Retirement Protectors, Inc.
Effective Date: September 21, 2026  | 
Last Updated: September 21, 2026

Retirement Protectors, Inc. (“RPI,” “we,” “us,” or “our”) is committed to protecting the
privacy and security of your personal information. This Privacy Policy describes how we collect,
use, disclose, and safeguard your information when you visit our website retireprotected.com,
use our services, or otherwise interact with us.

By using our website or engaging our services, you consent to the practices described in this
Privacy Policy.

1. Who We Are

Retirement Protectors, Inc. is a licensed insurance and financial services firm based in West
Des Moines, Iowa. We provide services across Medicare, retirement planning, life insurance, and
legacy planning.

2. Information We Collect

Information You Provide Directly

  • Contact information: Name, address, email address, phone number
  • Financial information: Income, assets, account balances, policy numbers,
    beneficiary designations
  • Health information: Medicare eligibility, health conditions relevant to
    insurance underwriting or claims
  • Identity information: Date of birth, Social Security number (last 4 digits
    displayed; full number stored encrypted), Medicare ID
  • Employment information: Employer, retirement status
  • Communications: Emails, call recordings (with consent), meeting notes,
    text messages you send to or receive from us

Information Collected Automatically

  • Website usage data: Pages visited, time on site, referring URL
  • Device information: Browser type, operating system, IP address
  • Cookies and similar technologies: We use cookies to improve your browsing
    experience and analyze site traffic

Information You Choose to Connect

  • Medicare claims data: If you choose to connect your Medicare account, we
    receive your Medicare claims and coverage information directly from the Centers for Medicare
    & Medicaid Services. This is optional, it is separate from everything above, and it is
    described in full in Section 7.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our insurance, financial planning, and advisory services
  • Process applications, claims, and policy changes
  • Communicate with you about your accounts, policies, and appointments
  • Send appointment reminders, service notifications, and account alerts via email, phone, or
    text message
  • Comply with legal and regulatory obligations
  • Respond to your inquiries and provide customer support
  • Analyze website usage to improve our online experience

4. How We Protect Your Information

Safeguarding your personal and financial information is foundational to everything we do. We
employ a multi-layer security approach:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest
    (AES-256) — the same standards used by financial institutions
  • Multi-factor authentication: Every team member must verify their identity
    with both password and phone authentication before accessing client data
  • Role-based access: Team members only see the information necessary for
    serving you — your Medicare specialist does not see investment details, and vice versa
  • Audit trails: Every access to your record is logged with timestamp and team
    member identity
  • Infrastructure: Our systems run on Google Cloud infrastructure, which
    maintains SOC 2 Type II, ISO 27001, and HIPAA certifications
  • Device security: Client information is only accessed from company-managed
    and secured devices with full-disk encryption
  • Team training: Every team member completes annual information security
    training covering current threats and best practices

5. How We Share Your Information

We do not sell your personal information. We may share your information with:

  • Insurance carriers: To process applications, underwriting, claims, and
    policy servicing
  • Service providers: Third-party vendors who assist with our operations
    (e.g., secure cloud hosting, communication platforms), all bound by data protection
    agreements
  • Regulatory authorities: When required by law, regulation, or legal
    process
  • With your consent: When you direct us to share information with other
    parties

All third-party vendors handling client data must meet our security requirements, including
encryption, access controls, and — where applicable — HIPAA Business Associate Agreements. Before
a vendor may receive or handle personal information on our behalf, we require contractual
commitments to data protection that are consistent with applicable law and appropriate to the
sensitivity of the information involved.

Medicare claims data is treated more restrictively than anything described above.
It is not shared with insurance carriers and is not shared with third parties. See
Section 7.4.

6. HIPAA & Health Information

When handling Medicare and health-related information, we comply with the Health Insurance
Portability and Accountability Act (HIPAA) Privacy and Security Rules. We have executed a Business
Associate Agreement with Google covering all Workspace services. Protected Health Information
(PHI) is stored exclusively within HIPAA-compliant systems and is never transmitted via
unencrypted channels.

7. Medicare Claims Data (Blue Button)

In plain terms: You can choose to connect your Medicare account to our
service. That lets us see your Medicare claims — the record of care you have received and what
Medicare paid. We use it to serve you better, we do not sell it or share it, and you can
disconnect at any time and have it deleted.

7.1 Connecting is your choice, and you make it separately

Connecting your Medicare record is optional. You do not have to connect it in order to work
with us, and nothing else about your service with us changes if you decide not to.

You connect through Medicare’s own website. You log in at Medicare.gov using your own Medicare
credentials and you authorize the connection there. We never see, ask for, or store your
Medicare.gov username or password
, and you should never give them to us or to anyone
else.

Before you connect, we ask you to actively agree to this Privacy Policy and to our Terms of
Service. We do not treat silence, inaction, or your continued use of our website as agreement to
connect your Medicare record.

7.2 What we receive

When you authorize the connection, Medicare sends us:

  • Your Medicare claims — Part A (hospital), Part B (medical), and Part D
    (prescription drug) claims billed to Medicare on your behalf, including the services and
    prescriptions involved, the dates, the providers, the amounts Medicare paid, and your share
    of the cost.
  • Your Medicare coverage information — which parts of Medicare you have and
    the periods you have been enrolled.
  • Your Medicare profile — the identifying information held in your Medicare
    record: name, date of birth, sex, race, and Medicare identifiers.

You can say yes to your claims and no to your profile. Medicare’s own
authorization screen lets you decline the profile information — the third item above, including
race and sex — while still sharing your claims and coverage. If you decline it we simply do not
receive it, we can still help you with everything in Section 7.3, and nothing else about your
service changes.

We receive only what Medicare sends us in response to the access you authorized. This
connection is read-only: we cannot change your Medicare record, we cannot change
your coverage, and we cannot see anything you have not authorized us to see.

7.3 What we use it for

We use your Medicare claims data for three purposes, and for nothing else:

  • Client service. Checking that your plan actually fits the care you receive,
    that your prescriptions are covered, and that your providers are in network — using your
    real claims instead of asking you to remember and re-enter everything on a questionnaire.
  • Proactive service. Noticing changes in your coverage, your costs, or your
    prescriptions so that we can reach you before a problem reaches you.
  • Claims and billing assistance. Helping you understand and resolve a claim
    or a bill, because we can see what was actually billed and what Medicare actually paid.

We do not use your Medicare data for advertising or marketing. We do not use it to
build prospect or marketing lists. We do not sell it. We do not use it to train artificial
intelligence models.

Where our AI-assisted tools help analyze your Medicare data, the protections in
Section 8 apply in full: your data is not stored by, and is not used to train,
AI models, and a qualified professional reviews the work before we act on it.

7.4 Who we share it with

We do not share your Medicare claims data with anyone outside RPI, except in two
circumstances:

  • When you direct us to. If you ask us to share something with a family
    member, caregiver, provider, or another advisor, we share only what you specifically direct,
    and only after you tell us to.
  • When the law requires it. A court order, a lawful subpoena, or a demand
    from a regulator with authority to make it.

We do not share your Medicare claims data with insurance carriers. We do not share it with data
brokers, marketers, advertisers, or analytics companies. We do not provide it to any third party
on a one-time basis, and we do not provide it to any third party on an ongoing basis.

7.5 De-identified and anonymized data

We do not create de-identified, anonymized, or pseudonymized datasets from your Medicare claims
data, and we do not share such data with anyone.

We take this position deliberately. Even health data that has had names removed can sometimes
be traced back to a specific person — particularly where a condition is rare or a combination of
treatments is unusual. Rather than manage that risk, we avoid it.

7.6 How long we collect it, and how it is stored

This is ongoing collection, not a one-time copy. While your connection is
active, we refresh your Medicare data periodically so that what we are looking at stays current.
That collection continues for as long as you keep the connection open, and it stops when you
disconnect.

Your Medicare data is stored inside our HIPAA-covered Google Workspace environment, encrypted
in transit and at rest, under the protections described in Sections 4 and 6. It is never written
to application logs, never transmitted over unencrypted channels, and never stored on a personal
device.

7.7 Disconnecting, and what happens to your data

You can disconnect at any time, in either of two places:

  • At Medicare.gov, in your list of connected applications; or
  • By contacting us at compliance@retireprotected.com or
    (515) 992-5000.

When you disconnect:

  • We stop retrieving your Medicare data immediately. Our access ends the
    moment you revoke it.
  • We securely delete the Medicare data we previously retrieved within
    30 days.
  • We confirm the deletion to you in writing.

Revoking access and deleting data are two different things, and we do both.
Revoking stops us reading anything new. Deleting removes what we already read. Some services stop
at the first and leave the second unsaid — we do not.

What we keep, and why — stated plainly rather than buried. If we used your
Medicare data to do actual work for you — a plan comparison we prepared, a roadmap we built with
you, or a claim we helped you resolve — then we keep that finished
work product, and two things make that the right answer. Insurance and financial recordkeeping law
requires us to keep a record of the advice we gave you. And the work itself is usually something
you still want: deleting your own plan comparison because you disconnected a data feed would be
a service failure, not a privacy protection.

What we keep is the document we produced with you. What we delete is
the underlying Medicare file — the claims themselves. We do not use the retained
work product for any purpose other than serving you and meeting our recordkeeping obligations.

If you want the work product deleted too, ask us and we will delete whatever the law
does not require us to keep
, and tell you specifically what remains and why.

7.8 Dormant and closed accounts

If your connection has gone unused and you have not worked with us for
24 months, we will contact you to ask whether you want to keep it
open. If we do not hear back from you within 60 days, we close the
connection and delete your Medicare data as described in Section 7.7.

If you close your account with us, we close the connection and delete your Medicare data on the
same terms.

7.9 If we change this section

Before we change anything in this section, we submit the proposed change to the CMS Blue Button
API team for review, as CMS requires of every organization with production access. We do not roll
out a change, and we do not notify you of one, until CMS has approved it.

Once approved, we will tell you by email what has changed, in plain language, before it takes
effect. You will have the opportunity to review it, change your settings, or disconnect. We will
never change how we handle your Medicare data quietly.

7.10 If there is a security or data breach

If your Medicare data is ever accessed, disclosed, or acquired without authorization, we will
notify you. We follow the HIPAA Breach Notification Rule and the Federal Trade Commission’s Health
Breach Notification Rule.

Our notice will tell you what happened, what information was involved, what we are doing about
it, and what steps you can take to protect yourself.

7.11 If our company is sold

If RPI is sold, merged with another company, or acquired, and the way your Medicare data would
be used could change as a result, we will notify you before that change takes effect. You will
have the opportunity to disconnect and have your Medicare data deleted first.

This product uses the Blue Button APIs but is not endorsed or certified by the Centers for
Medicare & Medicaid Services or the U.S. Department of Health and Human Services.

8. AI-Assisted Services

We use AI-powered tools to help analyze complex scenarios and generate documents. Your data is
never stored by or used to train AI models. All AI-generated work is reviewed by experienced
professionals before any action is taken. AI tools are used for operational efficiency only —
never as a database for client records.

9. Your Rights

Depending on your state of residence, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information (subject to regulatory retention
    requirements)
  • Opt out of certain data processing activities
  • Opt out of text message communications at any time by replying STOP
  • Disconnect your Medicare record at any time and have that data deleted, as described in
    Section 7.7 — this right does not depend on your state of residence

Iowa residents: RPI operates in compliance with the Iowa Consumer Data
Protection Act (effective January 1, 2025). To exercise your rights, contact us using the
information below.

10. Data Retention

We retain your personal information for as long as necessary to provide our services, comply
with legal and regulatory obligations, and resolve disputes. Insurance and financial records are
retained according to applicable state and federal requirements. When data is no longer needed, it
is securely deleted.

Medicare claims data obtained through the Blue Button connection is retained on the separate,
shorter terms described in Sections 7.7 and 7.8.

11. Cookies

Our website uses cookies and similar tracking technologies to improve your experience and
analyze site usage. You can manage cookie preferences through your browser settings. Disabling
cookies may affect certain website functionality.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy
practices of other sites. We encourage you to review the privacy policies of any site you
visit.

13. Children’s Privacy

Our services are not directed to individuals under 18 years of age. We do not knowingly collect
personal information from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an
updated effective date. We encourage you to review this page periodically.

Changes affecting Medicare claims data are governed by the additional process in Section 7.9,
which requires CMS review and approval before any change takes effect.

15. Contact Us

If you have questions about this Privacy Policy, how we handle your information, or wish to
exercise your privacy rights, please contact us:

Retirement Protectors, Inc.
6750 Westown Pkwy, Ste 200 PMB 382
West Des Moines, Iowa 50266
Phone: (515) 992-5000
Email: compliance@retireprotected.com

Insurance products and services are offered through Retirement Protectors, Inc.

We do not offer every plan available in your area. Currently we represent 14 organizations which offer 111 products in your area. Please contact Medicare.gov or 1-800-MEDICARE to get information on all of your options. This is a proprietary website and is not associated, endorsed or authorized by the Social
Security Administration, the Department of Health and Human Services or the Center for Medicare
and Medicaid Services. This site contains decision-support content and information about Medicare,
services related to Medicare and services for people with Medicare. If you would like to find more
information about the Medicare program, please visit the Official U.S. Government Site for People
with Medicare located at www.medicare.gov