Privacy Policy
This Privacy Policy explains how The Institute of Applied CX Science (IACS) ("we", "us", "our") collects, uses, stores, and protects personal data when you interact with our platform, services, and institutional programmes. We are committed to handling your information with the highest standards of transparency and security.
This policy applies to all individuals who access our platform, apply for certification, engage with our research library, or otherwise interact with IACS services. By using our platform, you acknowledge that you have read and understood this policy.
1. Data Controller
The Institute of Applied CX Science acts as the Data Controller for all personal data collected through this platform. Our registered address is 34–35 Hatton Garden, London, United Kingdom. For all data-related enquiries, contact us at chairman@appliedcxscience.com.
2. Data We Collect
We collect and process the following categories of personal data:
- Identity Data: Full name, professional title, organisation, and biography provided during registration or certification applications.
- Contact Data: Email address, telephone number, and business address.
- Account Data: Login credentials, account preferences, and settings.
- Professional Data: Certification records, credential identifiers, audit history, and research access logs.
- Technical Data: IP address, browser type and version, device identifiers, page views, session duration, and referring URLs collected automatically via cookies and server logs.
- Usage Data: Information about how you interact with our platform, including research papers accessed, certifications applied for, and verification requests submitted.
- Communications Data: Records of correspondence you have with us, including support enquiries and application submissions.
3. Legal Basis for Processing
We process your personal data under the following lawful bases:
- Contractual Necessity: Processing required to deliver certification programmes, audit services, and member access in accordance with our institutional terms.
- Legitimate Interests: Processing necessary for platform security, fraud prevention, research integrity, and institutional governance operations.
- Legal Obligation: Processing required to comply with applicable UK and EU legislation, including anti-fraud and record-keeping obligations.
- Consent: Where you have explicitly opted in to marketing communications or voluntary profiling features.
4. How We Use Your Data
Your personal data is used to:
- Create and manage your IACS member account and professional profile.
- Process certification applications, award credentials, and maintain your verification record.
- Deliver research library access, continuing professional development content, and institutional publications.
- Conduct corporate audits and governance assessments as engaged by your organisation.
- Communicate with you regarding your account, applications, and relevant institutional updates.
- Ensure platform security, detect abuse, and prevent fraudulent activity.
- Fulfil our legal, regulatory, and contractual obligations.
- Analyse aggregated usage patterns to improve our platform and services (data used in anonymised form only).
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your information with:
- Service Providers: Third-party processors acting under strict data processing agreements, including hosting providers, payment processors, and email delivery platforms.
- Verifying Organisations: Employers, institutions, or authorised parties who submit a formal credential verification request referencing your unique IACS identifier. You will be notified of any verification.
- Regulatory Authorities: Where required by law, court order, or regulatory directive.
- Professional Governance Bodies: Where relevant to the validation of a certification or audit engagement under an institutional agreement.
All third-party sharing is governed by contractual safeguards consistent with UK GDPR Article 28 requirements.
6. International Transfers
IACS operates primarily within the United Kingdom. Where data is processed outside the UK or European Economic Area, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO), or adequacy decisions where applicable.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Member account data: Retained for the duration of your membership and for 7 years following closure, in accordance with financial and governance record-keeping obligations.
- Certification records: Retained indefinitely as part of the permanent institutional credential registry, subject to your right to erasure where legally permissible.
- Audit records: Retained for 10 years in accordance with professional standards for corporate governance documentation.
- Technical and usage data: Retained for up to 24 months for security and analytical purposes, then anonymised or deleted.
8. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data where there is no legitimate reason for continued processing.
- Right to Restriction: Request that we limit the processing of your data in certain circumstances.
- Right to Portability: Receive your data in a structured, machine-readable format and transfer it to another controller.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Rights related to Automated Decision-Making: Request human review of any solely automated decisions that significantly affect you.
To exercise any of these rights, submit a written request to chairman@appliedcxscience.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Security Measures
IACS implements industry-standard technical and organisational security measures to protect your personal data, including encrypted transmission (TLS), secure credential storage, access controls, regular security audits, and staff data protection training. While no system can guarantee absolute security, we maintain a rigorous posture consistent with our institutional governance standards.
10. Cookies
We use cookies and similar technologies to operate this platform. For full details of the cookies we use and how to control them, please refer to our Cookie Policy.
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in legislation, technology, or our services. All material changes will be communicated to registered members by email and published on this page with an updated version number and effective date. Continued use of our platform following notification of changes constitutes acceptance of the revised policy.
12. Contact
For all privacy-related enquiries, please contact the IACS Data Governance team at chairman@appliedcxscience.com or write to us at 34–35 Hatton Garden, London, United Kingdom.