policy numbers, application information, banking information, card information, passwords, or other sensitive information through public comments, ordinary social-media messages, or other unsecured channels. Use only an AEG-approved secure form, carrier-approved application system, or other authorized secure method.

14. Data Retention and Disposal

AEG retains personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, provide requested services, administer insurance or business relationships, comply with carrier and contractual requirements, maintain required records, resolve disputes, investigate complaints, prevent fraud, enforce agreements, and satisfy legal or regulatory obligations.

Retention periods vary based on the type and sensitivity of information, the nature of the relationship, applicable insurance and licensing requirements, limitation periods, litigation holds, security needs, and backup practices. When information is no longer required, AEG will take reasonable steps to delete, destroy, de-identify, or otherwise dispose of it in accordance with applicable requirements.

Deletion may not be immediate where information remains in secure backups, archived systems, legal holds, carrier records, regulatory files, fraud-prevention records, or records that AEG is required or permitted to retain. Information retained for these purposes will remain subject to appropriate protections.

15. Privacy Rights and Choices

Depending on the individual’s state or country of residence, the nature of the information, AEG’s role, and applicable exemptions, an individual may have one or more of the following rights:

To confirm whether AEG processes personal information and to request access to certain information.

To request correction of inaccurate personal information.

To request deletion of personal information, subject to legal, insurance, security, contractual, and record-retention exceptions.

To request a portable copy of certain information in a usable format.

To withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.

To opt out of certain sales, sharing, targeted advertising, or profiling activities where applicable law provides that right.

To limit certain uses or disclosures of sensitive personal information where applicable.

To appeal a denial of a privacy request where applicable law provides an appeal right.

To receive equal service and not be unlawfully discriminated against for exercising a privacy right.

These rights are not absolute. AEG may deny or limit a request when permitted or required by law, including when information is subject to an insurance, financial-privacy, fraud-prevention, legal, regulatory, security, evidentiary, or contractual exception.

16. How to Submit a Privacy Request

A privacy request may be submitted using one of the following methods:

Email: [INSERT PRIVACY EMAIL ADDRESS]

Online request form: [INSERT PRIVACY REQUEST FORM URL]

Mail: Andreas Empire Group LLC, Attn: Privacy, 1900 laurel rd Clementon, New Jersey 08021, United States

Telephone: 856-8038588

The request should identify the requester, the nature of the request, the relevant relationship with AEG, and the information or service involved. AEG may request information reasonably necessary to verify identity and authority. AEG will use verification information only for verification, fraud prevention, and compliance.

An authorized agent may submit a request where permitted by law. AEG may require proof of authorization and may contact the individual directly to verify the request. AEG will respond within the period required by applicable law and may extend the response period where legally permitted and reasonably necessary.

To appeal a denied request, send an email with the subject line “Privacy Request Appeal” to the privacy email address above and explain the basis for the appeal. AEG will review the appeal in accordance with applicable law.

17. State-Specific and Insurance-Law Limitations

State consumer privacy laws may apply differently depending on business size, processing volume, the purpose for which information is used, and statutory exemptions. Information governed by the Gramm-Leach-Bliley Act, state insurance information-practices laws, or other sector-specific requirements may be exempt from some general state privacy laws while remaining subject to separate insurance and financial-privacy protections.

AEG will evaluate privacy requests under the law applicable to the particular information and transaction. Where a broader consumer privacy right is not legally required, AEG may nevertheless honor a reasonable request when doing so is consistent with insurance obligations, security, fraud prevention, carrier requirements, contractual duties, and record-retention requirements.

18. Children’s Privacy

AEG’s Services are directed to adults and are not directed to children under 13. AEG does not knowingly collect personal information online directly from a child under 13 without verifiable parental consent where such consent is required.

Insurance applications may identify a minor as a child, dependent, proposed insured, owner, or beneficiary when information is provided by a parent, guardian, owner, applicant, or other authorized adult. Such information is handled for the applicable insurance purpose and is subject to carrier requirements and applicable law.

AEG recruiting, contracting, and insurance-producer opportunities are intended for individuals who are at least 18 years old and otherwise legally eligible. A person who believes a child has submitted information improperly should contact AEG using the methods in Section 16.

19. Social Media, Public Comments, and Direct Messages

Information posted in a public comment, review, group, forum, livestream, or other public area may be read, copied, recorded, used, or shared by others. AEG cannot control how third parties use information voluntarily made public. Individuals should not place confidential, medical, financial, policy, application, or other sensitive information in public social-media content.

Social-media platforms process information under their own terms and privacy policies. AEG may receive information made available by the platform, including profile information, lead-form responses, messages, comments, reactions, and advertising or analytics data.

Direct messages and ordinary social-media communications should not be treated as secure channels for an insurance application, medical information, payment information, identity documents, or other sensitive data. AEG may redirect the individual to an approved secure channel.

AEG may moderate, hide, restrict, preserve, or remove comments or messages that contain sensitive personal information, misinformation, spam, harassment, unlawful content, impersonation, unlicensed solicitation, or other inappropriate material.

20. Third-Party Websites, Platforms, and Services

AEG content may link to or integrate with insurance-carrier websites, payment providers, scheduling tools, social-media platforms, video platforms, document-signature services, analytics providers, and other third-party services. AEG does not control the privacy, security, availability, or content of an independent third party. Individuals should review the third party’s privacy notice before providing information.

The inclusion of a link, logo, integration, or reference does not by itself mean that AEG controls, sponsors, endorses, or assumes responsibility for the third party’s privacy practices.

21. Processing in the United States

AEG is based in the United States. Personal information may be processed and stored in the United States or another location where AEG’s carriers or service providers operate. Privacy and data-protection laws may differ from the laws of the individual’s location. Where required, AEG will use an appropriate legal mechanism for a cross-border transfer.

AEG does not intentionally direct insurance solicitation to a jurisdiction in which AEG or the applicable producer is not authorized to conduct the proposed activity.

22. Changes to This Policy

AEG may revise this Policy to reflect changes in law, insurance requirements, technology, vendors, business practices, or the Services. The revised Policy will identify an updated effective or “last updated” date. Where required by law, AEG will provide additional notice or obtain consent before applying a material change to previously collected information.

Individuals should review this Policy periodically. Continued use of the Services after an update does not constitute consent where applicable law requires a separate affirmative consent.

23. Contact AEG

Questions concerning this Policy, AEG’s privacy practices, or a suspected misuse of personal information should be directed to:

Andreas Empire Group LLC