Privacy
Who controls the data
The institution is the data controller for its learners’ education records. VeloLibrary is a processor acting on the institution’s documented instructions. We do not sell learner data, and we do not use it to advertise.
What we hold
- Identity and roster data supplied by the institution — name, institutional email, role, program and cohort membership.
- Learning activity — practice responses, spaced-repetition reviews, case sessions, mastery estimates and assessment results.
- Accreditation artefacts — milestone evidence, review-committee records and, in due course, CME credit records.
- Operational records — sessions, audit events, and support correspondence.
What never reaches a model
Learner personal information is not sent to any AI model. References are replaced with a stable pseudonym before a request leaves our systems, and clinical case content passes a de-identification gate before it can be created. Our model provider operates under zero-data-retention terms: your data is not retained by them and is never used to train models — ours or theirs.
Access within an institution
Access follows a relationship, not a job title. Educators see the cohorts they teach; program directors see their own programs. Broader access to individual learner performance requires an explicit, time-boxed grant, and both the grant and the access are recorded in an audit log that cannot be edited or deleted.
Retention and deletion
- Audit records are retained for seven years to support accreditation review.
- Other records are soft-deleted for thirty days, then purged.
- On termination, the institution may export its data in a documented format before deletion.
Learner portability
A learner record is meant to outlive any single institution. Learners may export their own record in a documented format, so progress made as a student is not stranded when they become a resident or a practising physician.
Where data is processed
In our hosted service, data is processed in the region agreed with the institution. Where residency requirements do not permit that, VeloLibrary can be deployed entirely inside the institution’s own cloud tenant, in which case the institution holds the infrastructure and we hold none of the data.
Security
Encryption in transit and at rest, tenant isolation enforced both in the application and in the database, revocable sessions, and an append-only audit trail. Our security page describes the controls and their current status in more detail.
Contact
Privacy questions, data-subject requests and DPA copies: privacy@velolibrary.com.