CDM Prep logo

Privacy Policy

How we handle your data and protect your privacy

Privacy Policy

Privacy Policy

Last Updated: October 5, 2025

1) Who we are & scope

PrepForge LLC (“we,” “us,” “our”) operates Clinical Data Management Prep (web and mobile, the “Service”). We are the controller for personal data collected via the Service. Contact: support@clinicaldatamanagementprep.com, 1601 Carrington Park Cir, Apt 304, Morrisville, NC 27560, USA. (If applicable) Data Protection Officer / EU or UK Representative: Not currently appointed. If required by law in the future, we will update this notice and provide representative details.

2) What we collect

We collect information you provide and information generated by your use of the Service:

  • Account: email, name, password hash.
  • Purchases: transaction IDs, plan, last‑4 and card brand (processed by our payment processor; we do not store full card numbers).
  • Learning & quiz telemetry: items attempted, answers, flags, scores, timing, progress, audio play events.
  • Device/usage: IP address, approximate location, device and browser, event logs, diagnostics, crash data.
  • Support: messages/attachments and related metadata.
  • Cookies/SDKs: session, security, and (if enabled) analytics cookies.

We provide a California Notice at Collection (Appendix A) listing categories, purposes, retention, and whether data is sold/shared. CPRA requires this at or before collection.

Purposes: operate core features (auth, quizzes, saving progress), payments & fraud prevention, performance & diagnostics, content improvement/analytics, customer support, and legal compliance. Legal bases (EU/UK): contract, legitimate interests (e.g., security/analytics proportionate to impact), consent (non‑essential cookies/marketing), and legal obligation. You can object to processing based on legitimate interests or withdraw consent at any time.

4) Cookies & similar tech

We use essential cookies for login, security, and load balancing. If we use analytics/marketing cookies, we request consent where required. In the UK/EU we do not set non‑essential cookies before consent. Controls are available via Cookie Settings and your browser.

5) Sharing & disclosure

We don’t sell personal data. We disclose limited data to service providers under contracts requiring them to act only on our instructions—for example:

  • Payments (e.g., Stripe)
  • Hosting/CDN/object storage
  • Email/support tooling
  • Analytics/telemetry (if enabled)

Stripe may act as a processor or controller depending on activity; see Stripe’s privacy/DPA resources.

“Sale” / “Sharing” for advertising (California)

We do not sell or share personal information for cross‑context behavioral advertising. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link and honor Global Privacy Control (GPC) signals as a valid opt‑out.

6) International data transfers

When we transfer personal data internationally, we use lawful transfer tools—for example, the EU Standard Contractual Clauses (SCCs)—and additional safeguards as appropriate.

7) Retention

We keep personal data only as long as needed for the purposes above and applicable law, then delete or de‑identify it. Where exact periods aren’t possible, we apply documented criteria (e.g., account status, legal/tax requirements, security). See Appendix A for typical periods.

8) Security

We apply layered safeguards including encryption in transit/at rest, row‑level security, least‑privilege access, short‑lived tokens, and expiring/signed media links. No method is 100% secure, but we continuously improve controls.

9) Your privacy rights & choices

Depending on your location, you may have rights to access, correct, delete, port, object/restrict, and withdraw consent.

  • How to exercise: email support@clinicaldatamanagementprep.com with subject “Privacy Request.”
  • Verification & timing (California): we acknowledge within ~10 business days and respond within 45 days (extendable once by 45 days with notice).
  • Appeals (certain U.S. states): If we deny your request, you may appeal; our reply will explain how (Virginia/Colorado and similar state laws require an appeal mechanism and timelines).

EU/UK notes

We provide the Article 13/14 disclosures at or before collection (or within one month for indirect collection) and respect your rights under Articles 15–22 (including the right to object and data portability).

Automated decision‑making

We do not make decisions solely by automated means that produce legal or similarly significant effects about you (GDPR Article 22). If we ever do, we’ll provide required information and safeguards.

10) Children’s privacy

The Service is not directed to children under 13, and we don’t knowingly collect their personal information. If we learn a user is <13, we will delete the data or obtain verifiable parental consent as required by COPPA.

11) Region‑specific information

  • EU/UK: You can contact your supervisory authority (e.g., ICO/Data Protection Commission) if you believe your rights were infringed. We provide required transparency at collection (Articles 13/14).
  • California: See Appendix A for categories/purposes/retention and sale/share status; we honor GPC signals as an opt‑out where applicable.

12) Changes to this policy

We’ll post updates with a new “Last Updated” date and, where appropriate, notify you by email or in‑app.

13) Contact

support@clinicaldatamanagementprep.com · 1601 Carrington Park Cir, Apt 304, Morrisville, NC 27560, USA


Appendix A — California Notice at Collection (CPRA/CCPA)

This table summarizes what we collect, why, retention, and whether we sell/share PI (for cross‑context ads). We present this at or before collection (link OK for online). We also disclose retention periods or criteria.

Category (examples)Purposes (why)Typical retention (example/criteria)Sold?Shared for ads?
Identifiers (name, email, IP, cookie ID)Account, login, security, communications, fraud prevention, analyticsLife of account + up to 24 months after closure (for fraud/security/audit), or documented criteriaNoNo
Commercial info (purchases, plan)Billing, receipts, fraud detection, customer support7 years (finance/tax recordkeeping)NoNo
Internet/activity (pages, events, device/browser)Session management, performance, security, analytics180 days rolling logs (or shorter if operationally feasible)NoNo
Learning/usage (quiz telemetry, audio play)Provide features, track progress, content qualityUp to 36 months (or aligned to active learning history), or documented criteriaNoNo
Approx. geolocation (from IP)Fraud/security, localization90–180 daysNoNo
Inferences (e.g., mastery level)Personalization (difficulty, recommendations)Up to 36 months or until account deletionNoNo
Sensitive PI (not sought; if incidentally provided)N/A (use only to deliver the Service; minimize and segregate)Minimal; delete or segregate as soon as identifiedNoNo

Status today: We do not sell or share personal information for cross‑context behavioral advertising. If this ever changes, we will add a “Do Not Sell or Share My Personal Information” link and honor GPC signals.