Privacy Policy
Bright Paths Behavioral Corp. — CADP Portal
Effective Date: September 24, 2026
Bright Paths Behavioral Corp. (“BPBC,” “we,” “us,” or “our”) operates the Clinical Analyst Development Program (“CADP”) and the CADP Portal. This Privacy Policy explains how information is collected, used, stored, and protected when individuals use the CADP Portal, including when they sign in using a Google Account.
Information We Collect
When you use Google Sign-In to access the CADP Portal, Google may provide us with limited account and authentication information necessary to identify and authenticate you. Depending on the authentication response, this may include:
- your Google account unique identifier (sub);
- your email address;
- your name or basic profile information;
- authentication-related claims used to verify the security of the sign-in session, including authentication method or authentication time where available.
CADP does not request access to your Gmail messages, Google Drive files, Google Calendar data, Google Contacts, or other unrelated Google services as part of the sign-in process.
CADP may also collect program-related information that you provide directly, including enrollment, supervision, fieldwork, training, scheduling, assignment, competency, and administrative information necessary to operate the program.
How We Use Google User Data
Google account information received through Google Sign-In is used only to:
- authenticate users;
- associate an authenticated Google identity with the appropriate CADP account;
- support account and session security;
- determine whether applicable authentication-security requirements have been satisfied;
- maintain security and audit records;
- prevent unauthorized access.
Google user data obtained for authentication is not used for advertising, marketing profiling, or unrelated purposes.
Authentication and Security
CADP uses server-side authentication and authorization controls. A successful Google sign-in does not by itself grant access to privileged CADP functions. User roles, permissions, and access rights are controlled separately by CADP.
Where Google provides authentication-strength information, CADP may use those verified claims to determine whether additional security requirements, such as multi-factor authentication, have been satisfied for a particular session.
Storage and Retention
CADP stores only information reasonably necessary to operate the program, maintain account security, support authorized supervision and administrative functions, and satisfy applicable business, legal, contractual, and recordkeeping requirements.
Authentication tokens are handled only as necessary to complete and validate the authentication process. CADP does not intentionally retain Google account credentials or Google passwords.
Security, access, and audit records may be retained as reasonably necessary to protect the integrity of the CADP system and document authorized access.
Sharing of Information
BPBC does not sell Google user data.
We do not share Google user data with advertisers.
Information may be disclosed only when reasonably necessary to:
- operate or secure the CADP Portal;
- provide services requested by the user;
- comply with applicable law, legal process, or regulatory obligations;
- protect the rights, safety, or security of BPBC, CADP participants, or others;
- use service providers that support authorized CADP operations and are subject to appropriate confidentiality and security obligations.
Limited Use of Google User Data
CADP's use of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
Google user data will be used only for the purposes disclosed in this Privacy Policy and only to the extent necessary to provide and secure the CADP authentication and account-access functions.
Client and Clinical Information
The Google Sign-In process is not intended for the transmission of client clinical information. Users should not place client-identifying information, protected health information, diagnoses, payer identifiers, or other confidential clinical information into general authentication, enrollment, or account-profile fields.
Clinical information, when applicable to authorized CADP activities, must be handled only through approved workflows and according to applicable privacy, professional, organizational, and legal requirements.
User Choices and Access
Users may choose not to use the CADP Portal if they do not wish to provide the information required for authentication and program participation.
Users may contact BPBC regarding questions about their CADP account, personal information, or privacy practices.
Changes to This Policy
We may update this Privacy Policy when our services, security practices, legal requirements, or use of Google authentication services change. The current version will be posted on this page with its effective date.
Contact
Bright Paths Behavioral Corp.
Clinical Analyst Development Program
Email: bpbehavior@brightpathsbx.com
Website: https://brightpathsbx.com