Code 1 Training Solutions, LLC Privacy Policy

Effective date: September 8, 2026 ·  Last updated: September 8, 2026

Code 1 Training Solutions, LLC (“Code One,” “we,” “us,” or “our”) is a Connecticut limited liability company with its principal office at 2115 Colonial Avenue SW, Roanoke, VA 24015, providing in‑person and online CPR, first‑aid, and health‑and‑safety training and certification at locations across the United States. This Privacy Policy explains what personal information we collect, how we use, share, and protect it, how long we keep it, and the choices and rights you have. It applies to our websites and online services, our learner and client portals, our online course platform, our scheduling and registration tools, and our physical training locations — including training rooms and facilities that are monitored and recorded by video and, where enabled, analyzed by automated and AI‑assisted tools, as described in Section 6.

1. Information We Collect

Information you provide: registration and account data (name, email, phone, mailing/billing address, employer, profession, and — for certain courses — date of birth used to confirm eligibility and issue certifications); payment data (processed by our payment processor – we do not store full payment‑card numbers); training and certification records (courses registered, attendance, course and skills progress, assessment/skills‑check results, certifications and eCards issued, and any prerequisite certificates you upload); and communications you exchange with us (email, SMS/text, chat, and support requests).

Information collected automatically: device and usage data such as IP address, browser and device identifiers, pages viewed, and timestamps, collected through cookies and similar technologies (Section 5).

Information from employers and sponsoring organizations: if your employer, school, or another organization enrolls you, we receive roster information (such as name, email, and course assignment) from them (Sections 7 and 8).

Video from monitored locations: at our monitored training locations we record video (not audio) of training sessions and facility areas, and — where our automated monitoring is enabled — we derive inferences from it (for example, whether a participant is present, session start and stop times, whether required skills were performed, safety events, and facility conditions). Section 6 describes this in detail, including how audio is used and your consent.

We do not intentionally collect Social Security numbers, government‑ID numbers, financial‑account numbers, or medical records beyond the training and certification information above and any safety‑related information described in Section 2.

2. Sensitive Information

Some information we handle may be treated as “sensitive” under certain state privacy laws — for example, a learner’s date of birth, information about a known minor, and any health‑related information our safety monitoring may generate (such as a detected fall or medical emergency during a session, which we use only to respond to that emergency). Where the Connecticut Data Privacy Act, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, or a similar law requires opt‑in consent to process sensitive information, we obtain that consent or rely on a permitted exception (such as processing necessary to provide the service you requested or to protect someone’s vital interests). We minimize the sensitive information we process and limit its use to the purposes in this Policy.

3. How We Use Your Information

We use personal information to: register you for and deliver courses; verify attendance and skills and issue and deliver certifications and eCards; schedule appointments and send confirmations, reminders, and service messages; process payments and, for organizational clients, invoicing; monitor training sessions in real time and afterward, verify that required skills were performed, protect learner and staff safety, secure our facilities and equipment, and operate and maintain our locations (Section 6); provide support and improve our services and website; detect, prevent, and address fraud, misuse, and security incidents; and comply with legal, accreditation, and record‑keeping obligations, including certifying‑body requirements.

We do not use identifiable session recordings, or the inferences derived from them, to train, develop, or improve artificial‑intelligence or computer‑vision models; any model development uses only de‑identified or aggregated data, and we never use a minor’s or a school‑enrolled student’s recordings or inferences for model development. With your consent where required, we may send marketing communications; you can opt out at any time.

4. Cookies, Analytics, and Advertising

We use cookies and similar technologies to operate the site, remember your preferences, and measure and analyze traffic. You can control cookies through your browser settings. We do not sell your personal information, and we do not use it for cross‑context behavioral (“targeted”) advertising. We recognize and honor the Global Privacy Control (GPC) and other browser or device signals that communicate a choice to opt out of the sale or sharing of personal information; when we detect such a signal, we treat it as a valid opt‑out for that browser or device.

5. Video Monitoring, Recording, and AI‑Assisted Analysis

Please read this section carefully. It describes how we use cameras and automated tools at our training locations.

Where and why. Some of our locations operate as remotely monitored or self‑guided skills rooms. Cameras in these rooms and in common facility areas let us remotely supervise (“proctor”) and assist learners, verify that in‑person skills were actually performed as required for certification, respond to safety issues, secure the premises and equipment, and operate and maintain the facility. The cameras are conspicuous and visible at all times, these areas are openly monitored and are not private. We do not place cameras in restrooms or other areas where a person has a reasonable expectation of privacy.

Video only — we do not record audio.  Audio is connected only when our staff place a voice or video call into the room to assist or communicate with a learner; that audio is live only and is never recorded, and an audible chime sounds whenever audio or video is connected to the room so you know a connection is active. Recordings are captured and stored by our camera provider (Ring) on its servers, and access is limited as described below and in Section 9.

Automated and AI‑assisted analysis. At locations where automated monitoring is enabled, we use automated and AI‑assisted tools to analyze this video to derive operational information, which may include whether a participant is present; session start, duration, and completion; whether required physical skills (for example, chest compressions on a manikin) were performed; safety events (such as a fall or medical emergency); and facility conditions (such as supplies, cleanliness, or equipment status). These tools generate inferences and alerts about presence and activity in the room. They are not perfect and can produce errors.

Biometric data. Our analysis detects the presence of a person and physical activity in a room. It does not identify individuals from their biometric characteristics, and we do not capture, generate, store, or use a scan of face geometry, hand geometry, a fingerprint, a retina or iris scan, or a voiceprint, and we do not use any data to uniquely identify a person. We establish which enrolled learner is present through staff check‑in, the scheduled appointment, and the room context — not through biometric matching. If we ever introduce any feature that would collect or use a biometric identifier, we will first obtain separate, prior written consent (and, for a minor, verifiable parental or guardian consent) and update this Policy. Our camera and AI service providers are contractually prohibited from creating biometric identifiers from the footage, attempting to identify individuals, or using the footage to train their own models.

Human review of certification decisions. AI‑derived inferences are decision support, not the final word. Before we would deny or withhold a certification on the ground that required skills were not performed, a qualified staff member independently reviews the underlying footage, is authorized to and does override the automated result, and does not deny certification based on the automated output alone. If you are flagged, we will tell you, you may ask to review the footage of yourself that we relied on, you may contest the result, and you may re‑perform the skill. See Section 12.

Consent, and that recording is required. When you register, we ask you to acknowledge and consent to video recording and, where enabled, AI‑assisted analysis of your session. Recording and monitoring are necessary for safety and for the integrity of the skills verification that supports your certification, so they are a required condition of participating in a monitored self‑guided skills session — there is no non‑recorded alternative for those sessions. If you are not comfortable being recorded, please contact us before your appointment. Anyone who is present in a monitored area, including a person who accompanies a learner, is in an openly monitored, non‑private space and may be recorded; please do not bring others into a monitored skills room unless necessary.

6. How We Share Your Information

We do not sell your personal information. We share it only as follows:

  • Service providers that process data for us under contract, including Stripe (payments), the American Heart Association, RQI Partners, Ring (camera recording and storage), LiveKit (live‑session video), Twilio and RingCentral (calls and messaging), our email providers, ShipStation (shipping), and our hosting and analytics providers. Session video is stored by Ring on its servers. These providers may use your information only to perform services for us.
  • Employers and sponsoring organizations that enroll you receive only your enrollment status, attendance, skills‑check outcome, and certification result. They do not receive raw video recordings or the underlying AI inferences, except as required by a governing data agreement or by law.
  • Certifying bodies (such as the American Heart Association) as needed to issue and validate certifications.
  • Legal and safety: to comply with law, respond to valid legal process, enforce our agreements, or protect the rights, safety, and property of any person. We do not provide recordings to law enforcement except in response to valid legal process or a genuine emergency.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

7. Employer‑ and School‑Sponsored Learners

When an employer, school, or other organization enrolls you, that organization generally acts as the controller of the roster and results data, and Code One processes that data as its service provider under a written agreement. If you were enrolled this way, please direct requests to access or delete those records to your sponsoring organization; we will assist as our agreement requires.

Students and FERPA. When we provide training to students on behalf of a school under a contract, and student records are involved, we act as a “school official”/contractor under the Family Educational Rights and Privacy Act (FERPA) and applicable state student‑data‑privacy laws, including Connecticut’s student‑data‑privacy law (Conn. Gen. Stat. § 10‑234aa et seq.). Under our agreement with the school we use student data only to deliver the contracted training and certification; do not re‑disclose it except as the school directs or the law permits; do not use it for advertising, product development, or AI model training; and delete or return it at the school’s direction.

8. Data Retention

We keep personal information only as long as needed for the purposes described, or as required by law and certifying‑body record‑keeping rules, then delete or de‑identify it. In general:

  • Session video: stored by our camera provider (Ring) for approximately 180 days under its retention settings and then deleted, unless a specific recording is preserved for an active certification‑integrity, safety, dispute, or legal matter, in which case it is kept only as long as needed for that matter. Recordings of minors are handled with the heightened care described in Section 13.
  • AI‑derived inferences: kept with the related training record and deleted on the same schedule as the underlying footage unless they form part of a certification record.
  • Certification and training records: retained for the certification period and a reasonable time afterward to support card verification, accreditation, and audits.
  • Account and transaction records: retained as required by our tax, accounting, and legal obligations.

9. How We Protect Your Information; Breach Notice

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information, including role‑based, least‑privilege access controls; multi‑factor authentication for staff access; encryption of information in transit; limited and monitored access to recordings; and reliance on the security of our camera and hosting providers. No method of transmission or storage is completely secure. If a breach affecting your personal information occurs, we will notify affected individuals and, where applicable, sponsoring organizations and regulators without unreasonable delay and in accordance with applicable law (including Conn. Gen. Stat. § 36a‑701b) and our contractual obligations.

10. Your Privacy Rights and Choices

Depending on where you live, you may have some or all of the following rights regarding your personal information: to know about and access it; to correct it; to delete it; to obtain a portable copy; to opt out of the sale or sharing of personal information and of targeted advertising; to limit the use of sensitive information; to opt out of certain profiling; and to be free from discrimination for exercising these rights. Residents of states with comprehensive privacy laws — including California (CCPA/CPRA), Connecticut (CTDPA), Colorado, Virginia, and others — have these rights under their respective laws.

These rights extend to camera information: you may request access to the video and AI inferences of yourself (subject to redaction of others) and may correct or contest an adverse inference. We will honor deletion requests except where we are permitted or required to retain information — for example, to maintain certification and training records, meet accreditation or legal obligations, resolve an active safety or certification dispute, or detect security incidents.

How to exercise your rights. Submit a request by email to info@code1web.com or by mail at the address in Section 16. We will verify your request and respond within 45 days; if we need more time, we will notify you and may extend by up to an additional 45 days as permitted by law. You may use an authorized agent where the law allows; we will verify the agent’s authority and your identity. If we decline your request, you may appeal by contacting us at info@code1web.com with “Privacy Appeal” in the subject line. We will respond to an appeal within 60 days and explain our decision; if your appeal is denied, you may contact your state Attorney General.

11. Automated Processing and Human Review

Where enabled, we use automated and AI‑assisted tools (Section 6) to support monitoring and operations. The AI measures things like whether motion consistent with the required skill was detected for the required duration; it is not perfect and can produce errors, including false negatives. We do not make certification decisions by solely automated means. Before any adverse certification decision, a qualified staff member independently reviews the underlying footage and can override the automated result, and you may request that a different reviewer re‑examine it and may re‑perform the skill. Where your state’s law provides it, you may opt out of profiling used to make decisions that produce legal or similarly significant effects and request human review of a certification decision informed by automated analysis, by contacting us under Section 10 — except that we will continue to perform the certification‑integrity monitoring we are required to conduct.

12. Children and Minors

For purposes of this Policy, a minor is anyone under 18. Our website and online store are intended for adults and are not directed to children under 13.

Minors who take our courses. Some in‑person courses may be taken by minors, including, in some cases, children under 13. Before a minor is enrolled, recorded, or analyzed, we obtain verifiable consent from the minor’s parent or legal guardian — separate from course enrollment — covering the collection of the minor’s registration information, video recording of the minor during skills sessions, any automated/AI analysis of that footage, and our retention and use of it as described in this Policy. For children under 13 we handle this consistent with the Children’s Online Privacy Protection Act (COPPA); a sponsoring school’s or organization’s enrollment of a minor does not by itself constitute this consent. We do not knowingly collect personal information from a child under 13 without verifiable parental consent, and a parent or guardian may review, or request that we delete, their child’s information and recordings at any time by contacting us.

For learners we know to be minors, we do not sell their data, use it for targeted advertising, use their recordings or inferences to train models, or profile them except as strictly necessary to deliver and verify their training and certification. We apply data minimization and heightened access limits to minors’ recordings. A parent or guardian may exercise all applicable privacy rights on behalf of their minor, including access to and deletion of the minor’s recordings and inferences, under Section 10.

Children who accompany a learner. Monitored areas are openly monitored, with conspicuous cameras, and are not private; anyone present may be recorded. If you bring a child with you, please be aware the area is recorded, and avoid bringing children into a monitored skills room unless necessary.

13. Do Not Track and Opt‑Out Signals

Because there is no common standard for “Do Not Track” browser signals, we do not respond to them; however, as described in Section 4, we honor the Global Privacy Control and other recognized opt‑out preference signals as required by applicable law.

14. International Users

Code One operates in the United States and directs its services to U.S. residents. If you are located in the European Economic Area or the United Kingdom, please contact us and we will address applicable data‑protection rights on request.

15. Changes to This Policy

We may update this Policy to reflect changes in our practices or the law. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. We will communicate material changes to how we monitor or analyze recordings before they take effect.

16. Contact Us

Questions or privacy requests: info@code1web.com · Code 1 Training Solutions, LLC, 2115 Colonial Avenue SW, Roanoke, VA 24015 · 860‑786‑1789.

Help Me Find a Course

Go Back
Start Over