Legal & Compliance

Privacy Policy

Last Updated: April 2026

At CAISG, we hold data privacy and confidentiality to the highest professional standard. This Privacy Policy details how Certified AI Systems Governance & Security Professional ('CAISG', 'we', 'us', or 'our') collects, processes, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and global data protection frameworks.

1. Data Controller Identity & Privacy Officer Contact

CAISG serves as the Data Controller for personal data collected through our website, learning management system (LMS), and certification services. We have established rigorous data governance protocols to safeguard student and enterprise information.

For any inquiries regarding data protection, statutory access requests, or privacy practices, please contact our Data Protection Officer at privacy@caisg.org. We are committed to responding to verified statutory privacy inquiries within thirty (30) calendar days.

2. Categories of Personal Data Collected & Processing Methods

We collect and process only the minimal personal data necessary to deliver educational services, execute payments, manage accounts, and verify professional credentials:

  • Account Registration Data: Legal full name, professional email address, company or institutional affiliation, and job title.
  • Billing & Financial Metadata: Billing address, transaction reference ID, currency ($ USD), and payment authorization status. Payment processing is handled exclusively by Stripe, Inc.; CAISG does not store or process raw primary account numbers (PAN) or card verification values (CVV).
  • Educational & Learning Telemetry: Module progress, interactive slide view timestamps, quiz results, final examination submissions, proctoring integrity events, and Certificate of Completion verification records.
  • Technical & Operational Logs: Internet Protocol (IP) address, browser user-agent string, device operating system, referring URL, and session authentication timestamps.

3. Lawful Bases for Processing Under GDPR (Article 6)

Contractual Necessity (Article 6(1)(b)): Processing is required to perform our contract with you—including provisioning LMS access, processing enrollment payments, and issuing earned certificates.

Legitimate Interests (Article 6(1)(f)): Processing is necessary to protect platform integrity, prevent unauthorized credential sharing, detect fraudulent transactions, and secure our systems.

Legal Obligation (Article 6(1)(c)): Processing is necessary to comply with commercial accounting, corporate tax reporting, and statutory regulatory requirements.

Explicit Consent (Article 6(1)(a)): Where you provide affirmative consent for direct support interactions or voluntary feedback submissions.

4. Third-Party Payment Processing & Stripe PCI-DSS Standards

Payment processing is executed directly through our third-party payment infrastructure partner, Stripe, Inc. Stripe is certified as a PCI-DSS Level 1 Service Provider—the highest security level in the payments industry.

All payment card details are encrypted in transit via Transport Layer Security (TLS 1.3) and transmitted directly to Stripe's secure tokenization vaults. CAISG servers never capture, store, or transmit raw credit card credentials.

5. Cookies, Local Storage & Operational Session Telemetry

We utilize strictly essential first-party session cookies and secure browser local storage tokens solely to maintain authenticated user sessions and preserve course progression.

Zero Advertising Trackers: CAISG enforces a strict privacy policy. We do not deploy third-party advertising tracking pixels, cross-site behavioral cookies, or data broker analytics scripts.

6. Sub-Processors, Service Providers & International Data Transfers

We do not sell, rent, monetize, or trade your personal data. We disclose necessary data solely to vetted technical sub-processors who assist in operating our infrastructure (Stripe for payments, MongoDB Atlas for encrypted database hosting, Cloudflare for security and content delivery).

International Data Transfers: Personal data transferred internationally is protected through European Commission Standard Contractual Clauses (SCCs) and robust technical encryption safeguards.

7. Data Retention Schedule & Account Decommissioning

We retain personal data for as long as your account remains active or as necessary to provide educational access and maintain the permanent record of your earned Certificate of Completion.

Transaction and financial records are retained for a statutory period of seven (7) years to satisfy international corporate tax, financial auditing, and anti-fraud requirements.

Upon verified account deletion request, personal learning records are purged or permanently anonymized within thirty (30) days, subject to mandatory statutory legal holds.

8. European Union & UK Statutory Privacy Rights (GDPR)

If you reside within the European Union or United Kingdom, you hold the following statutory rights under GDPR Articles 15 through 22:

  • Right of Access (Article 15): Request confirmation of processing and obtain copies of your personal data.
  • Right to Rectification (Article 16): Request immediate correction of inaccurate or incomplete personal records.
  • Right to Erasure (Article 17): Request permanent deletion of personal data ('Right to be Forgotten'), subject to legal retention obligations.
  • Right to Restriction of Processing (Article 18): Request restriction of data processing under certain statutory conditions.
  • Right to Data Portability (Article 20): Obtain your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Article 21): Object to data processing based on legitimate interests.

Supervisory Authority Complaints: You have the right to lodge a formal complaint with your relevant national data protection supervisory authority if you believe our data processing violates applicable law.

9. California Consumer Privacy Rights (CCPA / CPRA Disclosures)

California residents possess specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected in the preceding 12 months.
  • Right to Delete: Request deletion of personal information collected, subject to statutory business exceptions.
  • No Sale or Sharing: CAISG does not sell personal information or share personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service for exercising your statutory privacy rights.

California Shine the Light: CAISG does not disclose personal data to third parties for direct marketing purposes.

10. Information Security Controls, Minors & Policy Amendments

Technical Security Measures: CAISG enforces state-of-the-art security controls, including TLS 1.3 encryption in transit, AES-256 encryption at rest, multi-factor administrative authentication, and automated vulnerability audits.

Protection of Minors (COPPA): Our services are directed strictly at enterprise professionals and adult learners (18+). We do not knowingly collect personal data from individuals under 18 years of age.

Policy Amendments: We may update this Privacy Policy periodically to reflect technological or regulatory changes. Updated policies become effective upon posting with a revised 'Last Updated' timestamp.

Privacy Inquiries: To submit a verified statutory request or inquire about our data practices, please contact privacy@caisg.org.