Data protection

Privacy notice

How AI Governance World LLC processes personal data when you use the website, membership, API, Academy and institutional services.

Who is responsible for your data

AI Governance World LLC is the controller of personal data processed for this website and its direct services, unless an enterprise agreement expressly assigns a different role. Contact us at hello@aigovernanceworld.com.

Personal data we process

  • Account data: email address, display name, password-derived security values, verification state, roles and account preferences.
  • Membership and transaction data: selected product, currency, billing status, transaction identifiers, subscription state and invoices. Stripe processes payment-card details; AI Governance World does not receive full card numbers.
  • Academy and credential data: enrolments, lesson progress, examination attempts and scores, certificate status, validity dates and identity information displayed on a credential. Public verification is limited to information needed to verify an issued credential.
  • API and service data: API client and key identifiers, request counts, timestamps, response status, security events and usage needed to apply contracted limits.
  • Communications: messages, correction requests, enterprise enquiries, support correspondence and delivery metadata.
  • Technical data: IP address, browser and device information, request logs, session identifiers and security signals generated when the service is accessed.
  • Public professional information: limited professional information about experts, officials and organization representatives obtained from cited public sources for the knowledge graph.

Why we process personal data

PurposeLegal basis where GDPR applies
Create and secure accounts; provide memberships, API access, courses, examinations and credentialsPerformance of a contract and steps requested before entering a contract
Process payments, maintain financial records and respond to lawful requestsPerformance of a contract and compliance with legal obligations
Prevent abuse, investigate incidents, protect users and maintain service integrityLegitimate interests in operating a secure, reliable service and, where applicable, legal obligations
Answer support, enterprise, privacy and editorial correspondenceContract, legitimate interests or consent, depending on the request
Publish evidence-led professional and institutional records in the public interestLegitimate interests in providing accountable public-interest information, balanced against individual rights
Send optional promotional communicationsConsent or another lawful basis expressly permitted by applicable law; you can opt out at any time

Service providers and recipients

We disclose personal data only where necessary for the purposes above and under appropriate contractual and security obligations. Relevant processors include Cloudflare for edge hosting, delivery and security; Stripe for payment and subscription processing; and Brevo for transactional or consented email delivery. We may also disclose data to professional advisers, competent authorities or another party when required by law, necessary to establish or defend legal claims, or involved in a lawful corporate transaction.

Each external service may also process information under its own privacy notice when it acts as an independent controller, such as on a hosted payment page.

International transfers

Our providers may process data in more than one country. Where data protected by GDPR or comparable rules is transferred outside its protected region, we use a lawful mechanism such as an adequacy decision, standard contractual clauses or another recognized safeguard, and assess supplementary protections where required.

Retention

We keep personal data only as long as needed. Account and service records are generally retained while the account or contract is active and afterwards as needed for financial, legal, security, dispute and audit obligations. Credential records may remain as revoked, expired or superseded records to prevent misrepresentation. Security and usage logs are retained proportionately to risk. Correspondence is deleted or anonymized when no longer needed.

Cookies and similar technologies

The platform uses strictly necessary session and security technologies for authentication, service state and abuse prevention. External payment or security services may set their own necessary technologies. We do not use non-essential cookies where consent is required unless that consent was first obtained.

Automated processing

Automated systems help detect abuse, apply API limits and score Academy examinations under published rules. Editorial extraction tools propose knowledge-graph content, but a human controls publication. We do not use solely automated processing for decisions about individuals with legal or similarly significant effects unless contractually necessary, legally authorized or based on explicit consent with required safeguards. Contact us to request review of a result you believe is incorrect.

Your privacy rights

Depending on applicable law, you may have rights to access, correct, erase or restrict your data; object to legitimate-interest processing; receive portable data; and withdraw consent without affecting prior lawful processing. You may complain to the competent data-protection authority. We may verify your identity and retain information where an exemption or obligation applies.

Send requests to hello@aigovernanceworld.com. We respond within the period required by applicable law.

Security

We use organizational and technical controls designed to protect personal data, including access controls, encrypted transport, secret separation, integrity logging and role-based administration. No internet service can guarantee absolute security. Report suspected incidents promptly.

Children

The services are intended for people who can lawfully use them or authorized institutional users. We do not knowingly solicit data from children who cannot consent under applicable law. A parent or guardian who believes a child supplied data without valid authorization should contact us.

Changes to this notice

We may update this notice for changes in the service, processors or legal obligations. The effective date identifies the current version. Material changes will be communicated through an appropriate service channel where required.