Privacy policy
Privacy Policy
Client, patient, service-user, or Rater Subject assessment data is not used for marketing.
Where CITS acts as processor, CITS processes personal data according to the controller's documented instructions, the DPA, and applicable data protection law.
Last Updated: July 24, 2026
1. Scope
This Privacy Policy describes how Center for Innovative Therapy Solutions, Inc. ("CITS," "we," "us," or "our") collects, uses, stores, shares, and protects personal information in connection with the CITS website, training platform, AMPS User Dashboard, cloud-based AMPS scoring software, support, communications, subscriptions, and related services (collectively, the "Services").
CITS is located at 329 S Woodruff Ave, Idaho Falls, ID 83401, United States. Questions about this Privacy Policy may be directed to amps-director@centerforinnovativetherapysolutions.com.
2. Relationship to the Data Processor Agreement
Where a customer, clinician, organization, or administrator enters client or service-user assessment data into the AMPS cloud-based software, that customer or organization is generally the controller of that data. CITS processes that data as a processor or service provider under the applicable Data Processor Agreement ("DPA"), customer agreement, or lawful instructions.
The DPA governs CITS's processing of Rater Data and other personal data processed on behalf of a customer. If this Privacy Policy conflicts with an executed DPA regarding processor obligations, the DPA controls for that processing relationship.
3. Key Definitions
Personal Data: Information relating to an identified or identifiable person, including account information, contact details, online identifiers, and, where applicable, health-related or assessment information.
Rater Data: Pseudonymized or minimized data submitted through the AMPS cloud-based software, which may include a rater subject's age or date of birth, gender, general diagnostic category, AMPS task selections, item scores, motor/process measures, and related assessment outcomes.
Rater Subject: A client, service user, patient, or other person whose assessment-related information is entered by a customer or clinician for AMPS scoring, training, calibration, or professional use.
Controller / Processor: The controller determines the purposes and means of processing. A processor processes personal data on behalf of a controller. For customer-entered Rater Data, CITS generally acts as processor.
4. Information We Collect
Depending on how you use the Services, we may collect or process the following categories of information:
- Identity and account information, such as name, username, password credentials, professional role, job title, organization, department, certification status, license key, and AMPS-related eligibility information.
- Contact information, such as email address, mailing address, phone number, and organizational contact details.
- Training and certification information, such as course enrollment, course progress, module completion, quiz completion, calibration status, uploaded proof of AMPS certification, and related support records.
- Subscription and billing information, such as plan selection, payment status, transaction records, invoices, and limited payment metadata. Card details are processed by payment providers such as Stripe and are not intended to be stored directly by CITS.
- Technical and usage information, such as IP address, browser type, device information, operating system, log-in events, security logs, URL activity, cookie identifiers, and similar diagnostic information.
- Rater Data and assessment-related information entered by customers or clinicians, as described in the DPA and customer instructions.
- Support and communications information, including emails, help requests, administrative messages, and other communications with CITS.
5. Special Category and Health-Related Data
The AMPS scoring software may be used by clinicians and organizations to enter information about Rater Subjects. Depending on the content entered, this information may include health-related or special category data under the UK GDPR, EU GDPR, or other applicable privacy laws.
Customers and clinicians are responsible for entering only the minimum necessary information, for obtaining any required consent or other lawful basis, and for complying with their employer, professional, ethical, jurisdictional, and organizational privacy obligations. CITS does not require customers to enter direct identifiers for Rater Subjects unless a feature or customer workflow specifically requires it.
6. How We Use Information
- To create, administer, secure, and support user accounts.
- To provide AMPS training, certification, calibration, scoring, reporting, subscription, and dashboard functions.
- To process payments, subscriptions, invoices, renewals, discounts, and related billing communications.
- To verify professional eligibility, AMPS certification status, legacy certification documentation, and calibration readiness.
- To provide technical support, customer service, administrative notices, and service communications.
- To maintain security, prevent unauthorized access, troubleshoot errors, monitor system performance, and protect the Services.
- To comply with applicable laws, contracts, DPA obligations, tax and accounting duties, dispute-resolution obligations, and lawful instructions from controllers.
- To improve the Services using aggregated or irreversibly anonymized information where the data no longer identifies a person and is not personal data.
Client, patient, service-user, or Rater Subject assessment data is not used for marketing.
7. Legal Bases for UK/EU Processing
Where the UK GDPR or EU GDPR applies and CITS acts as controller, CITS relies on one or more of the following legal bases: performance of a contract, legitimate interests, consent, compliance with legal obligations, and, where applicable, explicit consent or other lawful bases for special category data.
Where CITS acts as processor, CITS processes personal data according to the controller's documented instructions, the DPA, and applicable data protection law.
8. Cookies and Similar Technologies
We may use cookies and similar technologies to operate the Services, maintain sessions, improve security, remember preferences, analyze usage, and support service performance. Users may be able to control cookies through browser settings, but disabling cookies may affect the availability or function of some Services.
9. Sharing and Sub-processors
We share personal data only as needed to provide and protect the Services, comply with legal obligations, or follow controller instructions. Service providers and sub-processors may include cloud hosting, software development and support, payment processing, email delivery, learning platform services, and data protection representative services.
The DPA identifies current sub-processors and requires CITS to impose corresponding data protection obligations on sub-processors. Current or anticipated providers referenced in the DPA include Amazon Web Services, SoftKraft sp. z o.o., Stripe, LearnWorlds, Amazon SES, and DataRep, subject to change as described in the DPA or on the CITS website.
10. International Transfers
CITS is established in the United States. If personal data is transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions to CITS or a sub-processor outside that jurisdiction, CITS uses appropriate safeguards where required. For EEA transfers,
the DPA incorporates the European Commission Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, Module Two: Controller to Processor. For UK transfers, the DPA incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, Version B1.0.
11. Security
CITS maintains technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Measures referenced in the DPA include role-based access controls, authentication controls, logging and monitoring where technically available, encryption in transit using TLS/HTTPS, encryption at rest using AWS-managed encryption mechanisms where applicable, backups, firewalls or web application security controls, separation of environments, and confidentiality obligations for personnel authorized to process personal data.
No system can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of credentials, using strong passwords, enabling required security features, and promptly notifying CITS of suspected unauthorized account activity.
12. Retention and Deletion
We retain personal data for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and satisfy legitimate business or professional recordkeeping needs.
For personal data processed under the DPA, CITS will delete or return personal data according to customer instructions. If the customer has not requested deletion, the DPA provides that CITS will delete personal data no later than one hundred eighty (180) days after termination of the DPA or agreement, unless storage is required by applicable law. Backups may follow the backup retention schedule described in the DPA.
CITS may retain aggregated and irreversibly anonymized information for service improvement, development, research, quality assurance, or statistical purposes where the information no longer identifies any person.
13. Your Rights and Choices
Depending on your location and the role CITS plays in processing your information, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, and information about processing. You may also opt out of marketing communications.
Where CITS acts as processor for customer-controlled Rater Data, CITS may need to forward your request to the relevant customer or organization. Because Rater Data may be pseudonymized, CITS may require additional information from the controller before it can identify or act on a request.
14. Children
The Services are intended for adult professional users and organizational administrators. The Services are not directed to children. Rater Subject information concerning minors may be entered only by authorized customers or clinicians in accordance with applicable law, consent, professional obligations, and customer instructions.
15. Third-Party Links and Platforms
The Services may link to or integrate with third-party websites or platforms, including payment processors, learning platforms, and customer systems. Those third parties may have their own privacy policies and terms. CITS is not responsible for third-party practices except where those providers process data as CITS sub-processors under applicable agreements.
16. Changes to this Policy
CITS may update this Privacy Policy from time to time. The updated version will be identified by the Last Updated date. Continued use of the Services after an update means that you acknowledge the updated Policy, subject to any additional notice or consent requirements under applicable law.
17. EU/UK Representative and Contact
CITS has appointed DataRep as its designated data protection representative for the UK, EU, and EEA where required. Representative contact details may be made available on the CITS website or upon request.
Privacy questions and requests may be directed to: amps-director@centerforinnovativetherapysolutions.com.

