1. Who we are
TurnNet Labs LLC (“TurnNet,” “we,” “us”) provides OpenDesk, an agency desk SaaS product. Contact: turnnetprotocol@proton.me.
2. Data we process
Depending on how an agency uses OpenDesk, we may process:
- Account data: agency name, owner/producer emails, passwords (hashed), MFA secrets, seat roles.
- Client / applicant data the agency enters: name, contact, address, DOB, notes, household, vehicles/drivers, policy metadata. SSN may be stored by the agency in the desk; we do not use SSN for marketing.
- Billing: Stripe customer/subscription identifiers; we do not store full card PAN.
- Technical logs: IP-derived signals for abuse prevention, audit events for security actions.
3. How we use data
- Provide and secure the OpenDesk service
- Billing, support, and product communications
- Optional features the agency enables (email, Medicare Partner, gift cards, cloud sync, rater bridges)
We do not sell personal information. We do not scrape carrier or rater websites.
4. Sharing
We share data with subprocessors needed to run the product (see Trust): Vercel, Supabase, Stripe, Resend, and optional HealthSherpa / Tremendous. When an agency configures Canopy or Zapier outbound, applicant allowlist fields are sent to those destinations under the agency’s control — never SSN or full card PAN via OpenDesk rater exports.
5. Retention & security
Data is retained while the agency account is active and as needed for billing/legal obligations. We use HTTPS, provider encryption at rest, hashed passwords, MFA (TOTP), and aim to notify agencies within 72 hours of a confirmed security incident affecting their Customer Data. Details: Trust & security.
6. Agency responsibility
Agencies are controllers of their client book. They must have a lawful basis to enter client data, manage seats, enable MFA, and configure outbound integrations.
7. Your requests
Contact turnnetprotocol@proton.me for access, correction, or deletion requests. Agency owners can also export or delete data from the desk where the product allows.