Privacy Policy

    Effective date: 24 February 2026

    Applies globally · Compliant with GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), POPIA (South Africa)

    1. Data Controller

    AiCE (AI Continuous Education), trading as AiCE Credits, is the data controller for personal information processed through aicecredits.com and associated services. Registered in England & Wales.

    Data Protection Officer: dpo@aicecredits.com

    2. Information We Collect

    2.1 Information You Provide Directly

    • Account registration details (full name, email address, organisation)
    • Professional profile, qualifications, and learning preferences
    • Assessment responses, learning activity, and skill verification data
    • Content uploaded for AI evaluation (documents, URLs, media)
    • Payment information (processed by Stripe; we do not store card details)
    • Communications with support

    2.2 Information Collected Automatically

    • Device and browser information (type, version, operating system)
    • Usage analytics (pages viewed, features used, session duration, click paths)
    • IP address and inferred geolocation (country/region level)
    • Cookies and similar technologies (see our Cookie Policy)

    2.3 Information from Third Parties

    • Employer-provided data when organisations create team accounts
    • Single sign-on providers (Google, Microsoft) if you choose social login

    3. Legal Basis for Processing (GDPR Art. 6)

    PurposeLegal Basis
    Account creation & service deliveryContract performance
    AI content evaluation & assessmentContract performance
    Certificate issuance & verification registryLegitimate interest
    Platform analytics & improvementLegitimate interest
    Marketing communicationsConsent
    Legal compliance & fraud preventionLegal obligation
    Ledger attestation (blockchain recording)Legitimate interest / Consent

    4. AI Processing & Automated Decision-Making

    We use artificial intelligence to evaluate educational content, generate assessments, calculate AICE Points, and provide personalised learning recommendations. Under GDPR Art. 22, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our AI outputs (AICE Points, complexity bands) are clearly labelled as AI-derived reference measures and do not constitute legally binding accreditation.

    You may request human review of any automated decision by contacting dpo@aicecredits.com.

    5. Data Sharing & Disclosure

    We never sell personal data. We may share information with:

    • Infrastructure providers: Cloud hosting, database, and authentication services (data processed under strict data processing agreements)
    • Payment processors: Stripe, for secure payment handling (PCI DSS compliant)
    • Employers/organisations: Only when you explicitly consent to share your learning profile, certificates, or assessment results
    • Distributed ledger: Certificate verification hashes only (no personal data) are recorded on-chain when you opt into ledger attestation
    • Legal authorities: When required by law, court order, or to prevent fraud

    6. International Data Transfers

    Your data may be processed outside your country of residence. For transfers from the EEA/UK, we rely on:

    • EU Standard Contractual Clauses (SCCs) approved by the European Commission
    • UK International Data Transfer Agreement (IDTA) where applicable
    • Adequacy decisions where available

    Copies of relevant transfer safeguards are available upon request.

    7. Data Retention

    Data TypeRetention Period
    Account dataDuration of account + 30 days after deletion request
    Certificate recordsIndefinite (public verification registry)
    Ledger attestation hashesPermanent (immutable on-chain)
    Assessment responses3 years from completion
    Usage analytics24 months (aggregated thereafter)
    Payment records7 years (legal/tax requirement)
    Support communications2 years from resolution

    8. Your Rights

    8.1 Under GDPR (EU/UK Residents)

    • Access (Art. 15) — obtain a copy of your personal data
    • Rectification (Art. 16) — correct inaccurate data
    • Erasure (Art. 17) — request deletion ("right to be forgotten")
    • Restriction (Art. 18) — limit processing in certain circumstances
    • Portability (Art. 20) — receive data in machine-readable format
    • Objection (Art. 21) — object to processing based on legitimate interest
    • Withdraw consent at any time
    • Lodge a complaint with your supervisory authority (UK: ICO — ico.org.uk)

    8.2 Under CCPA/CPRA (California Residents)

    • Right to know what personal information is collected and how it is used
    • Right to delete personal information
    • Right to opt-out of the sale or sharing of personal information (we do not sell data)
    • Right to non-discrimination for exercising your rights
    • Right to correct inaccurate information
    • Right to limit use of sensitive personal information

    To exercise CCPA rights, email privacy@aicecredits.com or use the "Do Not Sell My Info" link on our website. We will verify your identity before processing requests.

    8.3 Under LGPD (Brazil Residents)

    • Confirmation of data processing and access to your data
    • Correction of incomplete, inaccurate, or outdated data
    • Anonymisation, blocking, or deletion of unnecessary data
    • Data portability to another service provider
    • Information about entities with whom data has been shared
    • Revocation of consent

    8.4 Under POPIA (South Africa Residents)

    • Right to be notified of data collection
    • Right to request correction or deletion
    • Right to object to processing
    • Right to submit a complaint to the Information Regulator

    9. Data Security

    • Encryption in transit (TLS 1.3) and at rest (AES-256)
    • Role-based access controls and principle of least privilege
    • Regular penetration testing and vulnerability assessments
    • Cryptographic hashing for ledger-attested certificates
    • Incident response procedures with 72-hour breach notification (GDPR Art. 33)

    10. Children's Privacy

    AiCE is designed for professional learners aged 16 and over. We do not knowingly collect personal information from individuals under 16 (or 13 in jurisdictions where that threshold applies). If we discover such data has been collected, we will delete it promptly.

    11. Changes to This Policy

    We review this policy at least annually. Material changes will be communicated via email and a prominent banner on the platform at least 30 days before taking effect.

    12. Contact & Complaints

    Data Protection Officer: dpo@aicecredits.com
    General privacy enquiries: privacy@aicecredits.com
    Support: aicecredits.com/support

    UK Supervisory Authority: Information Commissioner's Office (ICO) — ico.org.uk