AIGR · Institutional AI governance

Privacy Policy

EvidenceReviewDecision

Legal · Privacy

How AIGR handles information.

This Privacy Policy describes how the AIGR website and related governance assessment, ratings and assurance workflows may collect, use, disclose and protect personal information. AIGR refers to the Artificial Intelligence Governance Ratings brand and the site operator providing the applicable website or service.

01 · Who we are

AIGR provides an evidence-based framework for artificial intelligence governance assessment, ratings and assurance. Where a specific legal entity is identified in an engagement agreement, order form or other commercial document, that entity is the contracting party and is responsible for information processed under that engagement.

02 · Scope

This policy applies to personal information collected through the public AIGR website, enquiry forms, business communications, account administration and AIGR assessment or ratings workflows where the site operator acts as the organization responsible for that information. Where AIGR processes information only on a client’s documented instructions, the client’s privacy notice and the applicable services agreement may also apply.

03 · Information we may collect

  • Enquiry information: name, work email, organization, role, sector of interest and the content of a message.
  • Business relationship information: meeting notes, commercial correspondence, project contacts and engagement records.
  • Account information: account identifiers, role and permission assignments, authentication events and audit records where a client portal is used.
  • Assessment information: names or business contact details of evidence owners, reviewers and approvers that may appear in governance records supplied by a client.
  • Technical information: IP address, browser and device information, request timestamps, referring pages, security events and server logs.

04 · How information is used

  • Respond to enquiries and provide requested information.
  • Scope and deliver AIGR assessments, platform services, ratings and monitoring.
  • Administer accounts, permissions and audit trails.
  • Maintain traceability, integrity and reproducibility of governance decisions.
  • Secure the website and services, detect misuse and investigate incidents.
  • Improve the website, methodology, documentation and service quality.
  • Comply with contractual, legal, regulatory and recordkeeping obligations.

05 · Client assessment and rating data

AIGR assessments may involve governance artifacts supplied by a client organization. Clients should minimize personal information before uploading or sharing evidence and should not provide sensitive information unless it is necessary, authorized and covered by the applicable agreement. Access to assessment evidence should be limited to authorized personnel and maintained within the relevant client or engagement context.

Where a rating report is shared or published, the intended output is the rating designation, scope, rationale, conditions and related governance information—not the client’s underlying evidence—unless the client expressly authorizes additional disclosure.

06 · Legal bases and consent

Depending on the jurisdiction and context, information may be processed with consent, to perform a contract, to comply with a legal obligation, or for legitimate business interests such as operating, securing and improving AIGR services. Where consent is the applicable basis, it may be withdrawn subject to legal and contractual limits.

07 · Service providers and disclosure

Information may be disclosed to hosting, email, security, analytics, authentication, collaboration, professional-advisory and other service providers that support operation of the website or AIGR services. Providers are expected to process information only for authorized purposes and subject to appropriate contractual and security safeguards. Information may also be disclosed where required by law, to protect rights or security, or at the direction of the relevant client.

08 · International processing

Service providers or authorized personnel may process information in jurisdictions outside the user’s province, state or country. Where required, AIGR uses contractual or other lawful transfer mechanisms and evaluates appropriate safeguards for cross-border processing.

09 · Retention

Information is retained only for as long as reasonably necessary for the purpose for which it was collected, to maintain security and auditability, to support rating reproducibility, or to satisfy contractual and legal obligations. Assessment evidence and rating decision records may have different retention periods because a governed rating must remain traceable to its scope, methodology version, evidence set and decision record.

10 · Security

AIGR is designed around controlled access, evidence ownership and auditability. Reasonable administrative, technical and organizational safeguards should include role-based access, authentication controls, encryption where appropriate, logging, tenant or engagement segregation, backup and incident-response procedures. No transmission or storage method can be guaranteed to be completely secure.

11 · Your rights

Depending on applicable law, individuals may have rights to request access to personal information, correction, deletion, restriction, portability, withdrawal of consent or objection to certain processing. Requests can be submitted through the AIGR contact page or by email to [email protected]. Identity verification may be required before a request is completed.

12 · Cookies and analytics

The website may use essential cookies or similar technologies required for security, session management and site operation. Analytics or non-essential technologies should be enabled only in accordance with applicable consent requirements and the production configuration of the site.

13 · Children

The AIGR website and enterprise services are not directed to children and are intended for business and professional users.

14 · Changes

This policy may be updated as the AIGR platform, service providers, legal requirements or operating practices evolve. Material revisions should be identified by an updated effective date or version.

15 · Contact and complaints

Privacy questions, requests or complaints can be submitted through the AIGR contact page or to [email protected]. Where applicable, individuals may also have the right to contact their local privacy or data-protection authority.

Enterprise assessment

Establish governance readiness for a defined AI system.

Request an Assessment