This policy explains what personal data NoyMed Academy collects when you use this website and account portal, how and why we use it, who we share it with, how long we keep it, and the rights and choices you have. It is written to apply globally; the specific rights you have depend on where you live. This policy forms part of your agreement with us under the Terms of Service.

1. Who is responsible for your data

NoyMed Academy is a certification training program operated by NoyMed Corp, a company registered in California, United States ("NoyMed", "we", "us", "our"). NoyMed Academy is not a separate legal entity.

For the purposes of the EU and UK General Data Protection Regulation ("GDPR") and comparable data protection laws, NoyMed Corp is the controller of the personal data described in this policy.

NoyMed Corp also operates a contract research organization known as NoyMed CRO. Where this policy refers to recruitment (section 4), the personal data involved is controlled by NoyMed Corp acting through its NoyMed CRO recruitment function.

Contact details for data queries are in section 15.

2. The data we collect

Data you give us

  • Account data: your email address, and - for password sign-in - a password managed by our authentication provider; or, for Google sign-in, the identifier, name, email address, and profile photo we receive from Google.
  • Profile data: full name, country, and optionally job title, organization, years of experience, and areas of interest.
  • Program data: which Program you are enrolled in, your enrollment, cancellation, and re-enrollment dates, and your lesson progress.
  • Assessment responses: the answers you submit to module assessments and final exams, and your scores and attempt history.
  • Consent and acknowledgment records: the version and timestamp of the Terms and disclosures you accepted, and any later choices you make about recruitment use.
  • Support messages: messages you send through our contact form (name, email, subject, message).
  • Feedback: content you submit through the in-product feedback widget, together with the page you were on and basic technical context such as your browser, viewport size, time zone, and referring page.

Data we collect automatically

  • Technical data: IP address, browser type and settings, device and operating system, and the dates and times of your requests, recorded in standard server logs by our hosting and infrastructure providers.
  • Authentication data: a session token stored in your browser to keep you signed in.
  • Local storage: a random identifier the feedback widget stores in your browser so we can recognize repeat feedback from the same browser without identifying you, plus small values that remember your preferences. These are not advertising cookies. See section 7.

Data from third parties

  • If you sign in with Google, Google provides us with your Google account identifier, name, email address, and profile photo.

We do not intentionally collect special categories of data (such as health, racial or ethnic origin, or political opinions), and we ask that you do not submit them through the Service.

3. How and why we use your data

We use your personal data for the purposes below. Where the GDPR or a similar law applies, the legal basis for each purpose is shown in brackets.

  • To create, secure, and operate your account and the Service, using your account, profile, technical, and authentication data. (Performance of our contract with you - the Terms of Service.)
  • To process enrollments, deliver lessons, administer and score Assessments, and issue Certifications, using your profile, Program, and Assessment data. (Performance of our contract.)
  • To operate the public certificate verification register (section 10), using your name, the Program, the issue date, and the certificate status. (Performance of our contract, and our legitimate interest in maintaining a credential that third parties can rely on.)
  • To communicate with you about your account, your enrollment, and changes to Programs, using your account data. (Performance of our contract.)
  • To respond to your support messages and feedback. (Our legitimate interest in supporting and improving the Service.)
  • For recruitment for NoyMed's studies (section 4), using your profile, Program, and Assessment data. (Our legitimate interest in operating a talent pipeline, or your consent where local law requires it.)
  • To keep the Service secure, prevent fraud and abuse, and enforce our Terms, using your technical, account, and Program data. (Our legitimate interest in protecting the Service and its users; compliance with legal obligations.)
  • To produce aggregated, de-identified statistics - for example average pass rates or common areas of difficulty - to improve our curricula. The output does not identify you. (Our legitimate interest in improving the Service.)
  • To comply with law and respond to lawful requests. (Compliance with a legal obligation.)

We do not use your Assessment answers or the messages you send us to train machine-learning or AI models, and we do not permit our service providers to do so.

4. Recruitment by NoyMed

One of the reasons NoyMed Academy exists is to identify and develop people for roles on NoyMed's studies. We want you to understand this clearly rather than discover it later.

What happens. The professional profile you build, and - as Programs mature - your performance in them, may be reviewed by NoyMed's recruitment function, and we may contact you about job opportunities. This most often happens after you earn a Certification, and may happen earlier where your profile indicates a strong fit.

How candidates are identified. We use a combination of automated flagging and human review. Automated flagging surfaces profiles that may match an open role, based on the information you provide - such as your stated discipline, experience, and areas of interest - and on your Program progress and Assessment results. No decision that produces legal or similarly significant effects is made about you solely by automated means: a member of our recruitment team reviews a profile before any contact is made. You can ask us to explain or reconsider any recruitment-related processing by writing to legal@noymed.com.

Legal basis. We process your data for this purpose on the basis of our legitimate interest in operating a talent pipeline for our own studies, which we have balanced against your interests and rights. Where local law requires your consent instead, we will ask for it separately.

Your choices. You can object to the use of your data for recruitment at any time by writing to legal@noymed.com. Objecting will not affect your access to Programs, your Assessments, or your Certifications, and is not a condition of holding an account. Some features of the Service are provided specifically in support of this purpose.

No offer of employment. Nothing in the Service, in any Program, or in any Certification is an offer of employment, a promise of an interview, or a guarantee of any recruitment outcome.

5. When we share your data

We share personal data with:

  • NoyMed CRO's recruitment function, for the purpose described in section 4.
  • Service providers who process data on our behalf, under contract and on our instructions:
    • Google LLC / Google Cloud - Firebase Authentication, Cloud Firestore, and related infrastructure (identity, database, hosting). Operated primarily in the United States.
    • Vercel Inc. - website hosting and content delivery.
    • When configured, an email delivery provider for account and transactional email, and an error-monitoring provider. We will name any such provider in section 7 before it goes live.
  • Authorities, regulators, and professional advisors, where required by law, to enforce our Terms, or to protect the rights, safety, or property of NoyMed, our users, or the public.
  • A successor entity in connection with a merger, acquisition, reorganization, or sale of assets, under this policy or a policy at least as protective.
  • The public, limited to the certificate verification data described in section 10.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising.

6. International transfers

Our infrastructure is operated primarily in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US and in other countries where our providers operate.

For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on an adequacy decision where one is available, or otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional safeguards where needed. You can ask us for more information about these safeguards using the details in section 15.

7. Cookies, analytics, and similar technologies

  • Marketing pages set no advertising or third-party tracking cookies.
  • The account portal uses strictly necessary cookies and browser storage to keep you signed in and to protect the Service. These cannot be switched off without breaking sign-in.
  • The feedback widget stores a random local identifier and its last on-screen position in your browser's local storage. This is not shared and is not used to track you across sites.
  • Analytics. We do not currently use third-party analytics or advertising trackers. If we add privacy-respecting analytics or error monitoring, we will name the provider and purpose in this section before it goes live.

8. How long we keep your data

  • Account and profile data: kept while your account is open. On deletion it is removed from our live systems promptly and cycles out of encrypted backups within 90 days.
  • Program and enrollment data, and Assessment responses: kept with your account and deleted with it, except where the information has been incorporated into a Certification record.
  • Certification records: retained permanently in our register so a credential can be verified, including after account deletion. After deletion your account identifier is removed; the certificate keeps your name, the Program, the issue date, and its status.
  • Certificate verification records (section 10): retained for the same period as the Certification they relate to.
  • Support messages and feedback: kept for up to 24 months after the matter is closed.
  • Consent and acknowledgment records: kept for as long as we rely on them and for up to 6 years afterward to evidence compliance.
  • Server logs: typically kept 14 to 90 days, longer where needed to investigate a security incident.
  • De-identified deletion record: when you delete your account we keep a record that contains no name, email address, or account identifier and does not identify you. Because it is not personal data, we retain it indefinitely for security, fraud prevention, and statistical reporting.

9. Deleting your account

You can delete your account from Settings. Before you confirm, you will see a summary of exactly what happens. Deletion:

  • removes your profile data, enrollment records, Program progress, and Assessment responses from our live systems;
  • deletes your sign-in credentials with our authentication provider;
  • retains any Certification you earned, with your account identifier replaced by a non-identifying reference and your name kept on the certificate so it remains verifiable (see section 10); and
  • writes the de-identified deletion record described in section 8.

Backups that include your data are overwritten on their normal cycle within 90 days. Deleting your account does not by itself remove an earned certificate from the public verification register; you can separately ask us to remove it from name-based search, as described in section 10.

10. Certificate verification and public data

We operate a public verification page at academy.noymed.com/verify/ so that employers and others can confirm a Certification is genuine.

When you earn a Certification, the following becomes publicly available through that page: your name as it appears on the certificate, the Program certified, the issue date, and the certificate's current status (valid or revoked). It does not include your email address, account identifier, contact details, or Assessment scores. The record can be looked up by certificate serial number or by searching the holder's name.

This record is retained even if you later delete your account, so the credential remains verifiable.

Your control over public listing. You may ask us at any time, including after deleting your account, to remove your certificate from name-based search by writing to legal@noymed.com. We will action such a request within 30 days. Your certificate will then remain verifiable by anyone you give the serial number to, but will no longer be discoverable by searching your name. Correction and revocation of certificates are handled under the Terms of Service.

11. Your rights and choices

Depending on where you live, you may have the right to access your personal data; to have it corrected or erased; to restrict or object to certain processing (including recruitment use and processing based on our legitimate interests); to data portability; and to withdraw consent where we rely on it, without affecting processing already carried out.

How to exercise your rights. Email legal@noymed.com or use our contact form. We may need to verify your identity before we act. We respond within the period required by applicable law - under the GDPR, within one month, extendable by two further months for complex requests; under the CCPA, within 45 days, extendable once. You can also access, correct, and delete most account data directly in Settings. There is no charge unless a request is manifestly unfounded or excessive. Authorized agents may submit requests on your behalf with proof of authorization.

EEA, UK, and Switzerland. Our legal bases are set out in section 3. You have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office); we would appreciate the chance to address your concern first. If we are required to appoint an EU/UK representative under Article 27, or a data protection officer, we will publish their contact details on this page.

California. In the 12 months before the date of this policy we collected the categories of personal information described in section 2 - identifiers, professional or employment information, education information, internet or network activity such as server logs, and inferences drawn for recruitment - for the purposes in section 3, from the sources in section 2, and disclosed them to the categories of recipients in section 5. We do not sell personal information and do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not knowingly process the personal information of consumers under 16. You have the right to know, delete, and correct your personal information, and not to be discriminated against for exercising your rights.

Other US states. Where you have equivalent rights under your state's privacy law (for example Colorado, Connecticut, Virginia, or Utah), you may exercise them using the contact details in section 15.

12. Security

We use technical and organizational measures appropriate to the risk, including encryption of data in transit, authentication and access controls, least-privilege administrative access, and reputable infrastructure providers. No online service can be completely secure. You are responsible for keeping your sign-in credentials confidential and for using a strong, unique password. Tell us promptly at legal@noymed.com if you believe your account has been accessed without your authorization.

13. Children

The Service is intended for professionals aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will close the account and delete the associated personal data. See section 2 of the Terms of Service.

14. Changes to this policy

We may update this policy as the Service develops - in particular as course content, assessments, certifications, and analytics are introduced. When we do, we will change the version number and "last updated" date at the top of this page.

For material changes - for example to the recruitment disclosure, the verification register, our legal bases, or your rights - we will notify registered users by email at least 30 days before the change takes effect. Material changes to the recruitment disclosure will be re-presented for your acknowledgment. For non-material changes, your continued use of the Service after the effective date constitutes acceptance.

15. How to contact us

NoyMed Corp (NoyMed Academy)
California, United States
Privacy requests and questions: legal@noymed.com

You can also reach us through our contact form. If you are in the EEA or UK and we are required to appoint a representative under Article 27 of the GDPR, we will publish their contact details on this page.

NoyMed Academy is operated by NoyMed Corp.