Skip to main content

Privacy policy

Privacy Policy

RAIUC respects your privacy and is committed to protecting personal information.

On this page

About this policy

Last updated: 28 July 2026

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit RAIUC.org; apply for or renew certification; search for or verify a certificate; create or use a member account; submit a contact form, message or attachment; access resources or news content; subscribe to communications, where offered; or otherwise communicate or interact with RAIUC.

This policy is intended to provide transparent information to users internationally. It reflects the principles of applicable privacy laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR) and applicable United States state privacy laws.

Not every law mentioned in this policy will apply in every situation. Your rights depend on your location, your relationship with RAIUC and the applicable law.

1. Who we are and the data controller

RAIUC.org is the website of the Responsible AI Use Campaign, an independent, not-for-profit initiative that helps organisations use artificial intelligence safely, fairly, transparently and accountably.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC231212.

The data controller responsible for personal information processed through RAIUC.org is:

Data Protection Officer

RAIUC.org

2 Prospect Road, G68 0AN

Scotland, UK

Email: privacy@raiuc.org

The data controller determines why and how personal information is processed.

2. Scope of this policy

This policy does not govern independent third-party websites, services or platforms linked from RAIUC.org. Those providers operate under their own terms and privacy policies.

  • The RAIUC website
  • Certification applications and renewals
  • Public certificate-verification records
  • Member registration and account services
  • Contact and enquiry forms
  • Uploaded attachments
  • Optional surveys and self-assessments
  • Website analytics and security systems
  • Email communications
  • Related administrative activities

3.1 Organisation and certification information

When an organisation applies for certification, we may collect the following information. Information identifying a company is not always personal information, but it may be personal information where it identifies a sole trader, partnership, employee or other identifiable individual.

  • Organisation or company name
  • Selected department or organisation-wide designation
  • Industry or sector
  • Business address, town or city, region, state or county, country, and postcode or ZIP code
  • Organisation email address
  • Certification application details
  • Confirmation of agreement to the RAIUC commitments
  • Certificate number, issue and expiry dates, and status
  • Renewal history
  • Other information required to administer certification

3.2 Applicant and contact information

  • Title, first name and last name
  • Job title or role, where requested
  • Email address and telephone number, where provided
  • Organisation name
  • Messages, enquiries and feedback
  • Correspondence history
  • Information voluntarily provided in attachments

3.3 Member-account information

Passwords are managed by our authentication provider. RAIUC does not store passwords in readable form.

  • Account email address
  • Supabase account identifier
  • Linked certificate number, organisation and department
  • Account-creation date and time
  • Email-confirmation status
  • Last sign-in information and account status
  • Password-reset requests
  • Session and authentication information
  • Security and login records

3.4 Optional organisational responses

Certification applications may include optional questions about organisational AI use. These answers are private administrative information unless we explicitly state otherwise. They may be analysed in aggregated or anonymised form to understand responsible AI practices and improve RAIUC resources.

  • Whether the organisation has an AI policy
  • Whether controls prevent confidential information being used for AI training
  • Whether staff receive AI training
  • AI tools used and departments using AI
  • Organisational approaches to privacy, hallucinations and bias
  • Other voluntary responsible AI responses

3.5 Contact messages and attachments

Please do not send sensitive or confidential information unless it is necessary for your enquiry.

  • Name, email address and telephone number
  • Organisation and reason for contacting us
  • Certificate number, where relevant
  • Message content
  • Attachment filename, type, size and contents
  • Date and time submitted
  • Delivery and message status

3.6 Technical and usage information

  • IP address
  • Browser type and version
  • Device type and operating system
  • User-agent information
  • Approximate geographic location derived from an IP address
  • Pages viewed and referring page or website
  • Date and time of access
  • Navigation and interaction information
  • Form-submission records
  • Error and diagnostic information
  • Cookie and consent preferences
  • Security, rate-limiting and anti-abuse information

3.7 Analytics information

Where optional analytics have been accepted, we may collect information about website visits, pages viewed, navigation paths, session duration, interaction patterns, device and browser characteristics, referral sources, technical performance and website errors. Depending on your consent choices, analytics services may include Google Analytics 4 and Microsoft Clarity.

3.8 Live website activity

When optional analytics consent has been given, RAIUC may show an authorised administrator an anonymous live view of current website activity. This may include the page being viewed, entry page, country, browser category, device category, general traffic-source category, session duration and last activity time.

  • IP addresses are not stored in the live-session record.
  • URL query strings and fragments are removed.
  • The temporary record expires automatically after approximately 90 seconds without a browser heartbeat.
  • Live-session records are not retained as visitor history and are not included in reports or exports.
  • RAIUC administrators and recognised automated traffic are excluded where technically possible.

4. Information we do not intentionally request

RAIUC does not normally require special-category or sensitive personal information. Please do not include this information in forms, messages or attachments unless it is genuinely necessary and you have a lawful basis for providing it.

If sensitive information is submitted, we will process it only where reasonably necessary and legally permitted.

  • Health information
  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade-union membership
  • Genetic or biometric information
  • Sexual orientation or sex life
  • Criminal convictions and offences

5. Sources of personal information

If you provide information about another person, you should ensure that you are authorised to do so and that the individual has been given appropriate privacy information.

  • Directly from you
  • From an organisation applying for certification
  • From an authorised representative of an organisation
  • Through member registration and authentication
  • From correspondence and attachments
  • Automatically through website use
  • From analytics and security providers
  • From existing certification records
  • From publicly available sources where verification is necessary
  • From service providers helping us operate the website

6. Public certificate information

RAIUC certification is intended to be publicly verifiable. We may retain a limited public record of expired, suspended, revoked or replaced certificates where necessary to preserve the integrity of verification records and prevent misleading certification claims.

  • Public information may include: organisation or company name; selected department or organisation-wide designation; certificate number; issue date; expiry date; certificate status; certification or renewal status
  • Information not intended to appear publicly includes: applicant name; personal email address; telephone number; postal address; postcode or ZIP code; IP address; browser or device information; authentication information; optional survey answers; contact messages; attachments; internal security or administration records

7. How and why we use personal information

We will not use personal information for a materially incompatible purpose without providing appropriate notice and, where required, obtaining consent.

  • Operate and maintain RAIUC.org
  • Receive and assess certification applications
  • Issue, display and verify certificates
  • Administer renewals and certificate history
  • Create and manage member accounts
  • Confirm email addresses and process sign-ins, logouts and password resets
  • Provide certification marks and resources
  • Respond to enquiries and complaints
  • Receive and manage attachments
  • Send requested administrative communications
  • Maintain accurate records
  • Analyse optional responses in aggregated or anonymised form
  • Improve website content, usability and performance
  • Detect and prevent spam, fraud, misuse and security incidents
  • Enforce RAIUC terms, commitments and policies
  • Protect RAIUC, its users and the public
  • Establish, exercise or defend legal claims
  • Comply with legal and regulatory obligations
  • Manage a restructuring or transfer of the RAIUC initiative, if one occurs

8. Lawful bases for processing

Where UK or EU data-protection law applies, we rely on one or more of the following lawful bases.

Contract or steps before entering a contract: processing a requested certification, administering an account, providing requested resources or services, responding to service requests, and performing certification-related obligations.

Legitimate interests: operating RAIUC, maintaining verification records, preventing fraudulent certificate use, securing the website and databases, responding to enquiries, improving services, understanding use, protecting legal rights and managing the initiative. We consider whether these interests are overridden by your rights and reasonable expectations.

Consent: optional analytics, marketing communications, voluntary surveys, optional website features and other processing where consent is requested. You may withdraw consent at any time without affecting earlier lawful processing.

Legal obligation: complying with applicable laws, lawful regulatory, court or law-enforcement requests, legally required records, and legal security or breach-reporting duties.

Legal claims: establishing, exercising or defending legal claims.

Vital interests would be used only in exceptional circumstances recognised by applicable law.

9. Certification decisions and automated processing

Certain technical stages may occur automatically, including checking required fields, confirming acceptance of the commitments, generating certificate numbers and records, calculating validity periods, producing downloadable certificates, linking accounts and applying anti-spam checks.

RAIUC does not intentionally use solely automated decision-making or profiling that produces legal or similarly significant effects on individuals.

RAIUC certification records an organisation’s declaration to follow the 10 Responsible AI Commitments. It is not an independent audit, statutory approval, legal accreditation or regulatory determination.

10. Cookies and similar technologies

RAIUC.org may use cookies, local storage, pixels, tags, scripts and similar technologies.

Strictly necessary technologies may be used without consent where legally permitted to operate and secure the website, record cookie choices, support forms, maintain authentication sessions, prevent misuse and provide essential functionality.

Where required by law, optional analytics will be used only after consent. They help us understand navigation, useful pages, errors, performance, content and accessibility.

You may accept, reject or manage optional cookies through the website’s cookie controls. Further information is available in the RAIUC Cookie Policy.

11. Google reCAPTCHA and anti-abuse protection

RAIUC uses Google reCAPTCHA v2 on the Contact Us form, the Advertising enquiry form and when a new certificate application is issued. It helps distinguish genuine users from automated or abusive activity and protects the website, its forms and its users.

When reCAPTCHA is loaded or used, Google may receive and process information including your IP address, browser and device information, referring page, date and time, interaction information, cookies or similar identifiers, security signals and the result of the reCAPTCHA check. Google processes this information to provide, maintain and improve reCAPTCHA and for security and abuse prevention in accordance with its terms and privacy documentation.

Where UK or EU data-protection law applies, RAIUC relies on its legitimate interests in securing the website, preventing spam, fraud and misuse, and protecting users and certification records. reCAPTCHA is treated as a necessary security service rather than optional analytics or advertising. Google may process information outside the United Kingdom or European Economic Area using applicable safeguards.

Google’s Privacy Policy is available at https://policies.google.com/privacy and Google’s Terms of Service at https://policies.google.com/terms. If you cannot complete the security check, contact privacy@raiuc.org for an accessible alternative. RAIUC also retains honeypot fields, submission limits, validation checks and security logging as additional safeguards.

12. Marketing and service communications

If marketing subscriptions are offered and you subscribe, we may send responsible AI guidance, RAIUC resources, certification information, events, training, news and related updates. Where required, marketing will be sent only with consent or another valid lawful basis.

You may unsubscribe using the facility in the message or by contacting privacy@raiuc.org.

We may continue sending necessary non-marketing communications, including certificate and renewal notices, account confirmations, password resets, security alerts, enquiry responses, policy notices and important service information.

13. When we share personal information

RAIUC does not sell personal information. We may share information with service providers where reasonably necessary to operate the website and services. Providers may process information only for the relevant service and subject to contractual and legal obligations.

We may disclose information when required by law; in response to lawful authorities; to investigate fraud, misuse or security incidents; to protect rights, safety or property; for legal claims; or in connection with a restructuring, merger, transfer or sale of the initiative.

We do not intentionally share personal information for cross-context behavioural advertising.

  • Website hosting, cloud infrastructure and Cloudflare security
  • Website and database services
  • Supabase account authentication
  • Resend transactional email delivery
  • 123 Reg business email
  • Google Analytics
  • Microsoft Clarity
  • Google reCAPTCHA security and anti-abuse protection
  • File and attachment storage
  • Technical support
  • Legal, accounting or professional advice
  • Security and incident response

14. International transfers

RAIUC is administered from the United Kingdom and uses service providers that may process information in the United Kingdom, European Economic Area, United States or other countries. Some destinations may have different privacy laws.

Where UK or EU law requires safeguards, we will use an appropriate mechanism where applicable, such as an adequacy regulation or decision, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, EU Standard Contractual Clauses, a recognised privacy framework, contractual and technical safeguards, or another permitted mechanism.

We take reasonable steps to select reputable providers and limit information to what is needed.

15. Data retention

We retain personal information only for as long as reasonably necessary. Retention depends on the nature and sensitivity of the information; its purpose; certificate validity and renewal history; account status; security and fraud-prevention needs; limitation periods; regulatory requirements; complaints or disputes; and whether information can be anonymised.

Contact messages and attachments are retained for a reasonable follow-up and administration period. Active account information is retained while the account remains operational. Authentication and security records follow security requirements and provider settings. Certification records may be retained after expiry to maintain verification history and prevent fraud. Optional responses may be retained for analysis or anonymised. Analytics follows provider settings. Legal, complaint or security records may be retained longer where necessary.

When information is no longer required, we will delete it, anonymise it or restrict its use until secure deletion is possible. Backups may retain deleted information temporarily until overwritten through normal backup cycles.

16. Data security

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, misuse, alteration, unauthorised disclosure, destruction and other unlawful processing.

Measures may include encrypted connections, access controls, private administration, secure authentication, password hashing by the authentication provider, restricted database access, logging, monitoring, submission limits, anti-spam controls, software maintenance, backups, provider security controls and incident-response procedures.

Only people and providers with an appropriate operational need should have access to private records. No internet or storage system can be guaranteed completely secure. If you believe your information or account has been compromised, contact privacy@raiuc.org promptly. Security vulnerabilities should be reported to security@raiuc.org.

17. Your UK and European privacy rights

Where UK or EU law applies, you may have rights to be informed; access your information; correct inaccurate or incomplete information; request deletion or restriction; object to legitimate-interest processing or direct marketing; withdraw consent; request portability; receive information about automated decisions; complain to a supervisory authority; and seek a judicial remedy.

These rights are not absolute. We may retain or process information to preserve certificate-verification integrity, prevent fraud, comply with law, protect legal rights or handle legal claims.

To exercise a right, contact privacy@raiuc.org. We may request information necessary to confirm your identity and authority and will respond within the legally required period.

UK complaints

Individuals in the United Kingdom may complain to the Information Commissioner’s Office:

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom

Website: https://ico.org.uk/

Telephone – +44 (0)303 123 1113 (local rate) or +44 (0)1625 545 745

Website – https://ico.org.uk/concerns

We would appreciate an opportunity to address your concern first, although you are not required to contact us before approaching the regulator.

EU and EEA complaints

Individuals in the European Union or European Economic Area may complain to the data-protection supervisory authority in the country where they live, work or believe an infringement occurred.

18. United States privacy rights

Privacy rights differ between states. Depending on applicable law, you may have rights to confirm processing; access, correct or delete information; obtain a portable copy; opt out of sale, targeted advertising or certain profiling; limit certain sensitive-information uses; use an authorised agent; appeal a decision; and receive services without unlawful discrimination.

RAIUC does not sell personal information and does not intentionally use personal information for cross-context behavioural advertising.

To make a request, contact privacy@raiuc.org and identify your state of residence. We may verify your identity. Where an appeal right applies, you may appeal a refusal by replying to our decision and stating that you wish to appeal.

19. California privacy notice

This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), applies to RAIUC.

Information categories may include identifiers, contact details, internet activity, professional information, organisation and certification information, account and authentication information, correspondence, uploaded content and inferences based on voluntary organisational responses. Sources, purposes and recipients are described throughout this policy.

Subject to applicable exemptions, California residents may have rights to know the categories and specific pieces collected; know sources, purposes and recipient categories; request correction or deletion; opt out of sale or sharing; limit certain sensitive-information uses; and be free from unlawful discrimination.

RAIUC does not sell personal information, intentionally share it for cross-context behavioural advertising, or use sensitive information to infer characteristics. Where RAIUC is not legally subject to the CCPA, we may still consider reasonable requests voluntarily, but this does not mean the CCPA applies.

20. Children’s privacy

RAIUC.org is intended for organisations, professionals and adults interested in responsible AI. It is not directed to children under 13, and we do not knowingly collect their personal information online.

Certification applications and member accounts should be submitted or created only by adults or appropriately authorised organisational representatives.

If you are a parent or guardian and believe a child has provided information, contact privacy@raiuc.org. We will investigate and take appropriate action. Where another jurisdiction provides a higher minimum age, we will apply it where applicable.

22. Your responsibilities

  • Provide accurate information
  • Keep account credentials confidential
  • Tell us if account or certification information changes
  • Ensure you are authorised to submit information for an organisation
  • Avoid unnecessary sensitive information in messages or attachments
  • Notify us promptly of suspected unauthorised account use

23. Changes to this Privacy Policy

We may update this policy for changes in law, services, website functionality, service providers, security or analytics tools, certification processes or processing practices.

The updated policy will be published on this page with a revised date. Where required by law, we will provide additional notice or request fresh consent for material changes.

24. Contact us

For privacy questions, concerns, complaints or requests, contact:

Data Protection Officer RAIUC.org 2 Prospect Road, G68 0AN Scotland, UK

Email: privacy@raiuc.org

Please include enough information for us to understand your request. Do not send passwords or unnecessary sensitive information by email. We may need to verify your identity before disclosing, correcting or deleting personal information.

  • Next review due: 28 July 2027