Privacy Policy
Last updated: 9 October 2026
Who are we?
AIAdopt provides online AI trainings, consulting and advice to organisations and individuals. AIAdopt is responsible for the processing operations in this privacy policy, except where it says that AIAdopt processes data on behalf of an organisation.
What data do we process and where does it come from?
We process the data that you provide to us yourself and the data generated when you use our services. We receive some data from someone else: from the person placing the order or the administrator of your organisation, from someone who has a quote also sent to you, or from VIES when checking a VAT number.
Contact form. Your name, email address, telephone number, organisation, subject and message. Your message arrives as an email in our mailbox and is not stored in our database. To prevent misuse, we briefly count how often a message is sent from the same IP address. We do not store that IP address.
Quote configurator. Your name, email address, organisation, country and, optionally, the email address of someone who should also receive the quote. We send the quote by email to you and to that recipient. That recipient receives a reference to this privacy policy with the quote. We do not store your request itself.
Orders. Name, email address and telephone number of the person placing the order, organisation name, company number, billing address, country, VAT number, your own reference, the chosen trainings and the number of seats, the payment status, the invoice number and proof that you accepted the terms and conditions (date and time, language, version and IP address). If you buy as a private individual, we also store proof of your consent to start the training immediately. If you provide a VAT number, we check it in VIES (the European Commission's system) and store the response (name and address of the company).
Payment. You pay on Mollie's payment page. We give Mollie the amount, the order number and a description of the order. If you buy through the purchase page of an individual training, Mollie also receives your email address. We do not see or store your card or account details.
Learning portal. Name, email address, language preference, role, organisation and department of the participant, the time the account was created and the last login, the assigned trainings, the progress per lesson, the exam attempts with score and answers and the certificates. For a training for an organisation, we receive this data from the person placing the order or the administrator of that organisation. To log in, we use one-time login links that are valid for 24 hours. We store the time at which you use the link and the type of browser. After logging in, you stay logged in for 30 days. If an administrator removes a participant, we keep the name of that participant and of the administrator in a deletion log.
Exam and certificate. The exam in the learning portal is marked automatically with a fixed answer key. Anyone who scores 70% or more automatically receives a certificate. If you have doubts about your score, email info@aiadopt.eu. A person will then review your exam again. Apart from that, we do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). We do not create profiles.
AI-AdoptieScan. We store participants' answers without a name or email address. We do store the sector, the language, the start and completion times and, if the participant fills it in, the department. For the organisation requesting the scan, we store the organisation name, the sector, the name and email address of the contact person, the departments and the acceptance of the data processing agreement. For the administrators of the scan, we store the email address and the last login.
Withdrawals and the EU AI Act compliance checklist. See the separate sections below.
Security. For the checklist, the withdrawal form and the request for the AI-AdoptieScan, we use Cloudflare Turnstile to prevent misuse. Your IP address is passed on to Cloudflare for this purpose.
Web statistics. We measure visits with Pirsch Analytics. Pirsch places no cookies. It calculates a hash from your IP address, your user agent, the date and a salt that differs per website, and does not store the IP address itself. A visitor can therefore be recognised for at most 24 hours, and never from one website to another. Pirsch processes and stores the data within the European Union.
For visitors from outside the European Union, Cloudflare may measure visits, page views and load times without cookies. For visitors from the European Union, the site does not place that Cloudflare script.
Which data is mandatory? Each form indicates which fields are mandatory. Without the data for an order, we cannot carry it out or issue an invoice. Without the data for an account, we cannot give access. You provide other data voluntarily.
For what purposes and on what legal basis?
Data we process for an organisation. If an organisation buys trainings for its employees, that organisation is responsible for the accounts, learning data and reports of its participants. AIAdopt processes that data on its behalf. The organisation determines what it uses the data for and informs its participants. Administrators of the organisation can see, among other things, the name, email address, department, trainings, progress, exam results and certificates of their participants. The same applies to the AI-AdoptieScan: the organisation requesting the scan is responsible and concludes a data processing agreement with AIAdopt for that purpose. AIAdopt itself remains responsible for its own order and invoice records. Article 14 of the terms and conditions sets out the arrangements.
Who do we share your data with?
We do not sell your data. We share it only with the service providers below and only for the purposes in this privacy policy. The service providers with the role "processor" make up the list of processors referred to in Article 14 of the terms and conditions.
| Service provider | Purpose | Role | Location |
|---|---|---|---|
| Neon | database with accounts, orders, learning results, scans and requests | processor | Frankfurt, European Union; Neon is an American company |
| Cloudflare | hosting of the website and the servers, storage of certificates and invoices, security (Turnstile), web statistics | processor | global network; Cloudflare is an American company |
| Resend | sending email | processor | sent from Ireland, European Union; processing mainly in the United States |
| Zoho | AIAdopt's mailboxes, where among other things your contact message and order notifications arrive | processor | data centre in the European Union; Zoho is an Indian company |
| Microsoft | storage of the weekly backup in OneDrive | processor | Microsoft is an American company |
| Twilio | telephony for our business number | processor | Twilio is an American company |
| Doccle | sending invoices to Belgian companies via Peppol | processor | Belgium, European Union |
| Pirsch | web statistics without cookies | processor | Germany, European Union |
| Mollie | online payments | independent controller | Netherlands, European Union |
Mollie itself processes the data you enter on its payment page, in accordance with its own privacy statement. The organisation for which you follow a training sees the data and reports that belong to its assignment.
In addition, we pass on data where the law requires it. We check a VAT number in the European Commission's VIES. We send an invoice to a Belgian company via Peppol, the network for electronic invoices prescribed by Belgian law.
Transfers outside the European Economic Area. Neon, Cloudflare, Resend, Microsoft and Twilio are American companies and Zoho is an Indian company. As a result, data may be processed outside the European Economic Area or be accessible from there. For the United States, we rely on the EU-U.S. Data Privacy Framework to the extent that the service provider is certified under it. Otherwise, we rely on the standard contractual clauses of the European Commission. For other countries, the standard contractual clauses apply. You can obtain a copy of the safeguards on request via info@aiadopt.eu.
How long do we keep your data?
We delete data in our database and in Cloudflare storage (R2) automatically with a clean-up routine that runs every night. "Deleted" means: in the first night after the period has expired. Email in our mailbox and the backups in OneDrive are not covered by that routine; the rules below the table apply to them.
| Data | Period |
|---|---|
| Account and learning data (progress, exam attempts and answers, certificates with their PDF, assignments, enrolments, login links, administrator role) | Deleted in the first night after access has ended: the last personal entitlement as well as the organisation's licence. No additional retention period. An open order or a licence that starts later counts as valid access. An order awaiting payment counts as open for only 30 days after it was placed. Platform administrators are not covered by this. |
| Organisation without members and without a valid licence | Contact address, administrators, departments and email domains deleted in the first night after that, together with any AI-AdoptieScan linked to that organisation. Name, organisation code and orders remain. |
| Orders and invoices, with VAT check (VIES), fulfilment, invoice PDFs and linked withdrawals | 7 years, counted from 1 January of the year following the invoice date. |
| Order that was never paid and never invoiced | 12 months after it was placed. |
| Withdrawal without a linked order | 12 months after submission. |
| Withdrawal with a linked order | Together with that order. |
| Encrypted IP code of a withdrawal | 30 days after submission. |
| Leads (checklist request) | 12 months after the most recent request. |
| Login links for the learning portal | 30 days after use or expiry, whichever comes first. |
| Login links for the AI-AdoptieScan | 30 days after expiry; a scan link is valid for 24 hours. |
| AI-AdoptieScan (organisation, administrators, login links, sessions and answers) | 12 months after the last activity: creation, a session, an administrator login or the closing of the scan. |
| Names in the deletion log | 12 months after the deletion; after that, only an entry without names remains. |
| Exports from the clean-up routine | 30 days after creation. |
Email. We delete email to AIAdopt, such as contact messages, 12 months after the last contact. If a message relates to an order, we keep it for as long as the data of that order.
Telephone. We do not record calls. For each call with our business number, Twilio keeps the number, the time and the duration. We delete this data 12 months after the call.
Backups and restore points:
| Storage location | Period |
|---|---|
| Database (Neon) | Restore up to 6 hours back; after that, a deleted row is gone from there. |
| Storage of PDFs and exports (Cloudflare R2) | No versions; deleted means gone immediately. |
| Weekly backup (OneDrive) | The 13 most recent complete backups; we delete older backups. After that, up to 93 days more in the OneDrive recycle bin. |
If we have to restore a backup, we then reapply the deletions and periods set out in this policy.
Withdrawal
If you withdraw from a contract, we keep your name, email address, order number and the date and time of submission. If the withdrawal relates to an order, we keep this data for as long as we keep the data of that order. If it does not relate to an order, we delete this data after twelve months. For security purposes, we keep an encrypted code of your IP address for 30 days.
EU AI Act compliance checklist
When you request our checklist, we store your name, your email address, the sector and country you give us, the language you requested it in, the page you requested it from, the time of your first and your most recent request and the number of times you have requested it.
We use that data for two purposes, each with its own legal basis:
1. Delivering the checklist. Basis: you request the checklist and we deliver it (Art. 6(1)(b) GDPR). Without your email address we cannot deliver the checklist.
2. Messages about new versions of the checklist and about changes to the EU AI Act. Basis: your separate consent, given by ticking the box provided (Art. 6(1)(a) GDPR). That box is unticked by default and is not a condition for receiving the checklist. We record when you gave that consent.
We share this data with Resend, Neon, Cloudflare and Microsoft (weekly backup), see the table above. We do not sell your data and we do not pass it on for third-party purposes.
We keep your data for up to twelve months after your most recent request, after which we delete it. This also applies if you have consented to receive messages about new versions. If you withdraw that consent, we stop sending you messages from that moment on.
You can withdraw your consent at any time through the unsubscribe link in every message we send you, or by writing to info@aiadopt.eu. Withdrawing your consent does not affect the lawfulness of what we did before that.
What are your rights?
Under the GDPR you have the following rights:
Right of access: you can request which data we hold about you.
Right to rectification: you can have inaccurate data corrected.
Right to erasure: you can ask to have your data removed.
Right to restriction: you can ask to restrict the processing of your data.
Right to portability: you can ask to receive your data in a structured, commonly used format.
Right to object: you can object to the processing of your data on the basis of legitimate interest.
Right to withdraw consent: if the processing is based on consent, you can withdraw it at any time.
For all of these requests you can get in touch at info@aiadopt.eu. We respond within one month. For a complex request, we may extend that period by two months; in that case, we will let you know within the first month. If we process your data on behalf of an organisation, we help that organisation to handle your request.
Lodging a complaint
If you feel that we do not handle your data carefully, you can lodge a complaint with:
Data Protection Authority (Belgium)
Drukpersstraat 35, 1000 Brussels
https://www.gegevensbeschermingsautoriteit.be
contact@apd-gba.be
Dutch Data Protection Authority (Netherlands)
https://www.autoriteitpersoonsgegevens.nl
If you live in another country, you can also contact the supervisory authority of that country.
Changes
We may amend this privacy policy. The most recent version is always available on this page. If we want to use data for a new purpose, we will inform you about this in advance.