Privacy Notice
Effective Date: 1 February 2026
1. Introduction
The AI Assurance Limited (IT Governance.com) is committed to protecting your privacy and ensuring that your personal data is processed lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 (�GDPR�), as well as any applicable national data protection legislation.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you interact with our website (itgovernance.com), register for training or certification programmes, download resources, subscribe to communications, or engage our services related to AI governance, EU AI Act compliance, ISO/IEC 42001, and enterprise IT governance.
2. Data Controller
The data controller responsible for your personal data is:
AI Assurance Limited2 Buckingham Terrace
Glasgow G12 8EB
Email: info@aiassurance.Institute
Telephone: +44 7899 960882
We have an appointed Data Protection Officer who can be contacted at the above email address.
3. Personal Data We Collect
We collect the following categories of personal data:
- Identity and contact information (name, email address, telephone number, job title, organisation name)
- Any information you voluntarily provide in forms, emails, training registrations, or certification applications
4. How We Collect Your Data
We obtain personal data:
- Directly from you (via website forms, email correspondence, event/training registrations, downloads)
5. Purposes and Legal Bases for Processing
We process personal data for the following purposes on the legal bases indicated:
| Purpose | Legal Basis (GDPR Article 6) |
|---|---|
| Delivering services, training, certification, resources, and support | Performance of a contract (b) or legitimate interests (f) |
| Responding to enquiries, providing quotations, and customer support | Legitimate interests (f) |
| Sending informational updates, newsletters, and invitations (EU AI Act, ISO 42001, governance topics) | Consent (a) or legitimate interests (f) |
| Improving website functionality, security, and user experience | Legitimate interests (f) |
| Complying with legal and regulatory obligations (e.g., accounting, tax, certification records) | Legal obligation (c) |
6. Sharing of Personal Data
We may share personal data with:
- Competent authorities or regulators where legally required
International transfers outside the EEA do not occur.
7. Data Retention
We retain personal data only for as long as necessary:
- Contractual/service data: duration of relationship + up to 6 years (statute of limitations)
8. Your Rights Under the GDPR
You have the following rights regarding your personal data:
- Right of access, rectification, and erasure
- Right to restriction of processing
- Right to object (including to direct marketing)
- Right to data portability
- Right to withdraw consent at any time (where processing is based on consent)
- Right to lodge a complaint with a supervisory authority (e.g., your national Data Protection Authority or the Information Commissioner�s Office)
To exercise these rights, please contact us at info@itgovernance.com.
9. Cookies and Tracking Technologies
We only use cookies and similar technologies to enhance the functioning of this website.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration.
11. Changes to This Notice
We may update this Privacy Notice from time to time. The revised version will be posted here with an updated effective date. We encourage you to review it periodically.
12. Contact Us
For any questions, concerns, or to exercise your rights, please contact:
Email: info@itgovernance.comTelephone: +44 7899 960882