1. Introduction
This Privacy Policy explains how Eximion Medical Education, LLC (“Eximion,” “Eximion Medical Education,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the EXIMION continuing-education platform, including the websites, simulations, peer-benchmarked assessments, and related services made available at eximion.com (collectively, the “Platform”).
EXIMION operates the Platform as the technology and content partner for accredited continuing education (“CE”) activities. Individual CE activities are offered in joint providership with an accredited provider — for example, Partners for Advancing Clinical Education (“PACE”) — which is responsible for accreditation, awarding of credit, and conflict-of-interest management. Because the accredited provider is responsible for the educational record, certain participation and performance data is owned and controlled by the accredited provider, as described in Section 6. Please read this Policy together with our Terms of Use.
The Platform is intended exclusively for licensed healthcare professionals located in the United States. It is not intended for patients, members of the public, or individuals under 18 years of age.
2. An important note about patient data
The clinical scenarios on the Platform are simulated, educational case studies. They do not describe real, identifiable patients. We do not ask you to enter, and you must not enter, any real patient information or protected health information (“PHI”) into the Platform. Because we do not collect real patient information, the Platform is not designed to function as a HIPAA-covered service for patient records. The information this Policy addresses is about you, the participating healthcare professional — not about any patient.
3. Information we collect
3.1 Information you provide
- Registration and eligibility data: your name, email address, professional credentials, specialty, practice setting, and National Provider Identifier (“NPI”). We use third-party physician-verification services (for example, Doximity and public NPPES/NPI records) to confirm that you are an eligible licensed professional.
- Display identity (pseudonym): a self-selected pseudonymous handle and avatar that you choose for use in competitive and peer-benchmarking features.
- Communications: information you provide when you contact support, respond to surveys, or complete intent-to-change and feedback instruments.
3.2 Information generated through your use of the Platform
- Educational performance data: your answers, diagnostic and treatment decisions at each decision node, accuracy, time-to-decision, test-selection choices, and other simulation outcomes.
- Confidence and calibration data: self-reported confidence ratings paired with your decisions.
- Engagement data: activities started and completed, session counts, progress, rankings, and credits earned.
3.3 Information collected automatically
- Technical and usage data: IP address, device and browser type, log data, approximate location derived from IP, and interactions with the Platform, collected through cookies and similar technologies (see Section 12).
4. How we use information
We use the information described above to:
- operate, deliver, and secure the Platform and its competitive and peer-benchmarking features;
- verify your eligibility as a licensed healthcare professional;
- track participation and decision-making so the accredited provider can issue continuing-education credit;
- generate individual performance scorecards and peer-benchmarked rankings (displayed under pseudonyms);
- produce aggregate, de-identified educational analytics — such as Diagnostic Pathway Failure Analysis and Confidence Calibration Analysis — to measure educational effectiveness and inform future programs;
- respond to your requests, send service-related communications, and improve the Platform;
- comply with accreditation standards (including the ACCME Standards for Integrity and Independence), legal obligations, and our agreements with accredited providers.
5. Pseudonymity and how we protect your identity
The Platform uses a dual-layer identity architecture. Your verified identity (including your real name, NPI, and institutional affiliation) is held separately from your public participation profile. In competitive features, head-to-head challenges, leaderboards, and peer benchmarking, other participants and faculty see only your self-selected pseudonym and anonymized performance — never your real name, NPI, practice location, or individually identifiable results. Educational grant supporters receive only aggregate, de-identified outcomes and never see your pseudonym or any individual performance record (see Section 6.2).
6. How and with whom we share information
6.1 With the accredited provider
Individual participation and performance data generated through accredited CE activities is owned and controlled by the accredited provider (for example, PACE) as the entity responsible for the educational record. We process that data on the accredited provider’s behalf and in accordance with our agreement with it. The accredited provider uses this data to issue and document continuing-education credit and to meet its accreditation obligations.
6.2 With educational grant supporters (commercial supporters)
Accredited CE activities may be funded by independent educational grants from commercial supporters (for example, pharmaceutical companies). We and the accredited provider share only aggregate, de-identified outcomes data with a commercial supporter, according to a defined reporting schedule.
- We do not share with any commercial supporter: your name, NPI, contact details, pseudonym, individual performance records, raw behavioral data, or participant databases.
- Commercial supporters do not receive: access to the educational platform, participant databases, or granular individual performance records.
This separation reflects both our commitment to you and the independence requirements of accredited continuing education.
6.3 With service providers
We share information with vendors that perform services for us — such as hosting, data infrastructure, physician verification, analytics, email delivery, and technical support — under contracts that require them to protect the information and use it only to provide services to us.
6.4 For legal and safety reasons
We may disclose information if required by law, subpoena, or other legal process, or where we believe disclosure is necessary to protect our rights, the safety of any person, or the integrity of the Platform.
6.5 In a business transfer
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy.
We do not sell or share your identity, registration data, or individual participation or performance data for monetary or other valuable consideration or for cross-context behavioral advertising, as those terms are defined under the CCPA and comparable U.S. state privacy laws. To the extent any sharing of de-identified analytics could be considered a “sale” or “sharing” under those laws, we treat such data as de-identified and apply the safeguards in Section 7. Our use of cookies and similar technologies on our public marketing pages is described in Section 12.
7. De-identification and aggregation
When we create analytics for educational grant supporters or for our own research and product development, we aggregate data across participants and remove or obscure direct and indirect identifiers so that the output does not reasonably identify any individual physician. We maintain processes intended to prevent re-identification and contractually prohibit recipients from attempting to re-identify the data.
8. Data retention
We retain personal information only for as long as needed for the purposes described in this Policy, applying the following criteria by category:
- Account and registration data controlled by Eximion: retained until 36 months after your last activity, unless a longer period is required by law.
- Educational participation and performance records controlled by the accredited provider: retained for the period required by accreditation standards, typically at least six years from the date of the CE activity.
- Aggregate, de-identified data: may be retained indefinitely.
We also retain information as needed to comply with legal obligations, resolve disputes, and enforce our agreements.
9. Security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, or misuse, including encryption in transit, access controls, and separation of identity data from participation data. No system is completely secure, and we cannot guarantee absolute security.
10. Your privacy rights
Depending on your state of residence, U.S. privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA, and comparable laws in other states) may give you rights to:
- know and access the personal information we hold about you;
- request correction of inaccurate personal information;
- request deletion of your personal information, subject to exceptions (including continuing-education recordkeeping obligations held by the accredited provider);
- opt out of any “sale” or “sharing” of personal information and of targeted advertising; and
- not be discriminated against for exercising your rights.
To exercise these rights, contact us at support@eximion.com. We will verify your request before acting on it and will respond within 45 days, extending by up to an additional 45 days where reasonably necessary and with notice to you. Because the accredited provider owns certain CE performance records, we may need to direct part of your request to that provider, and some data cannot be deleted where retention is legally required. You may also designate an authorized agent to act on your behalf.
If we decline to act on your request, you may appeal by emailing us at support@eximion.com with the subject line “Privacy Appeal.” We will respond in writing within the period required by applicable law (generally 45 to 60 days). If we deny your appeal, we will provide information on how to submit a complaint to your state Attorney General.
11. Marketing communications
We may use your contact information to tell you about the Platform, new activities, and related educational offerings we believe may interest you.
- Where required by law, we will obtain your consent before sending marketing emails.
- You can opt out at any time using the unsubscribe link in any marketing email or by contacting us at support@eximion.com. Opting out of marketing does not affect service messages needed to administer your account, your continuing-education credit, or the Platform.
- We do not sell your personal information, and we do not share it with commercial supporters for their own marketing.
12. Cookies and tracking technologies
We use cookies and similar technologies for the following purposes:
- Essential and first-party cookies: to keep you signed in, remember your preferences, and secure the Platform. These are necessary for the Platform to function.
- Analytics: we use Google Analytics, configured as our service provider, to understand how the Platform is used. We do not permit this data to be used for Google’s own advertising purposes.
- Advertising and marketing (public marketing pages only): on our public marketing and landing pages, we use third-party cookies and similar technologies for advertising, retargeting, and campaign measurement. Under the CCPA and comparable U.S. state privacy laws, this activity may constitute a “sale” or “sharing” of personal information. We do not use these technologies within the logged-in Platform, and they are never applied to your individual participation or performance data.
Your choices. You can opt out of the sale or sharing of your personal information at any time using the “Your Privacy Choices” link in the footer of our website. We recognize and honor the Global Privacy Control (GPC) and other recognized opt-out preference signals as a valid request to opt out of the sale or sharing of personal information, and we will display confirmation that your signal has been honored. You can also control cookies through your browser settings, though disabling some cookies may affect Platform functionality.
Do Not Track. Because there is no industry-standard response to browser “Do Not Track” signals, we do not respond to them; however, we honor the Global Privacy Control as described above.
13. Children
The Platform is intended only for licensed healthcare professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children.
14. Users outside the United States
The Platform is operated for and directed to healthcare professionals in the United States, and information is processed in the United States. If you access the Platform from another country, you understand that your information will be processed in the United States under U.S. law.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and provide additional notice where appropriate. For non-material changes, your continued use of the Platform after an update means you accept the revised Policy. Where a change would materially expand how we use or disclose personal information we have already collected about you, we will obtain your affirmative consent before applying that change to that previously collected information.
16. Contact us
If you have questions about this Policy or our privacy practices, contact us at:
Eximion Medical Education, LLC
Attn: Privacy
Email: support@eximion.com
Address: 1207 Delaware Avenue, Suite 2033, Wilmington, DE 19806, United States
For questions specifically about continuing-education credit records held by the accredited provider, contact Partners for Advancing Clinical Education, LLC (partnersed.com).