Privacy & Data Protection

Privacy Policy

Council Safety of Artificial Intelligence (CSOAI)

Version 1.0
Last Updated: January 2026

1. Introduction

Council Safety of Artificial Intelligence ("CSOAI," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (csoai.org), use our services, or interact with us.

Data Controller

Council Safety of Artificial Intelligence
United Kingdom
Email: [email protected]

2. Information We Collect

Information You Provide

Account & Membership

  • • Name and contact details
  • • Organization name and role
  • • Professional background
  • • Payment information

Communications

  • • Emails and messages
  • • Feedback and surveys
  • • Meeting notes

Compliance Information

  • • AI system documentation
  • • Assessment results
  • • Incident reports

Collected Automatically

Technical Data

  • • IP address
  • • Browser type and version
  • • Device information
  • • Pages visited and time spent
  • • Referring website

Cookies

  • • Essential (required for site)
  • • Analytics (with consent)

3. How We Use Your Information

PurposeLegal Basis (GDPR)
Provide membership services
Contract performance
Process certifications
Contract performance
Send service communications
Legitimate interest
Improve our services
Legitimate interest
Comply with legal obligations
Legal obligation
Send marketing (with consent)
Consent
Maintain safety and security
Legitimate interest

We do NOT:

  • • Sell your personal data
  • • Share data with third parties for their marketing
  • • Use automated decision-making without human review
  • • Process sensitive data without explicit consent

4. Data Sharing

We may share your information with:

Service Providers

  • • Cloud hosting (UK/EU)
  • • Payment processors
  • • Email services
  • • Analytics providers

Legal Requirements

  • • Regulatory authorities
  • • Law enforcement
  • • Courts in proceedings

With Your Consent

  • • Public acknowledgment
  • • Case studies
  • • Testimonials

International Transfers

If data is transferred outside the UK/EU, we ensure appropriate safeguards: Standard Contractual Clauses, Adequacy decisions, or Binding Corporate Rules.

5. Data Retention

Membership records
Duration + 7 years
Certification records
10 years after expiry
Financial records
7 years (legal)
Communications
3 years
Website analytics
26 months
Marketing consent
Until withdrawn + 1 year

After retention periods, data is securely deleted or anonymized.

6. Your Rights (GDPR)

Access

Request a copy of your personal data

Rectification

Correct inaccurate data

Erasure

Request deletion ("right to be forgotten")

Restriction

Limit how we process your data

Portability

Receive your data in a portable format

Objection

Object to processing based on legitimate interests

Withdraw Consent

Where processing is based on consent

How to Exercise Your Rights

Email: [email protected]

We will respond within 30 days. We may request identification to verify your identity.

Right to Complain

You may lodge a complaint with the Information Commissioner's Office (ICO)
Website: ico.org.uk | Phone: 0303 123 1113

7. Security

We protect your data through:

Encryption in transit (TLS/SSL)
Encryption at rest
Access controls
Regular security assessments
Staff training
Incident response procedures

Data Breach Notification

In the event of a breach affecting your rights: We will notify the ICO within 72 hours (where required) and notify you directly if high risk to your rights.

8. Cookies

Essential Cookies

  • • Session management
  • • Security
No consent required

Analytics Cookies

  • • Usage patterns
  • • Site improvement
Consent required

Marketing Cookies

  • • Not currently used
  • • Would require consent

You can control cookies through our cookie consent banner, browser settings, or opt-out links.

9. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified by email (for members) and website notice. Continued use constitutes acceptance.

Contact Us

For privacy inquiries, contact our Data Protection Lead:

Nicholas Templeman

Council Safety of Artificial Intelligence

[email protected]

12. Additional Information for Specific Regions

UK GDPR

This policy complies with UK GDPR (retained EU law).

EU GDPR

For EU residents, your data controller is CSOAI, operating under UK adequacy arrangements.

California (CCPA)

California residents have additional rights. Contact us for CCPA-specific disclosures.

© 2026 Council Safety of Artificial Intelligence. All Rights Reserved.