Privacy Policy
Last updated
What this covers
EZ Recert is a web application at ezrecert.com, operated by EZ Recert LLC. New York State EMS agencies use it to track the continuing medical education their providers need to stay certified, and to prepare the paperwork that gets filed.
This policy covers three kinds of people, and they are in different positions:
- Visitors to the public site, who have no account and about whom we hold almost nothing;
- Providers — CFRs, EMTs, AEMTs and Paramedics — whose training records live here; and
- Agency staff, whose administrators review those records as part of running the agency.
It also covers people with no account at all who are asked to sign an agency's paperwork — a medical director or an instructor coordinator, typically. What we hold about them is their name, their email address, and the signature they made.
For a provider's training records, the agency directs much of what happens: it invites you, reviews your claims, decides what it requires beyond the State minimums, and switches features on or off for everyone in it. We run the platform those records sit on. Questions about how your agency uses your records go to your agency first; questions about how the platform handles them come to us.
What we collect
| What | Specifically | Where it comes from |
|---|---|---|
| Your profile | Name and middle initial, email address, phone number, date of birth, sex, mailing address including ZIP+4, your New York State provider number, your certification level, when your certification expires, when you were REMAC credentialed if you are, and your notification preferences. | You, at sign-up and on your profile page |
| The last four of your SSN | Those four digits and nothing more — never the full number. Collected because the State recertification form asks for them. Handled as set out in the next section. | You |
| Training records | Certificate files you upload or email in, which typically carry your name and licence number; the course name and completion date; how it was taken; the hours you claim in each CME category; and the topics covered. | You, or read from your documents where the reader is on |
| Review records | Whether each claim was approved or sent back, who decided, when, and any note they left for you. | Your agency's administrators |
| Signed packets | The assembled recertification or credentialing packet, the names and email addresses of everyone asked to sign it, their signatures, and the times each signature was made. | Your agency, and the signers themselves |
| Mail to your forwarding address | If certificates-by-email is on, you get a private address. For anything sent to it we hold the sender, the subject, a message identifier and the attachments. | Whoever writes to that address |
| Text messages and push | Your mobile number, the record of you opting in and of any STOP reply, and — if you enable push — the address your browser vendor issues for each device you turned it on for. | You, deliberately and separately from your profile |
| Your agency | Its name, DOH agency code, address and phone, and the names of its training officer, instructor coordinator and medical director. Where an agency is billed, the invoices, seat counts and trial dates that go with that. | Agency administrators and the platform operator |
| Activity and audit records | What happened to your account and when — sign-in and access changes, submissions and decisions — and, separately, a record of every support session in which the operator viewed the service as somebody: who, whose account, start and end. | Generated by the service |
| Operational logs | Whether each message was accepted, deferred or failed, and by which provider and for what purpose; notification records; and rate-limit counters. Rate limiting works on your IP address combined with a secret and one-way hashed — the address itself is not kept. | Generated by the service |
| The contact form | Your name, agency, work email, phone and message. It is delivered to our inbox as email and is not written to the database. If you have never had an account, this is the only thing we hold about you. | You, if you use it |
| Your browser | Six strictly necessary cookies and nothing else. No analytics, no advertising, no cross-site tracking. The full inventory is on the cookie page. | Your browser, as you use the site |
The last four of your Social Security number
The New York State recertification form asks for them, and that form is the entire reason we hold them. They get stricter handling than anything else here:
- Only four digits. The full number is never asked for, never entered, and could not be stored if it were.
- Encrypted at rest with AES-256-GCM, a fresh nonce for each record, and each record cryptographically bound to your profile so a stored value cannot be moved to another account. The key is held outside the database, so a copy of the database on its own does not reveal anything.
- Visible to nobody but you. Not your agency's administrators, not the platform operator. The database itself enforces this — there is deliberately no administrative path to read them, so it is not a rule somebody could forget to apply.
- Sealed during support access. When the operator views the service as you, those digits are excluded from what they can see.
- Used for the State form and for nothing else. They are not an identifier here, are not required to reach any part of the site, and are not printed on anything except the State paperwork you asked us to prepare. That is what New York General Business Law section 399-ddd requires, and we hold to it.
If you would rather we did not hold them at all, write to support@ezrecert.com and we will remove them. You will then have to write them on the form by hand.
What we use it for
- Running the service: counting your hours against the requirements for your level, working out your deadlines, putting your claims in front of your agency's reviewers, and keeping the record you both rely on;
- Preparing New York State paperwork, at your direction, and getting it signed;
- Telling you things: that a claim was reviewed, that a deadline is coming, that somebody needs to sign. By email, and by text or push if you asked for those;
- Account mail that is part of holding an account at all — invitations, password resets, security notices — which continues whatever your notification settings say;
- Keeping the platform sound: holding the boundaries between agencies and between accounts, rate-limiting abuse, running the bot check on public forms, and auditing support access;
- Fixing faults, from error reports stripped of identifying values first;
- Billing an agency, where it is on a paid arrangement;
- Answering you when you get in touch.
We do not sell personal information, we do not use it for advertising, and we do not use your records to train AI models. There is no analytics on this site and no ad network anywhere near it.
Reading your certificates automatically
Where the certificate reader is switched on — it needs both us and your agency to have enabled it — a certificate you upload or email in is sent to Reducto, a document-extraction service, which reads it and returns the course name, the date and a suggested split of hours. Because a certificate normally shows your name and licence number, those go with it.
Three things follow from that, and they are the point of this section:
- If the feature is off for your agency, nothing is sent anywhere. Your documents are stored for you and your reviewers and go no further.
- What comes back is a suggestion. It fills in a form you then check and correct. No claim is ever created from a machine reading alone, and values that fail validation are discarded and shown to you rather than quietly fixed.
- The decisions are made by people. Yours to submit, your agency's to approve. Nothing here decides anything about you automatically.
Who else sees it
Inside the service. Your agency's administrators see your profile, your submissions, your certificates and your progress — that visibility is what the product is for. They do not see the last four of your SSN, and they do not see certificates sitting unsubmitted in your incoming queue. The platform operator administers the service and can temporarily view it as a user for support, under the restrictions described above and with every such session recorded.
Outside it. These are the only companies that receive anything, and each receives only what its job needs:
| Who | What they do | What reaches them |
|---|---|---|
| Microsoft Azure | Hosts the virtual server the application and database run on | Everything, at rest and encrypted in transit, as the infrastructure underneath the service. We administer the server; Microsoft supplies and runs the hardware it sits on |
| Emailit | Sends our email | The recipient address and the message — which can name a course, a deadline or an agency |
| Maileroo | Receives mail sent to certificate forwarding addresses | Those messages and their attachments, in transit. This is the one place information is handled outside the United States — see below |
| Reducto | Reads uploaded certificates, where the feature is on | The certificate file, and whatever is printed on it |
| textbee | Sends text messages, where you opted in | Your mobile number and the text of the message — never your address, your licence number or your SSN digits |
| Cloudflare | The bot check on public forms, a relay in front of two vendor webhooks, and the offsite copy of the backups | For the bot check, only what its widget collects in your browser. For the backups, an encrypted-in-transit copy of stored files |
| Sentry | Error monitoring | Fault reports, stripped before they leave our server: request bodies, cookies and headers dropped whole; you reduced to an internal identifier; anything shaped like an SSN, an email address, an address or a licence number redacted by pattern rather than by field name. Session replay is switched off |
| Your browser vendor | Delivers push notifications, if you turned them on | The notification itself, on its way to your device. Turning push off stops it |
The signing service is not on that list, and that is deliberate. A signed packet carries more about a person than anything else in the product. We run the e-signature service ourselves, on our own infrastructure, rather than handing packets to an outside signing company — so no third party receives one.
Beyond those, information leaves only in these situations:
- New York State and regional authorities. Recertification and credentialing paperwork is prepared for your agency to file. We do not file it or send it to anybody on our own initiative.
- Legal process. If we are required to by law, subpoena or court order — and where we are lawfully able to, we will tell the affected agency first.
- Safety and abuse. To investigate fraud or misuse of the service, or to protect somebody.
- A change of ownership. If the business is merged, acquired or its assets sold, records move with the service and stay subject to the commitments in this policy.
Where information is handled outside the United States
One part of the service handles your documents outside the United States, and it is worth naming precisely rather than leaving in a general clause.
If certificates by email is switched on for your agency and you forward something to your private address, that message is received by Maileroo, and its attachments are served to us from a bucket on Hetzner object storage in Nuremberg, Germany. So the message and the certificate attached to it — normally carrying your name and licence number — are held on infrastructure in Germany between your sending them and our fetching them. Once fetched, the file is stored on our own server and in the backups, in the locations described above.
How long the provider keeps its own copy is governed by its terms rather than by this policy, and is not something we control. Nothing goes there if certificates-by-email is off for your agency, or if you simply never use your forwarding address — uploading a certificate from your own device does not touch it.
Two things this does not mean. It does not mean EZ Recert is offered in Europe; the service is for United States EMS agencies, which is a separate statement about who we serve rather than about where a file transits. And it is not a claim that nothing else ever leaves the country: the other companies listed above run their own infrastructure in places we do not choose, under their own terms. What we can tell you specifically is this one.
Cookies
Six cookies, all strictly necessary, no analytics and no trackers. Rather than summarise it here, the whole inventory — every name, what it holds and how long it lasts — is on the cookie page, along with what else is stored on your device and how to clear it.
How it is kept safe
Concretely, rather than as a promise of diligence:
- HTTPS everywhere, so nothing travels in the clear;
- Row-level security in the database. Every query runs under the permissions of the account that made it, so the boundaries between agencies and between people are enforced by the database rather than by application code remembering to check. Code can be wrong in one place; this cannot be wrong in one place;
- AES-256-GCM at rest for the SSN digits, keyed outside the database;
- Account creation by invitation only, enforced by the database itself — you cannot simply sign up;
- Rate limiting on sign-in, uploads and public forms, and a bot check on the forms reachable without an account;
- Support access that is restricted in what it can do and recorded when it is used;
- Error reports stripped of bodies, headers and anything matching a sensitive pattern before they leave the server;
- Backups, kept offsite, so a lost server is not a lost record.
Your records are stored on a server we rent and administer ourselves in Microsoft Azure's East US region, rather than on a managed platform. The offsite copy of the backups is held by Cloudflare, in a bucket placed in eastern North America.
These are the reasonable safeguards New York's SHIELD Act requires, and we maintain them as such. No system is perfectly secure and we are not going to claim this one is; the next section says what happens if that matters.
If there is a breach
If private information within the meaning of New York General Business Law section 899-aa is acquired without authorisation, we will notify affected New York residents in the most expedient time possible, consistent with the needs of law enforcement and with what the statute requires; notify the New York Attorney General and the other bodies the statute names; and tell the affected agencies what was involved and what we are doing about it. Residents of other states will be notified as their own state's law requires.
How long it is kept
Training records exist to prove a recertification cycle that runs for years, so they are kept while your account is active with an agency. Specifically:
- Certificate files are deleted from storage when the submission they belong to is deleted, including when an account is closed;
- Signed packets are kept as the record of what was filed. A voided packet is kept too — it is still the record of what was sent, and discarding it would leave a gap where a correction happened;
- Delivery logs, notification records and rate-limit counters are operational records for troubleshooting and abuse control. They are not a profile of you;
- Support-access records are kept as accountability records, which is the only reason to have them;
- Contact-form messages sit in our email inbox and never reach the database.
We do not currently run automated time-based deletion beyond the above — deletion happens when a record or an account is deleted. Saying so is more use to you than a retention schedule we do not enforce. To have your account and records deleted, ask your agency administrator or write to support@ezrecert.com, subject to the record-keeping your agency is itself obliged to do.
What you can ask for
- See and correct. Your profile and your whole submission history are visible and editable in the service.
- Stop the email. Turn notification email off on your profile. Account mail continues while the account exists.
- Stop the texts. Reply STOP to any of them, or switch them off in your profile. It has no effect on your account or your records.
- Stop the push. Turn it off in your profile, per device.
- Remove the SSN digits. Ask, and they go.
- Get a copy. Ask for your submissions and certificates in a portable form.
- Delete. Through your agency, or from us.
We honour these wherever you live rather than only where a statute compels them. New York does not currently have a general consumer-privacy statute; if you live somewhere that does, note that for training records we act largely on your agency's instructions, and we will pass a request to your agency where the law puts the decision with them rather than with us. The service is offered to EMS agencies in the United States and is not directed to people in the European Economic Area or the United Kingdom.
What this is not
- Not a patient record system. What is here is workforce credentialing — your training, not anybody's care. It is not built for protected health information, we are not a HIPAA business associate, and the Terms prohibit uploading patient information.
- Not a government system. We are not the New York State Department of Health, are not affiliated with or endorsed by it, and do not decide anybody's certification.
- Not an advertising business. No ad networks, no data sales, no cross-site tracking, no analytics.
Children
The service is for working EMS personnel and you must be 18 to hold an account. We do not knowingly collect anything from children. If you believe a child has given us information, write to support@ezrecert.com and we will delete it.
Changes, and how to reach us
Changes are posted here with a new date. For material ones we give notice in the service or by email — in particular, before any change to which third parties receive your documents.
Write to support@ezrecert.com for anything about this policy, or to make any of the requests above. Formal notice in writing goes to EZ Recert LLC, c/o Registered Agents Inc., 418 Broadway, Ste R, Albany, NY 12207.
The Terms of Service cover the rest of the relationship, the Cookie Disclosure itemises what is stored in your browser, and the Electronic Signature Disclosure covers signing.