IEU — Privacy Policy
1. About Us
The Institute for Ethical Use (“IEU,” “we,” “us”) operates the website at ethical-use.com and the IEU three-tier AI-ethics certification program. This statement explains how we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), and where applicable, provincial privacy legislation, such as the Act respecting the Protection of Personal Information in the Private Sector (“Quebec’s Privacy Act”) and foreign legislation such as EU or UK General Data Protection Regulation (“GDPR”).
IEU is committed to respecting and protecting the privacy rights of individuals. We are committed to maintaining the accuracy, confidentiality, and security of personal data in our custody. This commitment is reflected in our internal policies, safeguards and practices to ensure compliance with the relevant laws and regulations noted in the preceding paragraph. We adhere to maintaining the highest standard of quality, transparency, and accountability by developing policies and procedures about the collection, use, disclosure of information that align with federal, provincial, and industry standards.
For more information, please contact our Privacy Officer Connor Walsh at connor@ethical-use.com
2. Scope
This statement applies to personal information we collect through our website, the Level 1 self-assessment, Level 2 training and certification, Level 3 organizational assessments, and related communications.
3. Information we collect
IEU complies with all applicable provisions of privacy legislation in Canada. We have implemented PIPEDA, and where applicable, Quebec’s Privacy Act, and the EU or UK GDPR, which set the ground rules for how private-sector organizations collect, use, and disclose personal information during the course of commercial activity.
This Privacy Policy applies to information we collect that you provide us with, including:
- Assessment responses and company profile: your answers to the Level 1 self-assessment along with the profile details you provided (i.e. industry/sector, organization size, country, and your role/job title).
- Work-email verification: to begin the Level 1 assessment, we ask for a work email address and verify it with a one-time code. Please note that free webmail addresses are not accepted, as the assessment is completed on behalf of an organization.
- Authorization attestation: your name and an attestation that you are authorized to complete the assessment on behalf of your organization. We log the attestation, the date and time, and the IP address from which it was given, as proof of that authorization.
- Contact details: your name and work email, which you provided in order to receive your results or to hear from us.
- Account information: for Level 2, your name and email (authentication is handled by our identity provider), along with your training progress and exam attempts.
- Payment information: this is handled by our payment processor. We do not store full payment-card numbers on our servers.
- Inquiries: information you submit through our “Talk to us” or contact forms.
Information collected automatically
We collect information through:
- Cookieless, aggregate website analytics (i.e., page views, approximate visits, and referrers). We do not use advertising cookies and do not use Google Analytics.
- Marketing-attribution parameters (UTM tags) associated with a visit.
- Limited technical and security information necessary to operate and protect the site (i.e., IP addresses processed at our security/edge layer for rate-limiting and abuse prevention).
4. How we use your information
We use personal information to:
- deliver and score the assessment;
- verify that a user is authorized to act for their organization and prevent abuse;
- provide training and issue and verify certifications;
- respond to your inquiries;
- send follow-up or marketing communications where you have consented;
- understand, in aggregate, which industries engage with us;
- operate, secure, and improve the service; and
- comply with legal obligations.
5. Legal bases for processing
Depending on where you are located, we rely on your consent, the performance of a contract with you, and/or our legitimate interests.
6. Marketing and consent
We only send follow-up and marketing communications where you have given express consent, which is obtained solely through an opt-in mechanism (i.e., you can check off your consent in the blank box). You may withdraw your consent at any time, and at no cost to you, using the unsubscribe link in our emails or by contacting us at connor@ethical-use.com We take such requests seriously and your request is processed without delay and will be in effect within ten (10) business days after your request has been made.
7. Service providers and sub-processors
We do not sell your personal information to third parties. We share it with service providers who process it on our behalf under contract (and data-processing agreements where applicable) only where necessary for the purposes specified in this Privacy Policy. Before transferring personal information outside of Canada, we conduct an assessment to confirm that the service provides have the appropriate level of security in place and in accordance with Canadian privacy legislation and enter into contractual safeguards requiring the provider to maintain that protection.
A list of our current sub-processors is set forth below:
| Provider | Purpose | Personal data handled | Processing location |
|---|---|---|---|
| Vercel, Inc. | Application functions – server-rendering, server actions and route handlers | Request content and session data processed when service a page or action | Canada — Montreal (yul1) region |
| Vercel, Inc | Edge routing and content delivery – request routing, static assets, TLS termination | Request metadata and the session cookie, read in order to route the request | Global edge network |
| Supabase | Primary database, authentication, and file storage | Accounts, assessment responses & company profiles, enrollments, training progress, exam attempts, certificates, audit logs | Canada — Central (ca-central-1) region |
| Stripe, Inc. | Payment processing (Level 2 checkout, invoicing) | Billing name/email and payment-card data — card data is handled entirely by Stripe and never stored on our servers | United States |
| Amazon Web Services, Inc. – Simple Email Service (SES) | Transactional email delivery (verification codes, receipts, results summaries, certificate notices) | Recipient email address and message contents | Canada – Central (ca-central-1) region |
| Sentry (Functional Software, Inc.) | Application error and performance monitoring | Technical diagnostic/error data only — configured to scrub personal information and strip IP addresses before transmission, so personal information is not intended to reach this provider | European Union — Germany (Frankfurt) region |
| Cloudflare, Inc. | DNS, DDoS protection, web application firewall, edge rate-limiting | Network-level data (including IP addresses) processed at the edge to route and secure traffic | Global edge network |
| Cloudflare, Inc. – Web Analytics | Aggregate, cookieless traffic analytics | Aggregate page views, referrers, and campaign (UTM) parameters — no advertising cookies, no cross-site tracking, no Google Analytics | Global edge network |
| Google Workspace (Google LLC) | Business email hosting for @ethical-use.com (receiving inquiries; sending-domain authentication) | Email correspondence you send us (e.g. via ‘Talk to us’ / contact) | United States / global |
Please note that we may also disclose information where required by law or to protect our rights. This list may be updated from time-to-time and will be provided upon request
8. Where your data is stored (data residency)
Our primary application functions (Vercel), our database, authentication, and file storage (Supabase), and our transactional email delivery (Amazon Web Services – Simple Email Service) are hosted in Canada. Certain providers process limited data outside Canada:
- Stripe (payments — United States),
- Vercel edge routing and content delivery (global)
- Sentry (error monitoring — European Union, configured to exclude personal information and IP addresses),
- Cloudflare (edge security — global), and
- Google Workspace (business email — United States/global).
Where personal information is processed outside Canada, it may be accessible to foreign authorities under the laws of those jurisdictions. As described in Section 7, we use contractual and technical safeguards intended to provide a comparable level of protection.
9. Data retention
We keep personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law, after which we delete or anonymize it.
10. How we protect information
We use the following methods to protect your privacy:
- technical and organizational safeguards, including encryption in transit (HTTPS),
- database row-level security, mandatory two-factor authentication for administrators,
- restricted administrative access,
- audit logging of administrative actions,
- edge firewall and rate-limiting,
- and error monitoring configured to scrub personal information and IP addresses.
Please note that although we take reasonable steps to protect your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your rights
You may exercise the following rights with respect to your personal information, subject to applicable Canadian privacy legislation:
- access to, correction of, or deletion of your personal information;
- withdraw consent; and
- lodge a complaint with your privacy regulator (for example, the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, or an EU/UK authority).
To exercise any of these rights, please make a written request to our Privacy Officer Connor Walsh at connor@ethical-use.com.
12. The public certificate registry
For anyone to verify an issued certification, our public registry lists currently valid certifications and displays a limited set of information: the holder’s name; the organization, where the certificate identifies one; the certification level; its status; the issue and expiry dates; and the public certificate identifier. A Level 2 certificate names an organization only where the holder chose one at the point of purchase. Expired or revoked certifications are not listed.
13. Minors
Our services are directed to organizations and professionals and are not intended for use by minors. If we become aware that we unknowingly collected personal information from a minor, we will take reasonable steps to redact such information.
14. Changes to this statement
We may modify this Privacy Policy at any time from time to time and will post the updated version on our website. Where applicable, we will change the effective date and, where appropriate, provide additional notice.
Please note that the Privacy Policy posted at any time or from time to time on our website shall be the Privacy Policy then in effect.
15. Canada’s Anti-Spam Legislation (CASL)
This policy follows Canada’s Anti-Spam Legislation (“CASL”). CASL is intended to protect consumers from the misuse of digital technology, including spam. In all communications, we provide clear instructions on how to subscribe, and unsubscribe, where applicable, if an individual no longer wishes to receive future e-mails from us, at no cost to you.
16. Contact us
Please contact our Privacy Officer Connor Walsh at connor@ethical-use.com for any questions or concerns.
