Trust & Data Governance

Privacy Policy

How VieroMind Academy collects, uses, protects, and governs educational, identity, and account data across our platform.

Do not submit patient clinical records, therapy notes, or PHI into Academy learning or reflection fields unless a separately authorized workflow expressly permits it.

1.

Scope of this Policy

This Privacy Policy explains how VieroMind ("VieroMind Academy", "we", "us", or "our") collects, uses, stores, shares, and protects information when you access or use VieroMind Academy platforms, including our websites, web applications, learner and practitioner portals, faculty workbenches, institutional workspaces, and credential verification registries (collectively, the "Academy Platform" or "Services"). This policy applies to all registered learners, practitioners, institutional coordinators, faculty members, authorized reviewers, and public visitors.

  • Applies to all interactions with VieroMind Academy educational domains and API endpoints.
  • Covers account registration, social authentication, coursework progression, assessments, reflection entries, and institutional pilot administration.
  • Does not govern separate, independent third-party websites or external systems linked from our platform.
2.

Academy Educational & Clinical Boundaries

VieroMind Academy is dedicated to mental health education, cultural grounding, practitioner training, and institutional curriculum delivery. The Academy layer does not provide patient therapy, clinical psychiatric diagnosis, prescription management, or crisis intervention services.

Clinical Data Separation

VieroMind Academy is an education, professional-development, institutional-readiness, and governance environment. Users should not submit patient clinical records, therapy notes, protected health information (PHI), or other clinical-care content into Academy learning or reflection fields unless a separately authorized workflow expressly permits it.

3.

Categories of Data We Collect

We collect information directly from you, automatically through your device interactions, and from institutional partners who sponsor or coordinate your enrollment. We limit data collection to what is reasonably necessary to provide educational and administrative services.

A. Account & Profile Information

When you register or are provisioned access, we collect identifiers including your name, email address, institutional affiliation, professional title, credentials or role designation (where submitted), and profile picture (if provided).

B. Learning Progression & Assessment Records

We record your educational journey, including enrolled pathways, module progress, lesson completion timestamps, knowledge-check responses, quiz scores, reflection text entries, attendance records, and issued completion certificates.

C. Institutional & Workspace Metadata

For institutional deployments, we process cohort identifiers, pilot configurations, assigned faculty linkages, learner roster memberships, and administrative permission levels.

D. Uploaded Resources & Educational Artifacts

Institutional administrators and faculty may upload syllabi, training resources, and institutional documentation. We store file metadata, version records, and content digests to maintain repository integrity.

E. Technical, Device & Security Logs

When you access the platform, our infrastructure logs technical data including IP addresses, browser types, operating systems, referring URLs, access dates and times, session tokens, and security audit events to safeguard system integrity.

F. Cookies & Session Storage

We utilize essential session cookies and local storage tokens strictly required for authentication, session continuity, security controls, and locale preferences.

G. Communications & Inquiries

When you contact us for technical support, governance questions, or institutional inquiries, we collect records of your correspondence and contact details.

4.

Google Sign-In & Third-Party Authentication Data

VieroMind Academy provides the option to authenticate using Google Sign-In via OAuth 2.0. When you choose to sign in with Google, our OAuth integration requests access strictly limited to basic identity scopes: openid, userinfo.email, and userinfo.profile.

Information Received from Google

Through these basic identity scopes, VieroMind Academy receives your unique Google account identifier, email address, email verification status, and name or profile image made available by Google through your public profile.

What VieroMind Academy Does NOT Access

VieroMind Academy does NOT receive your Google password. VieroMind Academy does NOT access, read, or store the contents of your Gmail messages, Google Drive files, Google Contacts, Google Calendar, or other non-identity Google services.

Purpose of Processing Google Identity Data

Google identity information is accessed and used solely for user authentication, account creation or account linking, fraud prevention and security controls, and session routing within the Academy platform.

No Advertising or Commercial Sale of Google Data

Google user data is never used for commercial advertising, marketing profiling, or retargeting, and is never sold, rented, or traded to third parties.

5.

How We Use Your Information

We process personal information only for legitimate educational, administrative, and operational purposes, including:

  • Delivering educational coursework, modules, and pathway navigation.
  • Tracking learning milestones, evaluating knowledge check responses, and calculating completion progress.
  • Generating and verifying authentic completion certificates and educational credential records.
  • Enabling authorized faculty and institutional administrators to manage cohorts, review assignments, and monitor pilot readiness.
  • Maintaining system security, authenticating users, preventing duplicate submissions, and detecting unauthorized access.
  • Auditing pedagogical quality, curriculum alignment, and editorial rigor through our Clinical Review Console.
  • Communicating administrative updates, platform service notices, and responding to support or governance inquiries.
6.

Role-Based Visibility & Access Boundaries

VieroMind Academy applies role-based access principles to preserve institutional autonomy, privacy boundaries, and pedagogical governance across distinct user roles:

Learners & Practitioners

Users see data appropriate to their individual enrolled coursework, personal reflections, assessment scores, and issued certificates.

Faculty Members

Faculty visibility is scoped to authorized institutional workflows, designated cohorts, and assigned learners in accordance with institutional guidelines.

Institution Administrators

Institution administrators access administrative reports, pilot statuses, and progress summaries strictly scoped to their own institution.

Clinical Reviewers

Clinical Reviewer access is separately governed for curriculum and standards evaluation. Reviewers do not receive learner therapy, clinical records, or private identifiable account data merely by virtue of reviewer status.

Platform Administrators

Platform administrators have operational, security, and governance access only where necessary to maintain platform integrity, resolve technical issues, or satisfy compliance obligations.

7.

De-Identified & Aggregate Analytics

We may aggregate and de-identify learning interactions (such as aggregate completion rates, cohort pacing, and anonymized question difficulty metrics). De-identified and aggregate information supports product quality, curriculum improvement, operational analysis, research evaluation, and impact measurement. De-identified data is not used to identify individuals.

8.

Data Sharing & Vetted Service Providers

VieroMind Academy does not sell, rent, or trade your personal information to third parties. Information is shared only in the following limited circumstances:

Vetted Service Providers

We use vetted service providers for services such as authentication, hosting, database infrastructure, storage, email delivery, security monitoring, and analytics. Current providers may include Clerk (identity and authentication management), Amazon Web Services (cloud hosting and storage infrastructure), and Neon (database infrastructure). All providers are bound by appropriate confidentiality and data protection obligations.

Sponsoring Institutional Partners

If your enrollment is sponsored, funded, or administered by an academic institution, university, hospital, or clinic, your progress and completion records are accessible to authorized administrators and faculty of that institution pursuant to the applicable institutional agreement.

Public Certificate Verification Registry

When an issued certificate is queried via our public verification registry using a valid credential ID, the system displays the recipient name, module title, completion date, and credential status.

Legal & Regulatory Compliance

We may disclose information if required to do so by law, subpoena, court order, or governmental regulation, or when necessary to protect the safety, security, and integrity of our platform and users.

9.

Data Retention & Record Integrity

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law:

  • Completion, credential, and audit records may be retained for extended periods where needed for third-party certificate verification, institutional obligations, fraud prevention, legal claims, or record integrity.
  • Active account profiles are maintained for the duration of the account relationship plus a reasonable administrative wind-down period.
  • Retention periods may differ by record class and controlling institutional agreement.
  • Data may be securely deleted, destroyed, or de-identified when no longer required.
10.

Security Safeguards & Infrastructure

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure. Key measures include:

  • Encryption in transit (HTTPS/TLS) and encryption at rest where provided by the relevant underlying infrastructure services.
  • Authentication and session continuity controls, including multi-factor authentication for administrative and elevated roles.
  • Role-based access controls and environment separation.
  • Security monitoring, rate limiting, and audit logging of administrative and verification actions.

Security Notice

No system of electronic storage or transmission can be guaranteed to be completely secure. We encourage users to maintain robust passwords and safeguard their authentication credentials.

11.

International Data Handling & Transfers

Data may be processed in countries other than the user's country of residence, including the United States. Where required by applicable law or contract, VieroMind uses appropriate contractual, organizational, or technical measures for cross-border processing.

12.

Your Privacy Rights & Choices

Depending on applicable law and the nature of your account, you may have certain rights regarding your personal information, including:

  • Access & Inspection: Request confirmation of whether we process your data and obtain a copy of your records.
  • Correction: Request correction of inaccurate or incomplete account details.
  • Data Portability: Request an export of your learning progress and certificate records in a standard structured format.
  • Deletion: Request deletion of your personal data, subject to necessary retention for security, legal obligations, credential integrity, institutional contract, or audit purposes.
  • Withdrawal of Consent: Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
13.

Age Limitations & Minors

General and self-directed VieroMind Academy accounts are currently intended for adults (individuals aged 18 or older, or the age of majority in their jurisdiction). Current public registration is not designed as an unsupervised child-facing service. Any future participation by minors must occur only through separately authorized institutional workflows with applicable consent, safeguarding protocols, access controls, legal review, and partner approvals.

14.

Cookies & Session Technologies

We use essential and functional cookies and local storage technologies strictly necessary to operate the Academy platform:

  • Authentication & Session Continuity: Cookies managed by our authentication provider to maintain secure login sessions across page navigations.
  • Security & Device Verification: Tokens used to detect fraudulent activity, protect against cross-site request forgery, and enforce rate limits.
  • Preferences: Storing user interface preferences and locale selections.
15.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect enhancements in our platform, evolving educational services, or legal requirements. When revisions are made, we will update the "Last Updated" and "Effective Date" at the top of this page. For material revisions, we will provide notice through the Academy portal or by email where appropriate.

16.

Contact Information

If you have questions, feedback, or wish to exercise your privacy rights under this policy, please contact our team:

Compliance & Governance Contact

Email: compliance@vieromind.com Subject: Academy Privacy Inquiry

Support & Inquiries

Online: https://www.vieromindacademy.com/academy/support Email: compliance@vieromind.com (Attn: Academy Support)

Service & Governance

VieroMind Academy Attn: Privacy & Compliance Governance Website: https://www.vieromindacademy.com