Privacy policy
How the association collects, uses and protects personal information about members, candidates, organizations and visitors.
Version 1.0 · last updated 2026-09-10 · exercise your rights
1. Who we are
Association of Digital Trust Practitioners ("the association", "we", "us") is an independent practitioner association for privacy, security, risk, compliance, third-party assurance and AI governance, operating the website at trustpractitioners.org and the membership, learning and credentialing services it provides.
We are the controller of the personal information described in this policy. Privacy enquiries: privacy@trustpractitioners.org. Rights requests are handled through our Privacy Center.
2. What we collect
2.1 Information you give us
- Membership: legal name, display name, email address, country, the membership tier you choose and your acceptance of the code of ethics.
- Learning: course enrolments, lesson progress, quiz responses, self-assessment of artefacts and the notes you write in them.
- Credentialing: examination registrations, attempts, scores and score reports, continuing education submissions and the evidence links you provide, ethics affirmations, appeals and their outcomes.
- Organizations: if your employer holds seats, the administrator who invites you provides your name and work email, and your training assignments and completion are visible to them.
- Billing: billing contact and the payment reference returned by our payment processor. We never receive or store full card numbers.
- Correspondence: anything you send us by email or through a form.
2.2 Information collected automatically
IP address, browser and device information, pages visited and actions taken in the member application, and security logs of sign-in attempts and sessions. Cookies and similar technologies are described in the cookie policy.
2.3 Information from others
If you sign in through your employer's identity provider or a social provider, we receive the attributes that provider releases, normally your name and email address. If a partner verifies your membership with your consent, we record that disclosure.
We do not knowingly collect special category data. Do not include health, biometric or similar information in artefacts, submissions or correspondence.
3. How we use it
| Purpose | Examples |
|---|---|
| Running your membership | Authentication, entitlements, renewals, member number and badge |
| Delivering learning | Enrolment, progress, credits, certificates |
| Credentialing | Eligibility, examination delivery and integrity, scoring, renewal, appeals |
| Verification | Publishing the minimum needed to verify a credential you chose to make public |
| Organization administration | Seat management, assignment and completion evidence for your employer |
| Communication | Service messages, renewal notices, and the intelligence digest if you subscribe |
| Security and integrity | Preventing unauthorised access, examination misconduct and abuse |
| Legal and financial | Accounting, tax, responding to lawful requests, defending claims |
We do not sell personal information and we do not use it for cross-context behavioural advertising.
4. Legal bases
Where the GDPR or UK GDPR applies we rely on: contract for membership, learning and credentialing; legitimate interests for security, service improvement and communicating with members about the association's work; consent for non-essential cookies, the digest and any optional publication of your credentials; and legal obligation for accounting and lawful requests. You may withdraw consent at any time without affecting processing before withdrawal.
5. Public verification and your control over it
A credential is only useful if someone can check it. For each certificate or credential in your wallet you choose whether it is publicly verifiable. When it is, a person holding the verification code sees the credential name, its status, the issue and expiry dates, and the display name you set; nothing else. You can withdraw publication at any time, after which the code returns no result. Badges you add to a public profile carry the same information. Verification lookups are logged for abuse prevention.
6. Examinations
Examination delivery records the attempt, timing, responses, flags raised during the session, and where a proctoring provider is used, the identity check and the session report that provider returns. We keep this to defend the integrity of the credential. Score reports never disclose examination items. Appeals are decided by the ethics committee and the decision is recorded.
7. Sharing
- Service providers who host, deliver mail, process payments, deliver consent and privacy tooling, or provide examination proctoring, each bound by contract. The current list is published at sub-processors.
- Your employer, where you occupy a seat it pays for: your name, work email, assignments, completion and credential status. Not your personal learning outside those assignments.
- Partners, only where you request a benefit and consent to the specific disclosure. Each disclosure is logged and shown to you.
- Authorities, where the law requires it. We push back on overbroad demands.
8. International transfers
We operate in the United States and our providers may process data in the United States and the European Union. Where data leaves the EEA or UK we rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, with supplementary measures. A copy of the clauses is available on request.
9. Retention
| Category | Retention |
|---|---|
| Membership and profile | Membership term plus 7 years |
| Credential and certificate records | Permanently, because verification must outlive the membership |
| Examination attempts and integrity records | 7 years |
| Learning progress and artefact self-assessment | Membership term plus 2 years |
| Financial records | 7 years |
| Security and application logs | 90 days by default |
| Consent and disclosure records | 7 years, as evidence |
Deleting your account removes your profile and learning history. Credential records are retained in a minimised form, because withdrawing them would break verification for people who relied on it; you may still withdraw public verification.
10. Your rights
Access, correction, deletion, portability, restriction, objection, withdrawal of consent, opting out of sale or sharing (we do neither), and appeal. Exercise them at the Privacy Center or by writing to privacy@trustpractitioners.org. We verify identity before acting and respond within the period the applicable law allows, normally 30 days under the GDPR and 45 days under US state laws. We honour Global Privacy Control signals. You may complain to your supervisory authority; we would rather you told us first.
11. Security
Encryption in transit and at rest, multi-factor authentication for administrative access, least-privilege access control, append-only audit trails for credential and consent events, and signed credential documents. No system is perfectly secure; if a breach affects your information we will notify you and the regulators as the law requires.
12. Children
The association's services are for working professionals and are not directed at children under 16. We do not knowingly collect their information.
13. Changes
We publish the version and date at the top of this page. Material changes are announced to members, and where the law requires it we ask for renewed consent.
14. Contact
Privacy: privacy@trustpractitioners.org · General: hello@trustpractitioners.org · Rights: Privacy Center · Security posture: Trust Center