Privacy Policy
What information KPMS collects, how it is used, who can see it, and how long it is kept.
Version 1.0-draft · Effective Pending owner approval
DRAFT FOR OWNER/LEGAL REVIEW — this document has been prepared for review by the KPMS owner and, where appropriate, by an attorney. It has not been legally reviewed or approved and should not be relied upon as legal advice.
1. Scope
This policy describes how KPMS handles information collected through the KPMS platform, the public KPMS website, and the KPMS contact form.
KPMS is a training simulator that uses fictional patient data. It is not a healthcare provider, health plan, or clearinghouse, and this policy makes no claim of HIPAA covered-entity or business-associate status.
2. Information we collect
Account and profile information: name, email address, and optional profile details such as job title or phone number, together with your assigned role and a generated learner identifier.
Organization membership: the organization and cohort you belong to, your seat assignment, seat status, and your licence start and expiration dates.
Training activity: lessons and modules started and completed, knowledge-check and assessment attempts, scores and scoring breakdowns, work-queue and capstone decisions, documentation entries, progress events, badges, certificates, and instructor feedback notes.
Purchase and payment information: plan purchased, amount, currency, quantity, purchase and renewal dates, entitlement records, and Stripe references such as the Stripe customer identifier, checkout session identifier, payment or subscription identifier, and payment status.
Contact-form submissions: the name, email, organization, and message you send us through the KPMS contact or enquiry forms.
Security and integrity information: audit records of administrative and account actions with timestamps, sign-in events, and abuse-prevention data for public forms. For rate limiting of public forms, KPMS stores a salted hash of the requesting IP address rather than the raw address.
Technical information: cookies and local browser storage used to keep you signed in and to maintain your session and preferences. KPMS does not use advertising cookies or sell personal information.
3. Payment-card information is handled by Stripe
Card numbers, expiry dates, and security codes are entered directly with Stripe, our payment processor, through Stripe’s hosted checkout. KPMS does not receive, process, or store raw card numbers or security codes.
KPMS stores only the transaction references described above — for example the Stripe customer and session identifiers, the plan, the amount, and the payment status — so that we can provision access, support billing questions, and process refunds. Stripe’s handling of payment data is governed by Stripe’s own privacy notice.
4. How we use information
To create and secure your account, provision and expire training access, and deliver the training program.
To record, score, and report training activity to you and, where applicable, to your instructor and organization administrator.
To issue, display, and support verification of badges and Certificates of Completion.
To process purchases, renewals, cancellations, and refunds, and to send access-expiration and renewal reminders.
To respond to contact-form enquiries and support requests.
To protect the platform: authentication, authorization, abuse prevention, rate limiting, audit logging, and investigation of suspected credential sharing or fraud.
To improve the curriculum and platform using aggregated or de-identified activity information.
5. Who can see your information
You can always see your own account, training records, and purchases.
Instructors can see the learners in the cohorts they are assigned to. Organization administrators can see learners, seats, and reporting for their own organization only. Platform administrators can access platform-wide records for support, billing, and security purposes.
Access is enforced by server-side authorization and database row-level security policies, not by hiding controls in the interface. Organizations are isolated from one another.
Certificate verification: where a certificate is shared for verification, the verification page confirms the certificate’s validity and the training it represents. Verification requests are rate limited.
6. Service providers
KPMS uses a small number of processors to operate the service: a cloud database, authentication, and hosting provider; Stripe for payment processing; and an email delivery provider for account, reminder, and support messages.
Providers may only process information to deliver their service to KPMS. KPMS does not sell personal information and does not share it for cross-context behavioural advertising.
7. Security
KPMS uses authenticated access, role-based authorization, database row-level security, server-held service credentials that are never sent to the browser, audit logging, rate limiting on public endpoints, and safeguards against role or score tampering.
No online service can be guaranteed to be completely secure. We do not claim any specific security certification or compliance accreditation.
8. Retention
Training records, attempts, certificates, and audit records are retained so that completion can be verified and so that billing and security questions can be answered later. Ending access, expiring a licence, or reassigning a seat marks records inactive or archived rather than deleting them.
Purchase and payment records are retained as needed for accounting, tax, and dispute-resolution purposes. Contact-form submissions are retained for as long as needed to handle the enquiry and keep a record of it.
9. Your rights
You may access and export your own training record from your training summary page at any time, and you may correct your profile information from your account page.
You may request a copy, correction, or deletion of your personal information by contacting KPMS. Where deletion would remove a record KPMS must keep — such as a purchase record, an audit entry, or an issued certificate — we will explain what must be retained and why.
Depending on where you live, you may have additional rights under applicable privacy laws, including the right to complain to a supervisory authority.
10. Children’s privacy
KPMS is intended for adult learners and for post-secondary, career-school, and workforce training programs. It is not directed to children under 13, and we do not knowingly collect information from them.
Where a school enrols learners under 18, the school is responsible for obtaining any consent required by its own policies and applicable law. If we learn that we have collected information from a child under 13, we will delete it.
11. Changes and contact
This policy carries a version number and effective date shown at the top of this page. Material changes will be notified in the application or by email.
Billing, privacy, and policy questions can be sent to the KPMS support email published on the KPMS website and in the KPMS application. Organization customers may also contact their KPMS account contact directly.