Legal

Privacy Notice

Last updated: 3 October 2026

This notice explains what personal data Nurse Navigator Academy collects about you, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. We collect the minimum needed to run the academy and nothing beyond it.

1. Who is responsible for your data

Mazen Ahmed Attia Taha Al-Wahhab, trading as “Nurse Navigator Academy” (healthcareacademyhub.com), is the data controller for the personal data described in this notice. That means we decide why and how your data is processed. You can reach us at HealthcareAcademyHub@outlook.com, or through the “Inquiries & suggestions” button inside the academy.

Paddle.com acts as an independent controller and as Merchant of Record for orders. The notice below covers what we collect; Paddle's own privacy notice covers what it collects when you pay.

2. The data we collect and why

Account data

Your name and email address, your password (stored only as a cryptographic hash) or the identifier from the Google account you signed in with. Used to create and secure your account, and to contact you about it.

Membership data

Your subscription plan and its active period. Used to decide which lessons and PDFs you can open, and to keep your access current.

Learning records

Which lessons and scenes you opened, your pre-test and post-test answers, scores and score comparison. Used to show you your progress, to let you compare before and after, and to report to your educator where they run the dashboard.

Downloads

A record of which PDFs you downloaded. Used only to keep the download area working and to answer support questions.

Messages you send us

The type, subject and text of any inquiry, suggestion or material request, plus your email address. Used to read and answer your message and to decide what to produce next.

Technical and usage data

IP address, device and browser type, operating system, pages and scenes visited, and error logs. Used to keep the Service working, to diagnose faults and abuse, and to improve the lessons.

We do not ask for, and you should not send us, patient-identifiable information, health data about yourself or others, or any confidential clinical record.

3. Payment data

Card details, billing address, tax identifiers and invoices are collected and processed by Paddle as Merchant of Record. We receive only the fact that you hold an active membership and the plan you are on, so we never see or store your full card number.

4. Legal basis for processing

Contract

Account data, membership data, learning records and downloads are processed because they are necessary to give you the academy you signed up for.

Legitimate interests

Technical and usage data, error logs and abuse monitoring are processed to keep the Service secure, reliable and useful, in ways you would reasonably expect.

Consent

Non-essential cookies and any optional product-improvement analytics run only where you have chosen to allow them, and you can withdraw that choice at any time.

Legal obligation

Order and membership records are kept where tax, accounting or consumer-protection law requires it.

5. Who we share your data with

  • our hosting, storage, content-delivery and support-tooling providers, who process data on our instructions under confidentiality and security commitments;
  • our Merchant of Record, Paddle, for the sale of the product, subscription management, payments, tax compliance and invoicing;
  • our professional advisers, including our accountant and legal counsel, under duties of confidentiality;
  • competent authorities, courts or regulators, where we are required by law or to defend or protect our rights.

We do not sell your personal data, and we do not share it with advertisers.

6. Transfers outside your country

Our hosting and storage providers operate from more than one country, so your data may be processed outside the country where you live. Where that involves a transfer of UK or EEA personal data, we rely on recognised safeguards, such as adequacy decisions or the Standard Contractual Clauses with the transfer partner, so that the same protection travels with the data.

7. How long we keep your data

Account and membership

For as long as your account is open, plus up to 7 years after it closes where tax or consumer records must be kept.

Learning records

While your account is open. If you close it, progress and test records are deleted or anonymised within 30 days unless we must keep them for a legal reason.

Messages and requests

Up to 24 months after we last replied to you, then deleted unless you ask us to remove them sooner.

Technical logs

Up to 12 months, after which they are deleted or aggregated so they no longer identify you.

When data is no longer needed for the purposes above, we delete it or anonymise it so it cannot identify you.

8. Security

We use appropriate technical and organisational measures to protect your data: encryption in transit, hashed rather than plain-text passwords, access limited to people who need it, membership checks enforced on the server before lesson media or PDFs are released, and private storage for course video and audio so no public link can be shared. No system is perfectly secure, and we will tell you promptly if we become aware of a breach that affects you and is notifiable.

9. Cookies and similar technology

Essential

Keep you signed in, remember your choices, and protect the site against abuse. Always on; no consent needed.

Analytics

Show which lessons are used and where learners get stuck, so we can improve them. Only with your consent.

Marketing

Not used. We do not run advertising or marketing cookies on this site.

You can manage preferences through the consent control on the site and through your browser settings, and you can block or clear cookies at any time. Blocking essential cookies will stop the academy from working.

10. Your rights

You may ask us at any time to:

  • confirm whether we hold your data and give you a copy of it (access);
  • correct anything inaccurate, or complete anything incomplete (rectification);
  • delete your data where there is no overriding reason to keep it (erasure);
  • pause our processing of your data in defined circumstances (restriction);
  • give you your data in a portable format, or send it to another provider (portability);
  • stop processing your data where we rely on legitimate interests (objection);
  • withdraw a consent you gave, at any time, without affecting processing already carried out.

We answer requests within one month, free of charge. If we need longer, or if we refuse a request, we will tell you why. If you are in the UK or the EEA and are unhappy with our answer, you may complain to your supervisory authority — the Information Commissioner's Office in the UK, or your local data protection authority in the EEA. Elsewhere, you may complain to the consumer or data protection authority that applies to you.

11. Children

The academy is for adult healthcare professionals and students. It is not directed at children, and we do not knowingly collect data from anyone under 18. Tell us if you believe a child has given us data and we will delete it.

12. Changes to this notice

If we change this notice in a way that matters to you, we will update the date at the top of the page and, for significant changes, tell you by email or in the academy.

13. Contact

Questions, requests or complaints about your data can go to HealthcareAcademyHub@outlook.com, or through the “Inquiries & suggestions” button inside the academy. We will acknowledge your message within two business days.