Skip to main content

    Medtrics Certified Champion Enroll

    Privacy Policy

    Effective date: October 2026

    Medtrics Lab LLC ("Medtrics," "we," "us") builds software that helps medical, nursing, veterinary and allied-health programs run clinical education. This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It applies to:

    • our public website at medtricslab.com, including the forms through which you contact us, request a demo, request an on-site process-mapping session, or enroll in Champion Certification;
    • the Medtrics platform and Medtrics OS, including our web applications, mobile applications and integrations (together, the "Platform"); and
    • our sales, support and marketing communications.

    Two ways we handle your data

    How we treat your information depends on how you interact with us.

    When you visit our website or talk to our team, we decide how your information is used. We are the "controller" (or "business") for that information, and this policy governs it fully.

    When you use the Platform through your institution, your school, program or health system (your "Institution") has contracted with us to provide the service to its students, residents, faculty and staff. The Institution decides what information is collected and how it is used; we process it on the Institution's behalf and under its instructions, as a "processor" or "service provider." If you have questions about how your Institution uses the Platform, or want to access, correct or delete records held in it, please contact your Institution directly. We will help the Institution respond.

    If you do not agree with this policy, please do not use the website or the Platform.

    Information we collect

    We collect information in three ways: you give it to us, our systems record it automatically, or your Institution or another organization provides it.

    Information you give us

    • Contact and demo requests. When you fill in a form on our website, book a call, or email or phone us, we collect your name, work email address, organization, role, phone number and anything you write in your message.
    • Champion Certification. When you enroll, we collect your name, email address, password, institution and role, and we record your progress through the course and the certificate you earn.
    • Platform accounts. When your Institution gives you access to the Platform, we hold your name, email address, login credentials, role and program affiliation, and any profile details you or your Institution add.
    • Content you submit in the Platform. Evaluations and survey responses, case and procedure logs, schedule preferences, time and attendance entries, documents you upload, and messages you send through the Platform.
    • Support and feedback. Information you share when you contact our support team, join office hours, respond to surveys or take part in research or beta programs. Support calls and video sessions may be recorded with notice.
    • Events and marketing. Your name, contact details and interests when you sign up for a webinar, newsletter, conference meeting or similar.

    Information collected automatically

    • Device and connection data. IP address, browser type and version, operating system, device identifiers, language settings, and the general location derived from your IP address.
    • Usage data. Pages and screens you view, features you use, links you click, time spent, referring and exit pages, search terms, and error logs.
    • Cookies and similar technologies. See the Cookies section below for the specific tools we use and how to control them.
    • Mobile app data. If you use our mobile application, we collect your device type, operating system version, app version and crash reports. We request access to device features such as the microphone, camera or push notifications only when you turn on a feature that needs them, and you can revoke access in your device settings. The app does not collect your location.

    Information from your Institution and other sources

    • Education records. Your Institution loads information into the Platform so it can run its programs. Depending on how the Institution uses Medtrics this can include enrollment and rotation assignments, evaluations written about you by faculty or peers, competency and milestone ratings, grades and assessment results, case logs, OSCE results, attendance and duty hours, and, for GME finance modules, funding and stipend allocations.
    • Integrations. With your Institution's authorization, the Platform exchanges data with systems such as student information systems, learning management systems (for example Canvas), calendar services (Google Calendar, Outlook), email, Slack and SMS providers.
    • Business contacts. We may receive your work contact details from a colleague who refers you, from a partner, from an event organizer, or from publicly available professional sources, to help us keep our records accurate and reach the right people at an Institution.

    Patient information

    The Platform is an education-records system, not a clinical or medical-records system. It is not designed to receive, store or transmit protected health information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA). Medtrics is not a HIPAA covered entity or business associate, and because we do not handle PHI we do not enter into business associate agreements. Case logs, procedure records, voice dictation and similar features are built to capture what a student or trainee observed and did, in de-identified form. Institutions are responsible for instructing their users not to enter patient names, medical record numbers, dates of service or other identifiers, and users must follow their Institution's clinical-documentation and patient-privacy policies when using the Platform. If identifying patient information is entered contrary to these instructions, it remains the Institution's responsibility; the Institution can correct or delete the entry, and we will cooperate with the Institution to remove it.

    Voice dictation and microphone access

    Our mobile application includes an optional voice dictation feature. It lets a student or trainee speak clinical findings and observations, for example during a procedure or patient encounter, and have them converted to text and entered into the relevant Platform fields, such as a case log or procedure record. This is how it works and what we commit to.

    • You control the microphone. The app uses the microphone only after you grant permission in your device's operating system, and only while you are actively using the dictation control. It does not listen in the background. The first time you use the feature the app explains this and asks for your permission. You can withdraw permission at any time in your device settings; dictation will stop working and the rest of the app is unaffected.
    • Audio is used only to produce text. Your spoken audio is transmitted securely to a speech-recognition service that converts it to text. We do not keep the audio once the transcript has been produced. The resulting text is saved to the field you were completing and becomes part of your Institution's records in the Platform, governed by the Student and education records section of this policy.
    • No voice identification. We do not create voiceprints, use your voice to identify or authenticate you, or analyze voice characteristics for any purpose. We do not treat or use your voice as a biometric identifier.
    • No training, no marketing. Neither we nor our speech-recognition provider uses your audio or transcripts to train speech or AI models, and we never use them for advertising or sell them.
    • Keep patient information out. The feature is designed to capture clinical findings and what you did, not who the patient was. Do not dictate patient names, dates of birth, record numbers or other details that could identify a patient or any other person, and avoid capturing other people's voices. Your Institution's policies on clinical documentation and patient privacy apply whenever you use the feature. If identifying information is dictated by mistake, the resulting text is handled as Institution data and your Institution can correct or delete it; the audio itself is not kept.
    • Your Institution can see what you dictate. Dictation is a Platform feature your Institution chooses to enable, and the text it produces is visible to your Institution in the same way as text you type.

    How we use information

    We use personal information to run our business and deliver the Platform, and for no purpose that is incompatible with the reason it was collected.

    • Providing the Platform. Creating and managing accounts, delivering schedules, evaluations, logs, dashboards and reports, sending notifications your Institution has configured, and syncing with the integrations your Institution has authorized.
    • Responding to you. Answering demo, contact and process-mapping requests, scheduling calls and on-site sessions, issuing Champion certificates, and providing support.
    • Communicating with you. Sending service notices, security alerts, release notes, and changes to our terms or this policy. These messages are part of the service and cannot be opted out of while you hold an account.
    • Marketing. Sending newsletters, event invitations, product updates and other marketing to business contacts and website visitors who have asked for them or where the law otherwise allows. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us. We do not send marketing to students or residents based on their use of the Platform.
    • Improving our products. Understanding how the website and Platform are used, diagnosing problems, testing new features, and developing new products. Where practical we do this with aggregated or de-identified data.
    • Security and integrity. Authenticating users, detecting and preventing fraud, abuse and security incidents, and enforcing our agreements.
    • Legal compliance. Meeting our legal obligations, responding to lawful requests, and establishing or defending legal claims.

    Artificial intelligence

    Some of our features use artificial intelligence to summarize, analyze, transcribe or draft content. These features assist the people using them; they do not make decisions about students, trainees or Institutions on their own, and the results remain subject to review by the user and the Institution.

    • AI providers we use. We currently rely on OpenAI and Google (Gemini) models, accessed through their enterprise and API services. We may add or change providers over time and will update this policy when we do.
    • Data minimization. We send a provider only the information needed to perform the specific task requested, and we do not send more of your or your Institution's data than that task requires.
    • No training on your data. Our provider accounts are configured so that the data we submit is not used to train, retrain or improve the providers' models, and our agreements with those providers prohibit such use. We do not use Institution, student or website data to train AI models ourselves, and we do not sell or license personal information to anyone for AI training.
    • Retention. Requests sent to and results returned from AI services are retained by us for ninety (90) days for quality assurance and troubleshooting, as described in the Security and retention section, and are then permanently deleted. Content a user saves into a Platform record is governed by the Platform data retention terms.
    • Institution control. AI-assisted Platform features are enabled at the Institution level, and an Institution may request that specific features be disabled for its users.

    Legal bases for processing

    Where the data protection law that applies to you requires us to have a legal basis for processing, we rely on: performance of a contract (providing the Platform or responding to your request); our legitimate interests (running and securing our business, improving our products, and reaching business contacts), balanced against your rights; compliance with legal obligations; and your consent, where we ask for it, which you can withdraw at any time.

    Cookies and tracking technologies

    Our website and Platform use cookies, local storage, pixels and scripts ("cookies") to keep you signed in, remember your preferences, understand how our services are used, and measure our marketing. When you first visit medtricslab.com a consent banner lets you accept or decline non-essential cookies, and you can change your choice at any time through the Cookie Preferences link in the website footer.

    CategoryWhat it doesTools we use
    Strictly necessaryKeeps you signed in, secures sessions, remembers your cookie choices, balances traffic. Cannot be switched off.Medtrics session cookies, Supabase authentication, CookieYes consent cookie
    AnalyticsTells us which pages are visited, how long people stay, and where errors occur so we can improve the site and Platform.Google Analytics 4, Medtrics first-party page analytics, Lovable site analytics
    FunctionalPlays embedded video and scheduling widgets and remembers settings such as display preferences.Wistia, Calendly, YouTube
    Advertising (visitor identification)Attempts to match a visit to our website with a business contact profile (such as name, company, job title and work email) so our team can follow up with organizations that show interest in Medtrics. This script is blocked by default and loads only after you accept advertising cookies in our consent banner. You can withdraw that choice at any time through the Cookie Preferences link, after which the script will not load on future visits.RB2B

    These third parties may set their own cookies and collect information under their own privacy policies: Google, Wistia, Calendly, CookieYes, RB2B.

    Email analytics. Marketing emails we send contain a small image that tells us whether the email was opened and which links were clicked. You can prevent this by disabling images in your email client or by unsubscribing.

    Your controls. Besides our consent banner, you can block or delete cookies in your browser settings; the Platform will still work but you may need to sign in more often. You can also install the Google Analytics opt-out add-on. Our website honors the Global Privacy Control (GPC) browser signal as an opt-out of visitor identification and analytics cookies where the law requires it. We do not currently respond to "Do Not Track" signals, because there is no common standard for them.

    How we share information

    We do not sell personal information, and we do not share student or Platform data with anyone for advertising. We share information only in the following situations.

    • Your Institution. If you use the Platform through an Institution, the Institution and the administrators, faculty and staff it authorizes can see your information according to the permissions the Institution sets. Evaluations, logs and reports are visible to the people your Institution designates. Your Institution's policies govern that access.
    • Service providers. We rely on vendors who host our infrastructure, send email and SMS, run analytics, record support sessions, provide customer-relationship and support tools, and process payments. Our principal categories of providers are cloud hosting and databases, email delivery, marketing and CRM, customer support, analytics, video hosting, scheduling and AI services. Each is bound by contract to use the information only to provide services to us and to protect it appropriately.
    • Integration partners. When your Institution connects the Platform to another system (an SIS, LMS, calendar, email, Slack or SMS service), we exchange the data needed to make the integration work, as directed by the Institution.
    • Accreditation and reporting. At an Institution's direction we may prepare reports or exports for accrediting bodies and regulators such as the ACGME, LCME, COCA, CCNE, ACEN, AVMA COE or CAPTE.
    • Professional advisors. Lawyers, auditors, insurers and consultants who need the information to advise us, under confidentiality obligations.
    • Legal reasons. When we believe in good faith that disclosure is required by law, subpoena or court order, or is necessary to protect the rights, property or safety of Medtrics, our users or others, or to investigate fraud or security issues. Where we are legally permitted, we will notify the affected Institution before disclosing Platform data.
    • Business transfers. If Medtrics is involved in a merger, acquisition, financing, reorganization or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this policy or give you notice of any material change.
    • With your direction or consent. For example, when you ask us to send a generated document to a colleague, or to share your Champion certificate.

    We do not publish benchmarks or comparisons across Institutions. We may use aggregated or de-identified information that cannot reasonably be used to identify you or your Institution, such as overall usage statistics, to operate and improve our services.

    Student and education records

    Much of the information in the Platform is part of a student's, resident's or trainee's education record. We treat it accordingly.

    • FERPA. For U.S. Institutions, we act as a "school official" with a legitimate educational interest under the Family Educational Rights and Privacy Act. We use education records only to provide the Platform to the Institution, under its direct control, and we do not disclose them to anyone except as the Institution directs or the law requires.
    • No commercial use. We do not use student data for advertising, for building profiles for commercial purposes, or for selling to third parties. We do not use it to train AI models.
    • Access and correction. Students and trainees who want to see, correct or dispute something in their education record should contact their Institution, which controls the record. We will assist the Institution in responding.
    • Institution requests. We respond to an Institution's requests to access, export, correct or delete Platform data in line with our agreement with that Institution.
    • Other jurisdictions. For Institutions outside the United States, we comply with the student-privacy and data-protection terms in our agreement with the Institution and with the data protection and student-privacy laws that apply where the Institution operates.

    Children

    Our website and services are intended for adults in higher education and healthcare. We do not knowingly collect personal information from children under 13 (or under 16 where that is the applicable threshold). If you believe a child has provided us information, contact us and we will delete it.

    Security and retention

    How we protect information

    We use administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold. These include encryption of data in transit and at rest, role-based access controls, multi-factor authentication for our staff, logging and monitoring, regular backups, vendor security reviews, and staff training. Access to Platform data inside Medtrics is limited to people who need it to support your Institution, and our staff are bound by confidentiality obligations. No system is completely secure, so we also maintain an incident response process and will notify affected Institutions and individuals of a breach as required by law and our agreements.

    How long we keep information

    • Platform data. Education records and other Institution data are retained for the term of the Institution's agreement with us and for a defined transition period afterward, during which the Institution may export its records. At the end of that period the data is securely deleted or irreversibly de-identified, unless the Institution instructs us otherwise or a legal obligation requires longer retention.
    • Platform activity records. Records of individual user activity within the Platform, including authentication events, actions performed and changes made, are retained for two (2) years to support security monitoring, incident investigation, audit and accountability to Institutions. After two years they are securely deleted or anonymized.
    • AI processing data. Data processed by our AI-assisted features, including the inputs submitted to and outputs returned from the AI services we use, is retained for ninety (90) days to support quality assurance, error analysis and troubleshooting, and is then permanently deleted. Content that a user saves into a Platform record is governed by the Platform data retention above.
    • Website inquiries and marketing contacts. Retained while we have an active relationship or ongoing communication with you, reviewed periodically, and deleted on request.
    • Champion Certification accounts. Retained while the account is active; you can close the account by contacting us.

    We may keep information longer where needed to comply with legal obligations, resolve disputes, or enforce our agreements, and we may keep de-identified information indefinitely.

    Your rights and choices

    You can ask us to:

    • tell you whether we hold personal information about you and give you a copy;
    • correct information that is inaccurate or incomplete;
    • delete your information, subject to the exceptions below;
    • limit how we use certain information, or object to processing based on our legitimate interests;
    • provide your information in a portable format; and
    • stop sending you marketing, which you can also do through the unsubscribe link in any marketing email.

    To make a request, email help@medtricslab.com or write to the address in the Contact section. We will verify your identity before acting, usually by confirming the email address we have on file, and we will respond within the time the law requires (30 to 45 days in most places). You may use an authorized agent; we may ask the agent for proof that you authorized them. If we deny a request, we will explain why, and residents of states that provide an appeal right can appeal by replying to our decision.

    Some limits apply. We may keep information we need to meet legal obligations, complete a transaction you asked for, secure our services, or defend legal claims. Assessment results and other education records are controlled by your Institution, so requests to change them go to the Institution.

    If you use the Platform through an Institution, please direct requests about your Platform data to your Institution. It controls that data, and we will support it in responding.

    U.S. state privacy rights

    Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon and other states with comprehensive privacy laws have the rights listed above, plus the right to opt out of the "sale" or "sharing" of personal information and of targeted advertising, and the right not to be discriminated against for exercising their rights.

    We do not sell personal information for money. However, our website uses a visitor-identification service that matches website visits to business contact profiles, and analytics tools, and these may be treated as a "sale" or "sharing" of personal information under some state laws. You can opt out by declining advertising and analytics cookies in our consent banner (or through the Cookie Preferences link at any time), by turning on the Global Privacy Control signal in your browser, or by contacting us. We do not knowingly sell or share the personal information of anyone under 16.

    For California residents, the categories of personal information we have collected in the past 12 months are: identifiers (name, email, phone, IP address); professional information (institution, role); internet activity (pages viewed, interactions); commercial information (products of interest, agreements); education information (when provided by an Institution); and, for Platform users, any other categories the Institution chooses to collect. The sources, purposes and recipients are described in the sections above. We do not use or disclose sensitive personal information for purposes that require a right to limit.

    Users outside the United States

    We serve Institutions in a number of countries. Wherever you are, the rights listed above are available to you, and where the data protection law of your country grants additional rights, such as the right to withdraw consent, to restrict or object to processing, to request anonymization or blocking of data, or to be told which organizations we share your data with, we will honor them as that law requires. Requests go to the contact below. You also have the right to lodge a complaint with the data protection or privacy authority in your country. Medtrics Lab is established in the United States; the International transfers section explains how we protect information that moves across borders.

    International transfers

    Medtrics Lab LLC is established in the United States, and by default the Platform is hosted and supported from the United States. Our website, and the information collected through it (inquiries, demo and process-mapping requests, Champion Certification and marketing contacts), is hosted exclusively in the United States; the in-country hosting option described below applies to Platform data only. If you use our services from another country, your information may be transferred to, stored in and processed in the United States and in any other country where we or our service providers operate. Data protection laws in those countries may differ from the laws of your own.

    Where Platform data is hosted

    We recognize that many Institutions are subject to data residency, data sovereignty or sector-specific requirements that govern where student and institutional data may be stored.

    • In-country hosting on request. Where an Institution requires its Platform data to remain within its own country or region, we can provision a dedicated hosting environment in that jurisdiction. In that case the Institution's data is stored and processed in the agreed location, and the hosting location is recorded in our agreement with the Institution.
    • Local compliance. For each hosting jurisdiction, we operate in accordance with the data protection, privacy and information-security requirements that apply to the Institution under its national and sector regulations, as reflected in our agreement with the Institution, and we align our safeguards with the Institution's own governance framework. Where an Institution's regulations require specific controls, certifications or audit rights, we address them contractually before data is migrated.
    • Limited cross-border access. Even where data is hosted in-country, our support and engineering staff, who may be located outside that country, can require access to the environment to operate, maintain and support the Platform. Such access is role-based, logged and limited to what is needed, and is governed by the transfer terms in our agreement with the Institution. Where local law restricts such access, we agree the permitted scope with the Institution in advance.

    How we protect cross-border transfers

    Where the law requires a legal mechanism for transferring personal information across borders, we rely on recognized safeguards such as standard contractual clauses approved by the relevant authority, binding data transfer and data protection terms in our agreements with Institutions, and any additional measures the applicable law requires. Institutions may request a summary of the transfer mechanisms and safeguards that apply to their data by contacting us.

    Third-party sites and services

    Our website links to other sites (for example LinkedIn, YouTube and partner organizations), and the Platform can connect to third-party systems your Institution chooses. Those services have their own privacy practices, which we do not control. Review their policies before sharing information with them.

    Changes to this policy

    We will update this policy when our practices or the law change. The effective date at the top shows when it was last revised. For material changes we will give notice on our website, by email to Platform administrators, or through the Platform, before the change takes effect. Continued use of our services after the effective date means the updated policy applies.

    Contact us

    Questions, requests or complaints about this policy or our handling of your information can be sent to:

    Medtrics Lab LLC

    2000 Market Street, Suite 620, Philadelphia, PA 19103, United States

    Email: help@medtricslab.com

    Phone: 1-800-528-4718

    If you are not satisfied with our response, you may contact the data protection authority or consumer protection agency in your jurisdiction.