Privacy Policy
Last updated: June 29, 2026. This combined policy covers NEIMS and Vital Deploy.
Who This Policy Covers
This Privacy Policy applies to Vital Deploy, related public websites, account signup, marketplace access, certificate verification, public weather, community notification tools, and services operated by New England Institute of Medicine and Science LLC under the NEIMS and Vital Deploy names.
This policy is intended to support United States operations while using privacy practices that are compatible with GDPR-style transparency and rights workflows where applicable.
Information We Collect
We may collect contact information, account information, organization relationship, role or title, learning and certificate records, marketplace and subscription information, support communications, public form submissions, device and log information, and security/audit records.
Certificate verification is limited to verification-code or QR-target lookup. Public pages are not intended to expose protected learner records, personnel files, patient information, or private organization data.
How We Use Information
We use information to operate accounts, provide learning and marketplace services, manage certificates, support agency or institutional workflows, communicate about services, maintain security, meet legal or contractual obligations, and improve the platform.
We do not use public request-information forms for protected health information, patient information, student records, or sensitive personnel records.
Legal Bases and Privacy Rights
Depending on your location and relationship with us, processing may rely on contract necessity, consent, legitimate interests, compliance with law, or an organization-directed service relationship.
Where applicable, you may request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or appeal/review of a privacy decision. Some requests may be limited by legal, security, recordkeeping, contract, or certificate-integrity obligations.
Sharing and Service Providers
We may share information with service providers that help operate hosting, authentication, email delivery, payment processing, analytics if later enabled, support, security, and other platform functions.
We may share information with agencies, institutions, instructors, marketplace providers, or other organizations when needed to provide services, honor user or organization choices, administer courses, manage certificates, or comply with agreements.
International, State, and Sector-Specific Privacy
Vital Deploy is designed for U.S. operations, but we aim to support GDPR-compatible notices, rights intake, and data-minimization practices when applicable.
Education, health, workforce, and public-safety records may be subject to additional contracts or laws such as FERPA, HIPAA-adjacent obligations, state privacy laws, data-processing addenda, agency agreements, or institutional policies. Those obligations may add restrictions to how data can be accessed, disclosed, retained, or deleted.
Retention and Security
We retain information for as long as needed to provide services, maintain certificates and audit evidence, comply with legal or contractual duties, resolve disputes, and protect the platform.
We use administrative, technical, and organizational safeguards appropriate to the type of information involved. No online service can guarantee absolute security.
Cookies, Analytics, and Communications
The public site may use essential cookies or similar technologies for security, session handling, preferences, and core site operation. Analytics are not currently enabled on this public site.
If analytics or marketing tools are added later, this policy should be updated before launch to describe those tools and any choices available to users.
Contact
Privacy questions or requests can be submitted through the Vital Deploy contact page. Before public launch, this policy should be reviewed by legal counsel and aligned with customer agreements, vendor contracts, and production privacy operations.