Privacy Policy
How IACAIP collects, uses and protects personal data in delivering certification and assurance services.
Last updated: 21 August 2026
1Data Controller
The International Association of Cybersecurity and AI Professionals ("IACAIP", "we") is the data controller responsible for your personal data. We are a company limited by guarantee registered in England and Wales (No. 16843978), with our registered office at 128 City Road, London, United Kingdom EC1V 2NX. Our contact email is info@iacaip.org.uk.
This policy is prepared in accordance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
2Personal Data We Collect
- Account data: name, email address, password (hashed), role and profile details you provide when registering.
- Application data: certification selections, pathway choices, eligibility information and professional history.
- Assessment data: exam responses, case study submissions, portfolio evidence, references, interview records and assessor feedback.
- Organisational data: for organisational assessments, company details, scope information and uploaded evidence.
- Payment data: transaction identifiers and order status processed via Base44 Payments. We do not store full card numbers.
- Technical data: IP address, browser type and usage logs collected automatically.
3Lawful Basis for Processing
- Contract: processing necessary to deliver a Certification you have applied for and to issue Credentials.
- Legal obligation: retaining records to meet regulatory and audit obligations.
- Legitimate interests: fraud prevention, assessment integrity, quality assurance and service security.
- Consent: for optional analytics cookies and public registry listings, which you may withdraw at any time.
4How We Use Your Data
We use your personal data to:
- Administer applications, Assessments, moderation and panel reviews;
- Issue, verify and renew Credentials and maintain the Shielded Registry;
- Process payments and fulfil purchases;
- Communicate with you about your Certification and related matters;
- Maintain assessment integrity and investigate misconduct;
- Meet legal, regulatory and audit requirements.
5Data Sharing
We share personal data only where necessary, including with: assessors, moderators and panel members involved in your Assessment; our payment provider (Base44 Payments) for transaction processing; and regulators or law enforcement bodies where legally required. We do not sell personal data.
6International Transfers
Where personal data is transferred outside the UK, we rely on appropriate safeguards such as UK International Data Transfer Agreements or applicable adequacy regulations.
7Data Retention
We retain personal data for as long as necessary to provide our services and to meet legal and regulatory obligations. Assessment records and Credentials are typically retained for the validity period of the Credential plus a defined archive period. Account data is retained while your account is active and for a reasonable period thereafter.
8Your Rights
Under UK GDPR you have the right to:
- Be informed about how your data is used;
- Access, rectify, or erase your personal data;
- Restrict or object to processing;
- Data portability;
- Withdraw consent at any time (where processing is based on consent);
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk).
To exercise these rights, contact info@iacaip.org.uk.
9Security
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and server-side processing of sensitive assessment logic. However, no method of transmission or storage is completely secure.
10Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to registered users where practicable. Continued use of the services after changes take effect constitutes acceptance of the revised policy.
