3AM Technologies, SimServeRx: Privacy Policy
Effective Date: November 17th, 2025
Company: 3AM Technologies
Application: SimServeRx
Contact: privacy@3AMTechnologies.com
3AM Technologies
5551 Highway 41A
Joelton TN, 37080 USA
1) Scope & Purpose
This Privacy Policy explains how 3AM Technologies (“we,” “us,” or “our”) collects, uses, secures, and retains information in connection with our training platforms and services for educational facilities that simulate automated medication dispensing workflows.
Our training environments use generic, de-identified, or fictitious data. We do not collect or process real patient information (PHI) or student education records (FERPA-protected information) as part of standard operations. Any datasets used are fabricated or anonymized for simulation and instructional purposes only.
2) Summary of What We (Do Not) Collect
We design our services to minimize data collection and avoid sensitive data.
We typically collect:
- Service & device telemetry: IP address, device/browser type, session timestamps, app version, performance metrics, error logs.
- Training usage data: User role (e.g., “Instructor,” “Learner”), completion status, in-simulation actions, assessments related to training progress (non-educational record as configured—see Section 7).
- Account/workspace metadata: Organization name, authorized users’ business contact details (e.g., name, work email, role), permissions, and audit trails required for security and instructional integrity.
- Support communications: Messages you send to our support channels, including attachments you voluntarily provide.
We do not intentionally collect:
- Protected Health Information (PHI) or real patient data.
- Student education records (FERPA-covered records) in our default configuration.
- Sensitive personal data (e.g., SSNs, government IDs, precise health data).
If a customer uploads information contrary to our guidelines, we will take commercially reasonable steps to delete or anonymize it upon discovery (see Section 10).
3) Sources of Information
- You/your institution: When administrators provision users or configure training content.
- Automated collection: From your use of our applications (logs, if applicable).
- Service providers: Hosting, analytics, or support tools acting on our behalf.
4) How We Use Information
- To provide the services: Authenticate users, deliver training modules, track completion, maintain audit logs, and preserve content integrity.
- To secure and maintain the platform: Monitor, detect, and prevent fraud, misuse, and security incidents; debug and improve performance.
- To improve the product: Analyze aggregated usage trends to enhance features, content, and user experience.
- To support you: Respond to inquiries, provide technical assistance, and communicate essential service updates.
- To comply with law and contracts: Fulfill legal obligations and institutional agreements.
We do not sell personal information.
5) Legal Basis (where applicable, e.g., EU/UK/EEA)
If data protection laws such as GDPR/UK GDPR apply, our processing is based on:
- Performance of a contract (Art. 6(1)(b))—to provide the services.
- Legitimate interests (Art. 6(1)(f))—product security, service improvement, and fraud prevention (balanced against your rights).
- Legal obligations (Art. 6(1)(c))—where required by law.
6) Cookies & Similar Technologies
SimServeRx does not utilize cookies.
7) Education & Training Records (FERPA Considerations)
Our services are designed to use generic training data and role-based accounts, avoiding FERPA-covered student education records by default. If an institution configures the system to associate training outcomes with identified students, we can support institution-directed controls and will process such data solely as a “school official” under FERPA (or equivalent role) pursuant to a written agreement. Institutions remain the data controllers/record custodians, and we act as a service provider/processor. Please contact your administrator for institutional FERPA options.
8) PHI & Healthcare Privacy (HIPAA Considerations)
We do not require or intend to receive PHI. Our training datasets are synthetic/fictitious by design. SimServeRx is not configured to store PHI in any way shape or form, use of PHI by client is in violation of the SimServeRx EULA and will void any warranty of use.
9) Data Sharing & Disclosures
We may share limited information with:
- Service providers (processors): Cloud hosting, security monitoring, logging, analytics, and support tools, underwritten contracts that restrict use to providing services to us.
- Institutional administrators: For account management, audit reporting, and training oversight.
- Business transfers: In a merger, acquisition, or asset sale, consistent with this Policy.
- Legal compliance: To comply with valid legal process or protect rights, safety, and security.
We do not sell or rent personal information.
10) Data Minimization & Retention
- We collect only what is necessary to deliver the training and maintain platform security.
- Default retention: 90 Days of logs and training usage data, unless a shorter/longer period is contractually agreed or legally required. Data held within the local database is kept indefinitely.
- Customer-managed deletion: Upon verified request from an institutional admin, we will delete or anonymize platform data associated with that institution, subject to legal holds or security requirements.
- Erroneous uploads: If real PHI or student records are inadvertently uploaded, we will work with the institution to promptly delete or anonymize the data and investigate root cause.
11) Security
We implement administrative, technical, and physical safeguards designed to protect information, including:
- Role-based access control and least-privilege principles
- Encryption in transit (TLS) and at rest for specified information, (e.g. passwords)
- Network segmentation, logging, and intrusion detection as required and administered by the local facility IT department.
- Vulnerability management and secure development practices
- Employee confidentiality obligations and security training
No system is 100% secure. If we discover a security incident affecting your data, we will notify affected customers in accordance with applicable laws and our agreements.
12) International Data Transfers
If data is transferred across borders, we use lawful transfer mechanisms (e.g., Standard Contractual Clauses for EEA/UK; other equivalent measures as applicable). We also apply supplemental safeguards where required.
13) Your Rights & Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of certain information. Because we operate primarily with generic training data and business contact data, requests often relate to user account profile information and logs. Please contact your institutional admin or email privacy@3AMTechnologies.com. We may need to verify your identity and work with your institution to fulfill requests.
For EEA/UK residents, you may also have the right to object to processing based on legitimate interests and to lodge a complaint with your supervisory authority.
14) Children’s Privacy
Our services are intended for professional/technical education delivered by institutions. We do not knowingly collect information from children under the age defined by applicable law. Institutions are responsible for ensuring appropriate age eligibility for their learners.
15) Third-Party Links
Our services may link to third-party sites. We are not responsible for their privacy practices. Please review their policies.
16) Changes to This Policy
We may update this Policy from time to time. The “Effective Date” at the top indicates the latest version. Material changes will be communicated through the service or via email to administrators.
17) How to Contact Us
Email: privacy@3AMTechnologies.com
3AM Technologies
Attn: Privacy
Address:
3AM Technologies
5551 Highway 41A
Joelton TN, 37080 USA