Legal
Privacy Policy
How AIGX Research™ collects, uses, discloses and protects personal information.
Contents
01Who we are
AIGX Research™ (“AIGX”, “we”, “us”) provides AI governance assessments, a governance platform and AIGR™ AI Governance Ratings. AIGX Research™ is the organization accountable for personal information under this policy.
Questions about this policy, or requests relating to your personal information, should be directed to our Privacy Officer at info@aigx.ca, marking the subject line PRIVACY.
02Scope
This policy applies to personal information we collect through this website, through our commercial and assessment engagements, and through our platform and rating services.
It does not apply to third-party websites we link to, or to personal information we process on behalf of a client under a written services agreement. Where we process information on a client’s instructions as part of an assessment, the client remains accountable for that information and their own privacy notice governs it. Section 6 explains how we handle that material.
03Information we collect
Information you give us
Name, work email, organization, role, sector of interest and the content of your message when you submit an enquiry form; information you provide during scoping calls, assessments and commercial correspondence.
Information collected automatically
IP address, browser and device type, pages viewed, referring page and timestamps, collected through server logs and, where enabled, analytics tools.
Platform account information
For client users of the AIGX platform: account identifiers, authentication data, role and permission assignments, and audit records of actions taken in the system, including evidence uploads, approvals and reviewer decisions.
Information from other sources
Publicly available business information, and information provided by your colleagues or your organization in the course of an engagement.
We do not knowingly collect sensitive personal information through this website and we ask that you do not submit confidential data, patient information, or trade secrets through our web forms.
04How we use information
- To respond to enquiries and provide requested information
- To deliver assessments, platform services, ratings and monitoring under a contract
- To administer accounts, authenticate users and maintain audit trails
- To maintain the integrity, traceability and reproducibility of rating decisions
- To improve our website, methodology and service quality
- To send service communications, and marketing communications where you have consented
- To detect, prevent and investigate security incidents, fraud and misuse
- To comply with legal, regulatory and contractual obligations
We do not sell personal information. We do not use personal information to train third-party machine learning models, and we do not disclose client evidence to any generative AI service that would retain or train on it.
05Legal bases
Where Canadian privacy law applies, we rely on your consent, express or implied, and on the exceptions to consent permitted for business contact information and for information necessary to perform a contract.
Where the EU or UK GDPR applies, we rely on: performance of a contract; our legitimate interests in operating, securing and promoting our services, balanced against your rights; your consent, where we ask for it; and compliance with legal obligations.
06Client assessment data
Assessment engagements involve evidence supplied by the client organization. That evidence may incidentally contain personal information such as names of control owners, reviewers and approvers.
We handle assessment evidence under the following commitments:
- Evidence is processed only for the purposes set out in the engagement agreement
- Access is restricted to assigned assessment and review personnel
- Evidence is segregated by client tenant within the platform
- We ask clients to redact or minimize personal information, patient information and other sensitive data before uploading it
- Where a rating is published or shared with a third party at the client’s direction, it contains the rating designation, rationale and conditions — not the underlying evidence
Benchmark cohorts are constructed under consent and confidentiality rules, and cohort outputs are designed to be reported in aggregate rather than in a form that identifies an individual participant.
07Disclosure to third parties
We disclose personal information only:
- To service providers acting on our instructions, as described in Section 8
- To a client organization in relation to its own engagement
- Where you direct us to share a rating report with a named recipient
- Where required by law, legal process, or a lawful request by a public authority
- To professional advisers under duties of confidentiality
- In connection with a corporate transaction, subject to equivalent protection
08Service providers
We use third parties to host our website and platform, deliver email, and provide analytics and security services. Each is engaged under a written agreement that limits their use of personal information to the services they provide for us and requires appropriate safeguards.
A current list of the categories of service providers is available on request from info@aigx.ca.
09International transfers
Personal information may be stored or processed outside your province, state or country, including in the United States. Where information is held outside Canada, it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we do so on the basis of an adequacy decision or standard contractual clauses together with appropriate supplementary measures.
10Retention
| Category | Retention |
|---|---|
| Website enquiry submissions | 24 months from last contact |
| Marketing contact records | Until consent is withdrawn, then suppression only |
| Assessment evidence and working papers | As set out in the engagement agreement |
| Rating decision records and audit trails | 7 years, to support reproducibility and challenge |
| Platform account and access logs | Duration of the account plus 24 months |
| Server and security logs | 12 months |
Rating decision records are retained for an extended period because a governed rating must remain reproducible from the methodology version, evidence set and decision record used at the time of issuance.
11Security
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information, including access control, role separation, encryption in transit and at rest, logging, and incident response procedures.
No method of transmission or storage is completely secure. If we become aware of a breach of security safeguards creating a real risk of significant harm, we will notify affected individuals and the applicable regulators as required by law.
12Your rights
Subject to applicable law and to any legal or contractual restrictions, you may request to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Withdraw consent, including for marketing communications
- Request deletion, portability, or restriction of processing
- Object to processing based on legitimate interests
- Be informed about, and object to, any decision based exclusively on automated processing that produces legal or similarly significant effects
Send requests to info@aigx.ca. We will verify your identity before acting and will respond within the period required by applicable law, generally 30 days. There is no fee unless a request is manifestly unfounded or excessive.
13Cookies and analytics
We use cookies that are strictly necessary for the website to function. Where we use analytics or preference cookies, we request consent before they are set, and you may change or withdraw that choice at any time through the cookie settings on this site or through your browser controls.
We do not use cookies for cross-site behavioural advertising.
14Children
Our services are directed at organizations and business professionals. We do not knowingly collect personal information from individuals under the age of majority in their jurisdiction. If you believe we have done so, contact us and we will delete it.
15Changes to this policy
We may update this policy. The effective date and version number above indicate the current release. Where changes are material, we will provide notice through the website or by direct communication before they take effect. Prior versions are available on request.
16Contact and complaints
AIGX Research™ — info@aigx.ca
Privacy requests should be marked PRIVACY in the subject line so they are routed to our Privacy Officer.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec where Quebec law applies, or your local supervisory authority in the EEA or UK.
Notice
This policy describes AIGX Research™’s privacy practices. It is not legal advice to any reader. Nothing in this policy limits rights that cannot be limited under applicable law.