Skip to content
IEU: The Institute for Ethical Use

Last updated 30 July 2026

IEU — Privacy Policy

1. About Us

The Institute for Ethical Use (“IEU,” “we,” “us”) operates the website at ethical-use.com and the IEU three-tier AI-ethics certification program. This statement explains how we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), and where applicable, provincial privacy legislation, such as the Act respecting the Protection of Personal Information in the Private Sector (“Quebec’s Privacy Act”) and foreign legislation such as EU or UK General Data Protection Regulation (“GDPR”).

IEU is committed to respecting and protecting the privacy rights of individuals. We are committed to maintaining the accuracy, confidentiality, and security of personal data in our custody. This commitment is reflected in our internal policies, safeguards and practices to ensure compliance with the relevant laws and regulations noted in the preceding paragraph. We adhere to maintaining the highest standard of quality, transparency, and accountability by developing policies and procedures about the collection, use, disclosure of information that align with federal, provincial, and industry standards.

For more information, please contact our Privacy Officer Connor Walsh at connor@ethical-use.com

2. Scope

This statement applies to personal information we collect through our website, the Level 1 self-assessment, Level 2 training and certification, Level 3 organizational assessments, and related communications.

3. Information we collect

IEU complies with all applicable provisions of privacy legislation in Canada. We have implemented PIPEDA, and where applicable, Quebec’s Privacy Act, and the EU or UK GDPR, which set the ground rules for how private-sector organizations collect, use, and disclose personal information during the course of commercial activity.

This Privacy Policy applies to information we collect that you provide us with, including:

  • Assessment responses and company profile: your answers to the Level 1 self-assessment along with the profile details you provided (i.e. industry/sector, organization size, country, and your role/job title).
  • Work-email verification: to begin the Level 1 assessment, we ask for a work email address and verify it with a one-time code. Please note that free webmail addresses are not accepted, as the assessment is completed on behalf of an organization.
  • Authorization attestation: your name and an attestation that you are authorized to complete the assessment on behalf of your organization. We log the attestation, the date and time, and the IP address from which it was given, as proof of that authorization.
  • Contact details: your name and work email, which you provided in order to receive your results or to hear from us.
  • Account information: for Level 2, your name and email (authentication is handled by our identity provider), along with your training progress and exam attempts.
  • Payment information: this is handled by our payment processor. We do not store full payment-card numbers on our servers.
  • Inquiries: information you submit through our “Talk to us” or contact forms.

Information collected automatically

We collect information through:

  • Cookieless, aggregate website analytics (i.e., page views, approximate visits, and referrers). We do not use advertising cookies and do not use Google Analytics.
  • Marketing-attribution parameters (UTM tags) associated with a visit.
  • Limited technical and security information necessary to operate and protect the site (i.e., IP addresses processed at our security/edge layer for rate-limiting and abuse prevention).

4. How we use your information

We use personal information to:

  • deliver and score the assessment;
  • verify that a user is authorized to act for their organization and prevent abuse;
  • provide training and issue and verify certifications;
  • respond to your inquiries;
  • send follow-up or marketing communications where you have consented;
  • understand, in aggregate, which industries engage with us;
  • operate, secure, and improve the service; and
  • comply with legal obligations.

5. Legal bases for processing

Depending on where you are located, we rely on your consent, the performance of a contract with you, and/or our legitimate interests.

6. Marketing and consent

We only send follow-up and marketing communications where you have given express consent, which is obtained solely through an opt-in mechanism (i.e., you can check off your consent in the blank box). You may withdraw your consent at any time, and at no cost to you, using the unsubscribe link in our emails or by contacting us at connor@ethical-use.com We take such requests seriously and your request is processed without delay and will be in effect within ten (10) business days after your request has been made.

7. Service providers and sub-processors

We do not sell your personal information to third parties. We share it with service providers who process it on our behalf under contract (and data-processing agreements where applicable) only where necessary for the purposes specified in this Privacy Policy. Before transferring personal information outside of Canada, we conduct an assessment to confirm that the service provides have the appropriate level of security in place and in accordance with Canadian privacy legislation and enter into contractual safeguards requiring the provider to maintain that protection.

A list of our current sub-processors is set forth below:

ProviderPurposePersonal data handledProcessing location
Vercel, Inc.Application functions – server-rendering, server actions and route handlersRequest content and session data processed when service a page or actionCanada — Montreal (yul1) region
Vercel, IncEdge routing and content delivery – request routing, static assets, TLS terminationRequest metadata and the session cookie, read in order to route the requestGlobal edge network
SupabasePrimary database, authentication, and file storageAccounts, assessment responses & company profiles, enrollments, training progress, exam attempts, certificates, audit logsCanada — Central (ca-central-1) region
Stripe, Inc.Payment processing (Level 2 checkout, invoicing)Billing name/email and payment-card data — card data is handled entirely by Stripe and never stored on our serversUnited States
Amazon Web Services, Inc. – Simple Email Service (SES)Transactional email delivery (verification codes, receipts, results summaries, certificate notices)Recipient email address and message contentsCanada – Central (ca-central-1) region
Sentry (Functional Software, Inc.)Application error and performance monitoringTechnical diagnostic/error data only — configured to scrub personal information and strip IP addresses before transmission, so personal information is not intended to reach this providerEuropean Union — Germany (Frankfurt) region
Cloudflare, Inc.DNS, DDoS protection, web application firewall, edge rate-limitingNetwork-level data (including IP addresses) processed at the edge to route and secure trafficGlobal edge network
Cloudflare, Inc. – Web AnalyticsAggregate, cookieless traffic analyticsAggregate page views, referrers, and campaign (UTM) parameters — no advertising cookies, no cross-site tracking, no Google AnalyticsGlobal edge network
Google Workspace (Google LLC)Business email hosting for @ethical-use.com (receiving inquiries; sending-domain authentication)Email correspondence you send us (e.g. via ‘Talk to us’ / contact)United States / global

Please note that we may also disclose information where required by law or to protect our rights. This list may be updated from time-to-time and will be provided upon request

8. Where your data is stored (data residency)

Our primary application functions (Vercel), our database, authentication, and file storage (Supabase), and our transactional email delivery (Amazon Web Services – Simple Email Service) are hosted in Canada. Certain providers process limited data outside Canada:

  • Stripe (payments — United States),
  • Vercel edge routing and content delivery (global)
  • Sentry (error monitoring — European Union, configured to exclude personal information and IP addresses),
  • Cloudflare (edge security — global), and
  • Google Workspace (business email — United States/global).

Where personal information is processed outside Canada, it may be accessible to foreign authorities under the laws of those jurisdictions. As described in Section 7, we use contractual and technical safeguards intended to provide a comparable level of protection.

9. Data retention

We keep personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law, after which we delete or anonymize it.

10. How we protect information

We use the following methods to protect your privacy:

  • technical and organizational safeguards, including encryption in transit (HTTPS),
  • database row-level security, mandatory two-factor authentication for administrators,
  • restricted administrative access,
  • audit logging of administrative actions,
  • edge firewall and rate-limiting,
  • and error monitoring configured to scrub personal information and IP addresses.

Please note that although we take reasonable steps to protect your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your rights

You may exercise the following rights with respect to your personal information, subject to applicable Canadian privacy legislation:

  • access to, correction of, or deletion of your personal information;
  • withdraw consent; and
  • lodge a complaint with your privacy regulator (for example, the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, or an EU/UK authority).

To exercise any of these rights, please make a written request to our Privacy Officer Connor Walsh at connor@ethical-use.com.

12. The public certificate registry

For anyone to verify an issued certification, our public registry lists currently valid certifications and displays a limited set of information: the holder’s name; the organization, where the certificate identifies one; the certification level; its status; the issue and expiry dates; and the public certificate identifier. A Level 2 certificate names an organization only where the holder chose one at the point of purchase. Expired or revoked certifications are not listed.

13. Minors

Our services are directed to organizations and professionals and are not intended for use by minors. If we become aware that we unknowingly collected personal information from a minor, we will take reasonable steps to redact such information.

14. Changes to this statement

We may modify this Privacy Policy at any time from time to time and will post the updated version on our website. Where applicable, we will change the effective date and, where appropriate, provide additional notice.

Please note that the Privacy Policy posted at any time or from time to time on our website shall be the Privacy Policy then in effect.

15. Canada’s Anti-Spam Legislation (CASL)

This policy follows Canada’s Anti-Spam Legislation (“CASL”). CASL is intended to protect consumers from the misuse of digital technology, including spam. In all communications, we provide clear instructions on how to subscribe, and unsubscribe, where applicable, if an individual no longer wishes to receive future e-mails from us, at no cost to you.

16. Contact us

Please contact our Privacy Officer Connor Walsh at connor@ethical-use.com for any questions or concerns.