Who is responsible for your data
AI Governance World LLC is the controller of personal data processed for this website and its direct services, unless an enterprise agreement expressly assigns a different role. Contact us at hello@aigovernanceworld.com.
Personal data we process
- Account data: email address, display name, password-derived security values, verification state, roles and account preferences.
- Membership and transaction data: selected product, currency, billing status, transaction identifiers, subscription state and invoices. Stripe processes payment-card details; AI Governance World does not receive full card numbers.
- Academy and credential data: enrolments, lesson progress, examination attempts and scores, certificate status, validity dates and identity information displayed on a credential. Public verification is limited to information needed to verify an issued credential.
- API and service data: API client and key identifiers, request counts, timestamps, response status, security events and usage needed to apply contracted limits.
- Communications: messages, correction requests, enterprise enquiries, support correspondence and delivery metadata.
- Technical data: IP address, browser and device information, request logs, session identifiers and security signals generated when the service is accessed.
- Public professional information: limited professional information about experts, officials and organization representatives obtained from cited public sources for the knowledge graph.
Why we process personal data
| Purpose | Legal basis where GDPR applies |
|---|---|
| Create and secure accounts; provide memberships, API access, courses, examinations and credentials | Performance of a contract and steps requested before entering a contract |
| Process payments, maintain financial records and respond to lawful requests | Performance of a contract and compliance with legal obligations |
| Prevent abuse, investigate incidents, protect users and maintain service integrity | Legitimate interests in operating a secure, reliable service and, where applicable, legal obligations |
| Answer support, enterprise, privacy and editorial correspondence | Contract, legitimate interests or consent, depending on the request |
| Publish evidence-led professional and institutional records in the public interest | Legitimate interests in providing accountable public-interest information, balanced against individual rights |
| Send optional promotional communications | Consent or another lawful basis expressly permitted by applicable law; you can opt out at any time |
Service providers and recipients
We disclose personal data only where necessary for the purposes above and under appropriate contractual and security obligations. Relevant processors include Cloudflare for edge hosting, delivery and security; Stripe for payment and subscription processing; and Brevo for transactional or consented email delivery. We may also disclose data to professional advisers, competent authorities or another party when required by law, necessary to establish or defend legal claims, or involved in a lawful corporate transaction.
Each external service may also process information under its own privacy notice when it acts as an independent controller, such as on a hosted payment page.
International transfers
Our providers may process data in more than one country. Where data protected by GDPR or comparable rules is transferred outside its protected region, we use a lawful mechanism such as an adequacy decision, standard contractual clauses or another recognized safeguard, and assess supplementary protections where required.
Retention
We keep personal data only as long as needed. Account and service records are generally retained while the account or contract is active and afterwards as needed for financial, legal, security, dispute and audit obligations. Credential records may remain as revoked, expired or superseded records to prevent misrepresentation. Security and usage logs are retained proportionately to risk. Correspondence is deleted or anonymized when no longer needed.
Cookies and similar technologies
The platform uses strictly necessary session and security technologies for authentication, service state and abuse prevention. External payment or security services may set their own necessary technologies. We do not use non-essential cookies where consent is required unless that consent was first obtained.
Automated processing
Automated systems help detect abuse, apply API limits and score Academy examinations under published rules. Editorial extraction tools propose knowledge-graph content, but a human controls publication. We do not use solely automated processing for decisions about individuals with legal or similarly significant effects unless contractually necessary, legally authorized or based on explicit consent with required safeguards. Contact us to request review of a result you believe is incorrect.
Your privacy rights
Depending on applicable law, you may have rights to access, correct, erase or restrict your data; object to legitimate-interest processing; receive portable data; and withdraw consent without affecting prior lawful processing. You may complain to the competent data-protection authority. We may verify your identity and retain information where an exemption or obligation applies.
Send requests to hello@aigovernanceworld.com. We respond within the period required by applicable law.
Security
We use organizational and technical controls designed to protect personal data, including access controls, encrypted transport, secret separation, integrity logging and role-based administration. No internet service can guarantee absolute security. Report suspected incidents promptly.
Children
The services are intended for people who can lawfully use them or authorized institutional users. We do not knowingly solicit data from children who cannot consent under applicable law. A parent or guardian who believes a child supplied data without valid authorization should contact us.
Changes to this notice
We may update this notice for changes in the service, processors or legal obligations. The effective date identifies the current version. Material changes will be communicated through an appropriate service channel where required.