Privacy Policy
Last updated: May 14, 2026
1. Who we are
SafetyPathway (the "Service", "we", "us") is a patient-safety training-needs platform operated by Jacqueline Wastephen. You can reach us at afrigraciousdove@gmail.com or +1 (854) 844-5166. This policy explains what data we collect, why, how we store it, and the choices you have.
2. Important scope notice — we are not a HIPAA Covered Entity
SafetyPathway is a training-needs and continuing-professional-development tool. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we do not act as a Business Associate of any covered entity unless a separate, signed Business Associate Agreement (BAA) is in place. We design the platform to be HIPAA-aware: we minimise the collection of identifiers, we do not request patient identifiers, and we instruct users not to submit Protected Health Information (PHI) into free-text fields.
Do not enter patient names, medical record numbers, dates of service, photographs, or any other PHI into assessments, feedback forms, or the AI Coach. If you need a HIPAA-compliant deployment for your organisation, contact us to discuss a BAA and a private instance.
3. Data we collect
a. Nurse training needs assessment
- Professional details you choose to provide: role, years of experience, specialty, facility type, country/region.
- Self-rated competence and training priorities (refresher, retraining, full training).
- Optional contact email — only if you tick "I want follow-up".
- Free-text comments you write into the form.
b. Visitor & caregiver feedback
- Anonymous by default. Optional name and email only if you choose to be contacted.
- Your written feedback, ratings, and the facility/department you reference.
c. CPD referrals & affiliate clicks
- Which CPD course you clicked, the timestamp, the page you came from, and a coarse device/browser label.
- We do not sell or share your identity with CPD providers. Affiliate networks may set their own cookies after you leave our site — that is governed by their policies, not ours.
d. AI Training Coach
- The questions you type are sent to the Lovable AI Gateway (Google Gemini family models) to generate responses.
- We do not retain a transcript on our servers in v1. Your conversation lives only in your browser session.
- Do not paste PHI, identifiable case details, or confidential employer information into the Coach.
e. Technical data
- Standard server logs (IP address, user-agent, timestamp) retained for security and abuse prevention.
- Strictly necessary cookies for session and form state. No third-party advertising trackers.
4. Legal bases & purpose
We process the data above to:
- Run the assessment, generate personalised CPD recommendations, and operate the platform (legitimate interest / contract).
- Aggregate de-identified statistics for research, quality improvement, and publication (legitimate interest / public interest in nurse training research).
- Contact you back when you explicitly request follow-up (consent).
- Detect abuse, debug errors, and meet legal obligations (legitimate interest / legal obligation).
5. Aggregate research & publication
De-identified, aggregated assessment data may be used in academic publications, conference presentations, and policy submissions (including immigration petitions in the National Interest such as NIW). "De-identified" means no direct identifiers and no combination of indirect identifiers that could reasonably re-identify a respondent. If you do not want your responses included in aggregate research, email us and we will remove your record before the next analysis cycle.
6. How we store & protect data
- Hosted on Lovable Cloud (managed Postgres) with encryption in transit (TLS 1.2+) and at rest.
- Row-Level Security policies restrict reads to authorised admin accounts; the public can only insert their own submissions.
- Service-role keys are kept server-side only and never shipped to the browser.
- Access is limited to the project owner and named admins on a least-privilege basis.
7. Data sharing
We do not sell personal data. We share limited data only with:
- Sub-processors: Lovable Cloud (hosting/database), the Lovable AI Gateway (model inference for the Coach and recommender).
- CPD partners: we send you to their site via tracked affiliate links. Their cookies and policies apply once you arrive.
- Authorities: when required by valid legal process.
8. Retention
- Assessment and feedback records: kept for up to 5 years to support longitudinal research, then de-identified or deleted.
- Referral click logs: 24 months.
- Server logs: 90 days.
- You can request deletion at any time (see Your Rights).
9. Your rights
Depending on your jurisdiction (GDPR/UK GDPR, India DPDP Act 2023, US state laws), you may have the right to access, correct, delete, port, or object to processing of your personal data, and to withdraw consent. Email afrigraciousdove@gmail.com with your request and we will respond within 30 days. Anonymous submissions cannot be matched to you, so we cannot retrieve or delete records we cannot tie to your identity.
10. International transfers
Our infrastructure runs on global cloud providers and your data may be processed outside your country of residence. We rely on standard contractual safeguards offered by our providers.
11. Children
The Service is intended for healthcare professionals and adult caregivers. We do not knowingly collect data from children under 16.
12. Security incidents
If we become aware of a breach affecting your personal data we will notify affected users and relevant regulators in line with applicable law.
13. Affiliate links & sponsored recommendations
SafetyPathway is reader-supported. To help cover the cost of running the platform and producing free patient-safety content, some links on this site are affiliate links. If you click one and make a purchase, we may earn a small commission at no additional cost to you.
Programs we participate in
- Amazon Associates Program — As an Amazon Associate, we earn from qualifying purchases. Our Amazon affiliate tag is
safepath-20. - Etsy affiliate program — operated through Rakuten Advertising / Awin. We earn a commission on qualifying purchases made through Etsy product links on this site.
- CPD & training partners — some continuing-professional-development courses we link to operate referral or affiliate arrangements with us.
Editorial independence
We only feature products, books, equipment, and CPD programs that we believe genuinely benefit nurse training, clinical competence, and patient safety. Editorial selection is made independently of any commercial relationship. Affiliate commissions never determine clinical recommendations, assessment results, or research findings published on this site. Any content that is a paid placement will be clearly labeled "Sponsored".
Your choice
You are never required to use our affiliate links. You can navigate directly to Amazon, Etsy, or any CPD provider's website and obtain identical pricing. Using our links simply helps fund the platform.
Tracking on partner sites
Once you click an affiliate link and leave SafetyPathway, the destination site (Amazon, Etsy, Rakuten, Awin, or a CPD provider) may set its own cookies and collect data according to their privacy policies. We do not control and are not responsible for the data practices of third-party merchants or affiliate networks.
No medical or legal advice
Recommended products and courses are educational tools, not medical devices or clinical protocols. Nothing on this site constitutes medical, legal, or professional advice. Always follow your employer's policies, regulator's standards, and your own clinical judgment.
14. Changes
We will update the "Last updated" date when this policy changes. Material changes will be highlighted on the home page for at least 14 days.
15. Contact
Privacy questions, deletion requests, or BAA enquiries:
Jacqueline Wastephen — SafetyPathway
Email: afrigraciousdove@gmail.com
Mobile: +1 (854) 844-5166