Privacy Policy

Ready AI, Inc. and Affiliates

Effective Date: September 7, 2026

1. Scope

This Privacy Policy applies to personal information processed through our Services and websites, including information relating to:

  • Learners, students, trainees, and professionals

  • Employees and workforce participants

  • Faculty members, instructors, evaluators, managers, and administrators

  • Customers and prospective customers

  • Website visitors

  • Event participants

  • Support contacts

  • Other authorized users

Many users access the Services through an educational institution, employer, healthcare organization, government agency, or other enterprise customer ("Institution").

In those situations, the Institution may control how certain personal information is collected and used.

2. Our Role and the Institution's Role

Depending on the circumstances, ReadyAI may act as a controller, processor, service provider, contractor, school official, business associate, or similar service provider under applicable privacy law.

When ReadyAI acts on behalf of an Institution

For information processed through an Institution-managed account, the Institution generally determines why the information is processed and how the Services are used.

ReadyAI processes such information on the Institution's behalf and according to the applicable agreement, documented instructions, and law.

For example, an Institution may determine:

  • Who receives access to the Services

  • Which simulations or assessments are assigned

  • How assessment results are interpreted

  • Whether results are incorporated into education, training, remediation, workforce development, competency, or other processes

  • Who within the Institution may view user information

Requests concerning decisions made by an Institution should generally be directed to that Institution.

When ReadyAI acts independently

ReadyAI may act as a controller or business for certain activities, such as:

  • Operating our public websites

  • Managing customer and business relationships

  • Processing billing and account administration information

  • Securing and protecting our Services

  • Responding to support inquiries

  • Conducting permitted business analytics

  • Managing marketing communications

  • Meeting our legal obligations

3. Information We Collect

The information we collect depends on the Services you use and how they are configured.

3.1 Account and Contact Information

We may collect:

  • Name

  • Email address

  • Telephone number

  • Organization or Institution

  • Job title, professional role, department, or academic role

  • User ID or username

  • Authentication and account information

  • Professional credentials or educational information where relevant

  • Account permissions and roles

3.2 Simulation, Training, Assessment, and Performance Data

When you participate in a ReadyAI experience, we may process:

  • Simulation progress

  • Completion status

  • Responses and interactions

  • Conversation content

  • Decisions and decision sequences

  • Task performance

  • Timing and response information

  • Assessment results

  • Scores and performance metrics

  • Skill or competency indicators

  • Reasoning or rationale provided by users

  • Engagement information

  • Adaptive learning information

  • AI-generated feedback and insights

  • Remediation or improvement recommendations

This information may be used to provide feedback to users and authorized Institutions and to support training, education, assessment, program evaluation, workforce development, and other authorized purposes.

3.3 Audio, Voice, Visual, and Sensor Information

Certain Services may process information such as:

  • Voice or audio

  • Speech converted to text

  • Text transcripts

  • Images or video where enabled

  • Movement or controller activity

  • Eye gaze

  • Gestures

  • Facial or expressive signals

  • Device orientation

  • Interaction patterns

  • Other sensor-generated information

The particular information collected depends on the product, hardware, configuration, and Institution.

Some of this information may be considered sensitive information or biometric information under certain laws depending on how it is processed.

Unless specifically disclosed for an applicable feature, ReadyAI does not use these signals for the purpose of establishing an individual's identity or authenticating an individual based on a biometric identifier.

Where applicable law requires consent or another specific legal basis for processing sensitive or biometric information, ReadyAI and the applicable Institution will implement the required safeguards.

3.4 Customer Content

Institutions and users may submit information through authoring tools, prompts, uploaded documents, scenarios, curricula, training materials, communications, or other features.

Customer Content may contain personal information depending on what the Institution or user submits.

Users should not submit protected health information, identifiable patient information, biometric identifiers, or other specially regulated information unless the applicable Institution and ReadyAI have expressly authorized that processing.

3.5 Device, Technical, and Usage Information

We may automatically collect:

  • IP address

  • Approximate geographic location derived from IP address

  • Browser type

  • Operating system

  • Device type

  • Device identifiers

  • Application version

  • Login and authentication events

  • Access times

  • Session duration

  • Pages, screens, or features used

  • Navigation and interaction events

  • Performance information

  • Error logs

  • Diagnostic information

  • Security telemetry

  • Cookie and similar technology information

3.6 Communications and Support

If you contact us, we may collect information contained in:

  • Emails

  • Support requests

  • Customer-service communications

  • Feedback

  • Surveys

  • Meeting requests

  • Demo requests

  • Other communications with ReadyAI

3.7 Business and Marketing Information

For customers, prospective customers, partners, and website visitors, we may collect:

  • Business contact information

  • Organization information

  • Areas of interest

  • Marketing preferences

  • Event participation

  • Website engagement

  • Sales and customer relationship information

4. Sources of Information

We may receive personal information:

  • Directly from you

  • From your Institution

  • From administrators or authorized users

  • Through your interaction with the Services

  • From integrated systems authorized by your Institution

  • From identity providers or learning management systems

  • From business partners

  • From publicly available business sources

  • From service providers acting on our behalf

5. How We Use Personal Information

We may use personal information to:

  • Provide and operate the Services

  • Authenticate users and manage accounts

  • Deliver simulations, training, and assessments

  • Generate feedback, scores, analytics, and adaptive experiences

  • Support authoring and content-management functionality

  • Provide reports to authorized Institutions

  • Personalize authorized training experiences

  • Provide customer support

  • Monitor performance and reliability

  • Detect, prevent, and investigate security incidents, misuse, and fraud

  • Maintain and improve the Services

  • Develop new products and functionality

  • Conduct permitted analytics and research

  • Communicate with customers and users

  • Manage business relationships

  • Process transactions and administer contracts

  • Meet legal, regulatory, compliance, and audit obligations

  • Enforce our agreements and protect our rights

  • Establish, exercise, or defend legal claims

We may also use information for other purposes disclosed at the time of collection or permitted by applicable law.

6. Artificial Intelligence and Product Improvement

ReadyAI uses artificial intelligence and automated technologies to provide features such as conversational simulations, adaptive experiences, scoring, feedback, summarization, analysis, and assessment.

We may process information submitted during a session to generate these features.

We may use Service data as permitted by applicable Customer Agreements and law to operate, secure, troubleshoot, evaluate, and improve our Services.

We may use aggregated or de-identified information to evaluate and improve products, analytics, assessment methods, artificial intelligence systems, and models.

We do not use identifiable Customer Content, education records, or identifiable learner or workforce performance information to train generalized artificial intelligence models for unrelated customers unless the applicable Institution has expressly authorized that use or the information has first been de-identified in accordance with applicable law.

Where third-party artificial intelligence or technology providers process Customer Content on our behalf, we use contractual and organizational protections appropriate to the applicable service and information.

7. Automated Processing and Decisions

The Services may generate automated scores, assessments, recommendations, classifications, feedback, or other Outputs.

In many cases these Outputs are provided to an Institution or user as decision-support information rather than as a final decision.

Unless expressly authorized under an applicable Customer Agreement, ReadyAI Services are not intended to independently make fully automated decisions producing legal or similarly significant effects on an individual.

Institutions are responsible for determining how they use Outputs in employment, education, credentialing, professional, or other decision-making processes and for providing human review, notice, appeal rights, explanations, or other safeguards required by applicable law.

Where ReadyAI itself engages in automated decision-making subject to specific legal requirements, we will provide any additional notices and rights required by applicable law.

8. Legal Bases for Processing in the United Kingdom and European Economic Area

Where the UK GDPR, EU GDPR, or similar laws apply and ReadyAI acts as a controller, our legal bases may include:

Contract

We may process information when necessary to provide Services requested by you or perform a contract.

Legitimate Interests

We may process information for legitimate interests such as:

  • Operating and improving our Services

  • Securing our systems

  • Supporting customers

  • Managing business relationships

  • Preventing fraud and misuse

  • Conducting reasonable business analytics

We rely on legitimate interests only where those interests are not overridden by applicable individual rights.

Legal Obligation

We may process information when necessary to comply with applicable laws, regulations, court orders, or other legal obligations.

Consent

Where required, we may rely on consent, including for certain communications, cookies, sensitive information, or specific optional features.

Consent may be withdrawn where applicable.

Where ReadyAI acts as a processor on behalf of an Institution, the Institution is generally responsible for establishing the applicable legal basis for processing.

9. How We Disclose Personal Information

We may disclose personal information to:

Institutions

We may provide information to the Institution sponsoring, administering, or managing your access to the Services.

This may include assessment, training, performance, completion, analytics, and related information.

Service Providers and Subprocessors

We may use third parties to provide:

  • Cloud hosting

  • Data storage

  • Artificial intelligence infrastructure

  • Communications services

  • Authentication

  • Security

  • Analytics

  • Customer support

  • Payment processing

  • Software development and operations

  • Other services supporting ReadyAI

These providers are authorized to process personal information for defined purposes and subject to contractual obligations as appropriate.

Affiliates

Ready AI, Inc., Patient Ready, Inc., Patient Ready, Ltd., and other controlled affiliates may share information when reasonably necessary to operate and support the Services.

Legal and Safety Purposes

We may disclose information where reasonably necessary to:

  • Comply with applicable law or legal process

  • Respond to lawful governmental requests

  • Protect users, customers, ReadyAI, or others

  • Investigate fraud or security incidents

  • Enforce our agreements

  • Establish or defend legal claims

Business Transactions

Information may be disclosed in connection with a merger, acquisition, financing, reorganization, sale of assets, corporate transaction, or similar event, subject to applicable legal safeguards.

10. Sale, Sharing, and Targeted Advertising

ReadyAI does not sell personal information in exchange for money.

We do not use learner, assessment, education-record, or Institution-managed account information for third-party targeted advertising.

Our public websites may use analytics, marketing, or advertising technologies to understand website activity and support business communications.

Certain U.S. state privacy laws may define some uses of advertising or analytics technologies as "sale," "sharing," or targeted advertising even where no money changes hands.

Where applicable law provides an opt-out right for such activity, we will provide the legally required mechanism and honor qualifying preference signals where required.

11. Cookies and Similar Technologies

Our websites and Services may use cookies, pixels, local storage, software development kits, and similar technologies.

These technologies may be used for:

  • Authentication

  • Security

  • Essential website functionality

  • User preferences

  • Performance

  • Analytics

  • Service improvement

  • Marketing where permitted

Where applicable law requires consent for particular technologies, we will request consent before using them.

You may also be able to manage cookies through your browser or a cookie preference tool made available on our websites.

12. De-Identified and Aggregated Information

We may create aggregated or de-identified information that cannot reasonably be associated with an identifiable individual.

We may use such information for lawful purposes, including:

  • Product improvement

  • Analytics

  • Benchmarking

  • Research

  • Model evaluation and improvement

  • Security

  • Service development

  • Business planning

Where applicable law imposes requirements on de-identified information, we will maintain and use the information in de-identified form and will not attempt to re-identify it except as legally permitted for purposes such as testing de-identification safeguards.

13. FERPA and Education Records

Where the Services are used by an educational Institution subject to the Family Educational Rights and Privacy Act ("FERPA"), ReadyAI may receive information from education records.

Where the requirements of FERPA's school-official exception are satisfied, ReadyAI may act as a contractor or outsourced school official performing services for which the Institution would otherwise use its own employees.

In those circumstances, ReadyAI processes education-record information:

  • For authorized educational or institutional purposes

  • Subject to the Institution's direct control as required by FERPA

  • Subject to applicable restrictions on use and redisclosure

  • Consistent with the applicable Customer Agreement

The Institution remains responsible for determining whether ReadyAI qualifies for a particular FERPA exception and for administering student rights under FERPA.

Students and parents seeking access, correction, or other rights concerning education records should ordinarily contact the applicable Institution.

14. Healthcare Information and HIPAA

ReadyAI and Patient Ready are not healthcare providers merely because they provide healthcare education or training technology.

The standard Services are not intended for the submission of identifiable patient medical records or PHI governed by HIPAA unless expressly authorized.

Where ReadyAI processes PHI on behalf of a HIPAA-covered entity or business associate and ReadyAI qualifies as a business associate, the parties will enter into a Business Associate Agreement as required by law.

When a Business Associate Agreement applies, that agreement governs ReadyAI's permitted use and disclosure of PHI.

Health-related content used for education and simulation may be fictional, simulated, de-identified, or otherwise provided by an authorized Institution.

15. Sensitive Personal Information

Depending on product configuration and applicable law, certain information processed through the Services may be considered sensitive personal information.

This may include information concerning:

  • Professional or educational evaluations

  • Health-related training information

  • Precise or approximate location where enabled

  • Voice or sensor data

  • Biometric information where applicable

  • Other legally protected categories of information

ReadyAI processes sensitive information only for purposes reasonably necessary to provide authorized Services, comply with law, protect security, or fulfill other disclosed and legally permitted purposes.

Where applicable law provides a right to limit certain uses of sensitive information, ReadyAI will honor that right where required.

16. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to:

  • Provide the Services

  • Maintain customer and user accounts

  • Support training and assessment requirements

  • Fulfill contractual commitments

  • Maintain security and system integrity

  • Resolve disputes

  • Meet legal, regulatory, audit, and accounting obligations

  • Enforce agreements

Retention periods may vary based on the type of information, applicable Customer Agreement, Institution instructions, legal requirements, and technical requirements.

When ReadyAI acts as a processor, deletion and return of Institution data are generally governed by the applicable Customer Agreement or data processing agreement.

Backup copies may remain for a limited period until overwritten or deleted through normal backup processes.

17. Security

ReadyAI maintains administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

Security measures may include access controls, authentication, encryption, monitoring, secure development practices, security testing, logging, backup procedures, and organizational policies as appropriate to the applicable Service.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

Users are responsible for protecting their account credentials and promptly reporting suspected unauthorized access.

Security concerns may be reported to security@patientready.net.

18. International Processing and Transfers

ReadyAI operates internationally.

Personal information may be processed in the United States, United Kingdom, or other countries where ReadyAI, its affiliates, customers, or service providers operate.

An applicable Customer Agreement may provide for regional hosting or other geographic processing requirements.

Where personal information is transferred internationally and applicable law requires transfer safeguards, ReadyAI uses appropriate mechanisms, which may include:

  • Adequacy decisions or regulations

  • Standard Contractual Clauses

  • The UK International Data Transfer Agreement or UK Addendum

  • Other legally recognized transfer mechanisms

We implement additional organizational, contractual, and technical safeguards where appropriate.

19. United Kingdom and European Economic Area Privacy Rights

Subject to applicable law, individuals in the United Kingdom and European Economic Area may have rights including:

  • Access to personal information

  • Correction of inaccurate information

  • Deletion of information

  • Restriction of processing

  • Data portability

  • Objection to certain processing

  • Withdrawal of consent

  • Rights relating to certain automated decisions

  • The right to lodge a complaint with a data protection authority

When ReadyAI processes information solely on behalf of an Institution, we may refer your request to the applicable Institution or assist the Institution in responding.

UK individuals may lodge a complaint with the UK Information Commissioner's Office.

EEA individuals may lodge a complaint with the applicable data protection supervisory authority in their country.

20. United States State Privacy Rights

Residents of certain U.S. states may have privacy rights under applicable state law.

Depending on the jurisdiction and circumstances, these rights may include:

  • The right to know or access personal information

  • The right to obtain a copy of personal information

  • The right to correct inaccurate information

  • The right to request deletion

  • The right to opt out of certain sales, sharing, targeted advertising, or profiling

  • The right to limit certain uses of sensitive personal information

  • The right not to receive discriminatory treatment for exercising privacy rights

  • The right to appeal certain decisions concerning privacy requests

These rights apply only to the extent provided by applicable law.

Where ReadyAI processes personal information as a service provider or processor on behalf of an Institution, privacy requests concerning that information should generally be directed to the applicable Institution.

We may need to verify your identity before fulfilling certain requests.

Where permitted by law, an authorized agent may submit a request on your behalf.

21. California Privacy Information

If the California Consumer Privacy Act, as amended ("CCPA"), applies to ReadyAI's processing of your personal information, California residents may have rights provided by that law.

The categories of personal information we may collect are described throughout this Privacy Policy and may include:

  • Identifiers

  • Customer and account information

  • Internet or electronic network activity

  • Professional or employment-related information

  • Education information

  • Audio, electronic, visual, or similar information

  • Inferences and assessment information

  • Sensitive personal information where applicable

We collect this information from the sources described in Section 4 and use it for the purposes described in Section 5.

We may disclose these categories to the recipients described in Section 9.

ReadyAI does not sell personal information for money.

ReadyAI does not use Institution-managed learner, assessment, education-record, or workforce-performance information for cross-context behavioral advertising.

If website technologies constitute "selling" or "sharing" under California law, ReadyAI will provide required opt-out mechanisms.

We do not discriminate against individuals for exercising applicable CCPA rights.

22. Children's and Minors' Privacy

Our public websites are not directed to children under 13.

ReadyAI does not knowingly collect personal information directly from children under 13 through public consumer-facing websites without legally required authorization.

The Services may be provided to minors through educational Institutions or other authorized organizations.

Where an Institution provides access to minors, the Institution is responsible for obtaining any parental consent or other authorization required under applicable law unless an applicable Customer Agreement provides otherwise.

If you believe a child has provided personal information without appropriate authorization, please contact us.

23. Marketing Communications

You may opt out of promotional email communications by using the unsubscribe mechanism in the communication or by contacting us.

We may continue to send non-promotional messages concerning your account, security, transactions, or Services where appropriate.

24. Privacy Requests

Privacy inquiries and requests may be submitted to:

legal@patientready.net

Please describe the nature of your request and the jurisdiction in which you reside.

We may request information reasonably necessary to verify your identity or authority to make the request.

Where an Institution controls the applicable information, we may direct the request to that Institution.

25. Privacy Complaints

If you have concerns about our handling of personal information, you may contact us at legal@patientready.net.

Where applicable law requires a particular privacy-complaint process, ReadyAI will process complaints in accordance with that requirement.

Nothing in this Policy limits your right to contact an applicable privacy or data protection regulator.

26. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technology, business practices, or legal obligations.

The current version will be posted on the applicable ReadyAI or Patient Ready website with the updated effective date.

Where required by applicable law, we will provide additional notice of material changes.

27. Contact Us

For questions, privacy requests, or complaints concerning this Privacy Policy, contact:

Ready AI, Inc. at legal@wearereadyai.com 

Patient Ready, Ltd. may serve as a UK affiliate in connection with Services provided to UK customers as specified in applicable Customer Agreements.