Policies
Privacy notice
This notice explains what personal data the Council holds about website visitors, enquirers, candidates, and credential holders, and what you can do about it.
- Reference
- AIAC/LEG/2026/02
- Issue
- 1.0
- Effective
- 9 August 2026
- Next review
- August 2027
- Status
- Draft — pending legal review
§ 1 — Policy
1. Who is responsible
Arthiq, operating the AI Assurance Council, is the organization responsible for the personal data described here. Enquiries: hello@aiassurancecouncil.org.
2. What we collect and why
Launch updates list
If you submit your email address, we hold that address and the date of submission, for the purpose of sending certification announcements. We do not use it for any other purpose and we do not sell or share it. You can unsubscribe from any message.
Enquiries
If you write to us, we hold your message and contact details in order to answer it and to keep a record of what was asked and answered.
Candidates and credential holders
From the first cohort, the Council will hold: identity details sufficient to confirm who sat an examination, assessment records and results, credential identifiers, and status history. This is necessary to operate a certification scheme in which a credential can be independently verified.
Website analytics
This website does not use third-party advertising or cross-site tracking. See the cookie policy for what is set.
3. The public register
A credential entry on the public register shows the credential name, identifier, issue and expiry dates, and status. The holder's name is published only where the holder has given consent, which can be withdrawn at any time. The non-identifying entry remains, because a register from which entries can vanish provides no assurance.
4. How long we keep it
- Launch updates list: until you unsubscribe.
- Enquiry correspondence: three years from the last message.
- Assessment and certification records: retained for the life of the scheme, as these are the evidence base for a credential that third parties rely on.
5. Your rights
Subject to the Personal Data Protection Act, you may ask what we hold about you, ask for it to be corrected, or withdraw consent to a particular use. We may decline a request, or charge a reasonable fee for access, where the Act permits — including where a request is manifestly unreasonable or repetitive, would reveal another person's data or our confidential examination material, or would defeat the integrity of the certification register. Withdrawing consent may mean we can no longer maintain your credential or register entry. We respond within 30 days. Requests: hello@aiassurancecouncil.org.
6. Sharing and international transfer
We share personal data with service providers acting on our instructions (for example email delivery, website hosting, examination delivery, and payment processing), with professional advisers, where required by law or by a regulator, and in connection with any sale, merger, or transfer of the scheme or of the operating company. Approved training partners do not receive assessment records.
Our service providers operate outside Singapore, including in the United States and the European Union. Where personal data is transferred abroad we take steps required by the Personal Data Protection Act to ensure a comparable standard of protection, but we are not liable for the acts or omissions of an independent third party beyond our reasonable control.
7. Security
We apply administrative and technical measures appropriate to the sensitivity of the data. No transmission or storage method is completely secure, and we do not warrant absolute security. You are responsible for keeping any credentials issued to you confidential.
8. Changes
This notice is version controlled. Material changes are published with a new issue number and effective date.
Contact
Questions about this policy should be addressed to hello@aiassurancecouncil.org.