Privacy Policy
Effective date: 24 February 2026
Applies globally · Compliant with GDPR (EU/UK), CCPA/CPRA (California), LGPD (Brazil), POPIA (South Africa)
1. Data Controller
AiCE (AI Continuous Education), trading as AiCE Credits, is the data controller for personal information processed through aicecredits.com and associated services. Registered in England & Wales.
Data Protection Officer: dpo@aicecredits.com
2. Information We Collect
2.1 Information You Provide Directly
- Account registration details (full name, email address, organisation)
- Professional profile, qualifications, and learning preferences
- Assessment responses, learning activity, and skill verification data
- Content uploaded for AI evaluation (documents, URLs, media)
- Payment information (processed by Stripe; we do not store card details)
- Communications with support
2.2 Information Collected Automatically
- Device and browser information (type, version, operating system)
- Usage analytics (pages viewed, features used, session duration, click paths)
- IP address and inferred geolocation (country/region level)
- Cookies and similar technologies (see our Cookie Policy)
2.3 Information from Third Parties
- Employer-provided data when organisations create team accounts
- Single sign-on providers (Google, Microsoft) if you choose social login
3. Legal Basis for Processing (GDPR Art. 6)
| Purpose | Legal Basis |
|---|---|
| Account creation & service delivery | Contract performance |
| AI content evaluation & assessment | Contract performance |
| Certificate issuance & verification registry | Legitimate interest |
| Platform analytics & improvement | Legitimate interest |
| Marketing communications | Consent |
| Legal compliance & fraud prevention | Legal obligation |
| Ledger attestation (blockchain recording) | Legitimate interest / Consent |
4. AI Processing & Automated Decision-Making
We use artificial intelligence to evaluate educational content, generate assessments, calculate AICE Points, and provide personalised learning recommendations. Under GDPR Art. 22, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our AI outputs (AICE Points, complexity bands) are clearly labelled as AI-derived reference measures and do not constitute legally binding accreditation.
You may request human review of any automated decision by contacting dpo@aicecredits.com.
5. Data Sharing & Disclosure
We never sell personal data. We may share information with:
- Infrastructure providers: Cloud hosting, database, and authentication services (data processed under strict data processing agreements)
- Payment processors: Stripe, for secure payment handling (PCI DSS compliant)
- Employers/organisations: Only when you explicitly consent to share your learning profile, certificates, or assessment results
- Distributed ledger: Certificate verification hashes only (no personal data) are recorded on-chain when you opt into ledger attestation
- Legal authorities: When required by law, court order, or to prevent fraud
6. International Data Transfers
Your data may be processed outside your country of residence. For transfers from the EEA/UK, we rely on:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreement (IDTA) where applicable
- Adequacy decisions where available
Copies of relevant transfer safeguards are available upon request.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion request |
| Certificate records | Indefinite (public verification registry) |
| Ledger attestation hashes | Permanent (immutable on-chain) |
| Assessment responses | 3 years from completion |
| Usage analytics | 24 months (aggregated thereafter) |
| Payment records | 7 years (legal/tax requirement) |
| Support communications | 2 years from resolution |
8. Your Rights
8.1 Under GDPR (EU/UK Residents)
- Access (Art. 15) — obtain a copy of your personal data
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — request deletion ("right to be forgotten")
- Restriction (Art. 18) — limit processing in certain circumstances
- Portability (Art. 20) — receive data in machine-readable format
- Objection (Art. 21) — object to processing based on legitimate interest
- Withdraw consent at any time
- Lodge a complaint with your supervisory authority (UK: ICO — ico.org.uk)
8.2 Under CCPA/CPRA (California Residents)
- Right to know what personal information is collected and how it is used
- Right to delete personal information
- Right to opt-out of the sale or sharing of personal information (we do not sell data)
- Right to non-discrimination for exercising your rights
- Right to correct inaccurate information
- Right to limit use of sensitive personal information
To exercise CCPA rights, email privacy@aicecredits.com or use the "Do Not Sell My Info" link on our website. We will verify your identity before processing requests.
8.3 Under LGPD (Brazil Residents)
- Confirmation of data processing and access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymisation, blocking, or deletion of unnecessary data
- Data portability to another service provider
- Information about entities with whom data has been shared
- Revocation of consent
8.4 Under POPIA (South Africa Residents)
- Right to be notified of data collection
- Right to request correction or deletion
- Right to object to processing
- Right to submit a complaint to the Information Regulator
9. Data Security
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Role-based access controls and principle of least privilege
- Regular penetration testing and vulnerability assessments
- Cryptographic hashing for ledger-attested certificates
- Incident response procedures with 72-hour breach notification (GDPR Art. 33)
10. Children's Privacy
AiCE is designed for professional learners aged 16 and over. We do not knowingly collect personal information from individuals under 16 (or 13 in jurisdictions where that threshold applies). If we discover such data has been collected, we will delete it promptly.
11. Changes to This Policy
We review this policy at least annually. Material changes will be communicated via email and a prominent banner on the platform at least 30 days before taking effect.
12. Contact & Complaints
Data Protection Officer: dpo@aicecredits.com
General privacy enquiries: privacy@aicecredits.com
Support: aicecredits.com/support
UK Supervisory Authority: Information Commissioner's Office (ICO) — ico.org.uk
