EXIMIONPrivacy Policy

Privacy Policy

EXIMION continuing-education platform for U.S. healthcare professionals

Effective date: July 2, 2026  •  Last updated: July 15, 2026  •  Version 1.1

1. Introduction

This Privacy Policy explains how Eximion Medical Education, LLC (“Eximion,” “Eximion Medical Education,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the EXIMION continuing-education platform, including the websites, simulations, peer-benchmarked assessments, and related services made available at eximion.com (collectively, the “Platform”).

EXIMION operates the Platform as the technology and content partner for accredited continuing education (“CE”) activities. Individual CE activities are offered in joint providership with an accredited provider — for example, Partners for Advancing Clinical Education (“PACE”) — which is responsible for accreditation, awarding of credit, and conflict-of-interest management. Because the accredited provider is responsible for the educational record, certain participation and performance data is owned and controlled by the accredited provider, as described in Section 6. Please read this Policy together with our Terms of Use.

The Platform is intended exclusively for licensed healthcare professionals located in the United States. It is not intended for patients, members of the public, or individuals under 18 years of age.

2. An important note about patient data

The clinical scenarios on the Platform are simulated, educational case studies. They do not describe real, identifiable patients. We do not ask you to enter, and you must not enter, any real patient information or protected health information (“PHI”) into the Platform. Because we do not collect real patient information, the Platform is not designed to function as a HIPAA-covered service for patient records. The information this Policy addresses is about you, the participating healthcare professional — not about any patient.

3. Information we collect

3.1 Information you provide

3.2 Information generated through your use of the Platform

3.3 Information collected automatically

4. How we use information

We use the information described above to:

5. Pseudonymity and how we protect your identity

The Platform uses a dual-layer identity architecture. Your verified identity (including your real name, NPI, and institutional affiliation) is held separately from your public participation profile. In competitive features, head-to-head challenges, leaderboards, and peer benchmarking, other participants and faculty see only your self-selected pseudonym and anonymized performance — never your real name, NPI, practice location, or individually identifiable results. Educational grant supporters receive only aggregate, de-identified outcomes and never see your pseudonym or any individual performance record (see Section 6.2).

6. How and with whom we share information

6.1 With the accredited provider

Individual participation and performance data generated through accredited CE activities is owned and controlled by the accredited provider (for example, PACE) as the entity responsible for the educational record. We process that data on the accredited provider’s behalf and in accordance with our agreement with it. The accredited provider uses this data to issue and document continuing-education credit and to meet its accreditation obligations.

6.2 With educational grant supporters (commercial supporters)

Accredited CE activities may be funded by independent educational grants from commercial supporters (for example, pharmaceutical companies). We and the accredited provider share only aggregate, de-identified outcomes data with a commercial supporter, according to a defined reporting schedule.

This separation reflects both our commitment to you and the independence requirements of accredited continuing education.

6.3 With service providers

We share information with vendors that perform services for us — such as hosting, data infrastructure, physician verification, analytics, email delivery, and technical support — under contracts that require them to protect the information and use it only to provide services to us.

6.4 For legal and safety reasons

We may disclose information if required by law, subpoena, or other legal process, or where we believe disclosure is necessary to protect our rights, the safety of any person, or the integrity of the Platform.

6.5 In a business transfer

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy.

We do not sell or share your identity, registration data, or individual participation or performance data for monetary or other valuable consideration or for cross-context behavioral advertising, as those terms are defined under the CCPA and comparable U.S. state privacy laws. To the extent any sharing of de-identified analytics could be considered a “sale” or “sharing” under those laws, we treat such data as de-identified and apply the safeguards in Section 7. Our use of cookies and similar technologies on our public marketing pages is described in Section 12.

7. De-identification and aggregation

When we create analytics for educational grant supporters or for our own research and product development, we aggregate data across participants and remove or obscure direct and indirect identifiers so that the output does not reasonably identify any individual physician. We maintain processes intended to prevent re-identification and contractually prohibit recipients from attempting to re-identify the data.

8. Data retention

We retain personal information only for as long as needed for the purposes described in this Policy, applying the following criteria by category:

We also retain information as needed to comply with legal obligations, resolve disputes, and enforce our agreements.

9. Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, or misuse, including encryption in transit, access controls, and separation of identity data from participation data. No system is completely secure, and we cannot guarantee absolute security.

10. Your privacy rights

Depending on your state of residence, U.S. privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA, and comparable laws in other states) may give you rights to:

To exercise these rights, contact us at support@eximion.com. We will verify your request before acting on it and will respond within 45 days, extending by up to an additional 45 days where reasonably necessary and with notice to you. Because the accredited provider owns certain CE performance records, we may need to direct part of your request to that provider, and some data cannot be deleted where retention is legally required. You may also designate an authorized agent to act on your behalf.

If we decline to act on your request, you may appeal by emailing us at support@eximion.com with the subject line “Privacy Appeal.” We will respond in writing within the period required by applicable law (generally 45 to 60 days). If we deny your appeal, we will provide information on how to submit a complaint to your state Attorney General.

11. Marketing communications

We may use your contact information to tell you about the Platform, new activities, and related educational offerings we believe may interest you.

12. Cookies and tracking technologies

We use cookies and similar technologies for the following purposes:

Your choices. You can opt out of the sale or sharing of your personal information at any time using the “Your Privacy Choices” link in the footer of our website. We recognize and honor the Global Privacy Control (GPC) and other recognized opt-out preference signals as a valid request to opt out of the sale or sharing of personal information, and we will display confirmation that your signal has been honored. You can also control cookies through your browser settings, though disabling some cookies may affect Platform functionality.

Do Not Track. Because there is no industry-standard response to browser “Do Not Track” signals, we do not respond to them; however, we honor the Global Privacy Control as described above.

13. Children

The Platform is intended only for licensed healthcare professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children.

14. Users outside the United States

The Platform is operated for and directed to healthcare professionals in the United States, and information is processed in the United States. If you access the Platform from another country, you understand that your information will be processed in the United States under U.S. law.

15. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date and provide additional notice where appropriate. For non-material changes, your continued use of the Platform after an update means you accept the revised Policy. Where a change would materially expand how we use or disclose personal information we have already collected about you, we will obtain your affirmative consent before applying that change to that previously collected information.

16. Contact us

If you have questions about this Policy or our privacy practices, contact us at:

Eximion Medical Education, LLC

Attn: Privacy

Email: support@eximion.com

Address: 1207 Delaware Avenue, Suite 2033, Wilmington, DE 19806, United States

For questions specifically about continuing-education credit records held by the accredited provider, contact Partners for Advancing Clinical Education, LLC (partnersed.com).