Policies
Privacy notice
This notice explains what personal data the Council holds about website visitors, enquirers, candidates, and credential holders, and what you can do about it.
- Reference
- AIAC/LEG/2026/02
- Issue
- 1.0
- Effective
- 26 August 2026
- Next review
- August 2027
- Status
- Current
§ 1 — Policy
1. Who is responsible
The AI Assurance Council is responsible for the personal data described here. The organisation accountable for it is AI Assurance Council Pte. Ltd. (UEN 202640068G), the company identified in section 1 of the terms of use, whose registered office is on the contact page. Enquiries: hello@aiassurancecouncil.org.
2. What we collect and why
Launch updates list
If you submit your email address, we hold that address, the date of submission, and the page you submitted it from. If you answer the optional question about how you found us, we hold that answer too: it is a choice from a short list, it may be left blank, and nothing about it is taken from your browser or inferred from your visit. We hold no IP address, no device information and no tracking identifier. We use all of it to send certification announcements and to decide what to publish next. We do not use it for any other purpose and we do not sell or share it. You can unsubscribe from any message.
Registrations of interest
A credential that is published but not yet open for enrolment takes registrations of interest from its page. If you submit one, we hold your name, your email address, the credential you registered interest in, the date, and the page you submitted it from. Organisation and role are optional and are held only if you give them. We hold no IP address, no device information and no tracking identifier. We use it to write to you when that credential opens and to decide the order in which credentials open. We do not use it for any other purpose and we do not sell or share it.
Enquiries
If you write to us, we hold your message and contact details in order to answer it and to keep a record of what was asked and answered.
Candidates and credential holders
For candidates and holders, the Council holds: identity details sufficient to confirm who sat an examination, assessment records and results, credential identifiers, and status history. This is necessary to operate a certification scheme in which a credential can be independently verified.
Identity verification
Before any assessment is sat — including the free AI Literacy assessment — a candidate completes an identity check: a photograph of a government-issued identity document and a short face check. The purpose is narrow and it is the reason the scheme can be relied on: to establish that the person assessed is the person named on the credential and on the public register.
The check is carried out by Didit (didit.me), a specialist identity verification provider acting as our data intermediary. The document image and the biometric data are collected and held by Didit, which retains them for two years and then deletes them;the Council never receives them. If you would rather they were deleted sooner, write to hello@aiassurancecouncil.org and we will have them removed — the outcome of your check, and so your credential, is unaffected. What the Council receives and stores is the outcome of the check — verified, not verified, or awaiting a decision — the provider’s reference for the session, so that an outcome can be matched to a candidate record and audited later, and the name as it appears on the document.
On a successful check that verified name replaces the name you gave at sign-up, because it is the name your credential, your certificate and your public register entry will carry, and a certification body should publish a name it has established rather than one it was told. If you believe the name recorded from your document is wrong, write to hello@aiassurancecouncil.org and it will be corrected. No other detail from the check — document number, date of birth, or the result of the biometric comparison — is taken into our records.
Proctored examinations
An examination leading to a credential is recorded from the moment you consent at the start of the sitting until you submit. The recording is your camera and microphone, your entire screen, twenty seconds of your room and desk before you begin, and a log of events in the browser during the sitting: leaving full screen or the examination tab, the screen share or camera stopping, use of the clipboard, and a second display appearing. The check that runs before the sitting records the browser you used, the camera and microphone it found, and which surface you shared. Nothing you type is captured other than the answers you submit.
The recording is held in the Council's own private storage and is seen by an assessor reviewing that sitting, and by a conduct panel if one is convened. It is used for no other purpose, is never used to train anything, and is not shared with any third party other than the storage provider holding it on our behalf. A candidate who declines to be recorded cannot sit a proctored examination; the free AI Literacy assessment is not proctored and is not recorded.
Website analytics
This website uses Umami, a self-hosted, cookie-free analytics tool, to measure aggregate page views and how the site is used: which links are followed, how far down a page or through an article people read, how long a visit lasts as a broad band rather than a time, whether a page was printed, and which addresses produce a "page not found". It also records technical signals about the site itself — how quickly a page rendered, and whether a script failed. It sets no cookie, stores no identifier on your device, records nothing you type, and shares nothing with an advertising company. There is no session recording and no device fingerprinting. Google Analytics runs alongside it only if you consent through the cookie banner; without consent nothing is loaded from Google. Consent can be withdrawn at any time. This website does not use third-party advertising or cross-site tracking. See the cookie policy for what is set.
3. How we write to you
Automated messages — address verification, assessment results, your certificate and the account notifications you can switch off — are sent from noreply@aiassurancecouncil.email, which is a separate domain from this website and is not read. Anything from a person at the Council comes from hello@aiassurancecouncil.org and can be replied to. The Council never asks for a password or for payment details by email, and every link in a genuine message points at aiassurancecouncil.org or portal.aiassurancecouncil.org — the contact page sets this out in full, so an unexpected message can be checked rather than guessed at.
4. Age
The Council's services are for adults, and its terms of use require an account holder to be 18 or over. We do not knowingly collect personal data from anyone under 18, and we do not ask a child for data at any point. Age is checked, not taken on trust: at identity verification the date of birth on your document is read and checked against the minimum age, and a verification that does not meet it is refused. All we take from that is the outcome — we do not receive, store or log the date itself. If we learn that an account belongs to someone under 18 we close it, withdraw any credential issued to it, and delete the personal data we hold — the one exception being a record we are required to keep by law, which is kept for that purpose alone and nothing else. If you believe a child has given us personal data, write to hello@aiassurancecouncil.org and we will act on it.
5. The public register
A credential entry on the public register shows the credential name, identifier, issue and expiry dates, and status. The holder's name is published only where the holder has given consent, which can be withdrawn at any time. The non-identifying entry remains on the register.
6. How long we keep it
- Launch updates list: until you unsubscribe.
- Registrations of interest: until the credential opens and you have been told, or until you ask for it to be removed, whichever is sooner.
- Enquiry correspondence: three years from the last message.
- Assessment and certification records: retained for the life of the scheme, as these are the evidence base for a credential that third parties rely on.
- Proctoring recordings and event logs: retained for twelve months from the sitting, or until any appeal or conduct proceeding that relies on them has concluded, whichever is later, and then deleted. The assessor's determination on the recording is part of the assessment record and is kept with it.
- Identity verification outcomes: retained with the assessment record they permit, for the same period and for the same reason. The underlying documents and biometric data are not ours to keep — the verification provider holds those and deletes them two years after the check, or sooner on request.
7. Your rights
Subject to the Personal Data Protection Act, you may ask what we hold about you, ask for it to be corrected, or withdraw consent to a particular use. We may decline a request, or charge a reasonable fee for access, where the Act permits — including where a request is manifestly unreasonable or repetitive, would reveal another person's data or our confidential examination material, or would defeat the integrity of the certification register. Withdrawing consent may mean we can no longer maintain your credential or register entry. We respond within 30 days. Requests: hello@aiassurancecouncil.org.
8. Sharing and international transfer
We share personal data with service providers acting on our instructions (for example email delivery, website hosting, identity verification, examination delivery, and payment processing), with professional advisers, where required by law or by a regulator, and in connection with any sale, merger, or transfer of the scheme or of the Council. No preparation provider ever receives assessment records, and within the Council the people who write or deliver its preparation course have no access to them.
Our service providers operate outside Singapore, including in the United States and the European Union. Where personal data is transferred abroad we take steps required by the Personal Data Protection Act to ensure a comparable standard of protection, but we are not liable for the acts or omissions of an independent third party beyond our reasonable control.
9. Security
We apply administrative and technical measures appropriate to the sensitivity of the data. No transmission or storage method is completely secure, and we do not warrant absolute security. You are responsible for keeping any credentials issued to you confidential.
10. Changes
This notice is version controlled. Material changes are published with a new issue number and effective date.
Contact
Questions about this policy should be addressed to hello@aiassurancecouncil.org.