Responsible AI · UB-AI-004
AI Data Protection & Privacy
The additional controls that apply whenever an AI workflow touches learner or client information.
This sits on top of our general Data Protection & Privacy Policy. It applies whenever AI is anywhere near learner or client information.
What it covers
- Personal data, participant-authored content, notes, form responses, assessment data and uploads processed in AI-supported training workflows.
- Our training platform, its local records and any external AI service it calls.
- AI tools used in course preparation whenever client confidential information, learner information or other non-public data may be involved.
What we commit to
- We apply GDPR-aligned principles as an internal baseline: lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Applicable UAE, other national or client legal requirements remain controlling where they apply.
- Personal data and client confidential information are not entered into unapproved public AI tools.
- Every AI workflow that processes learner or client data requires a documented assessment covering purpose, necessity, data categories, access, storage and retention, external provider, cross-border considerations, security controls, human oversight and approval. A formal impact assessment is completed where law, client policy or risk level requires it.
- Only the minimum information needed for the learning purpose is used. Sensitive or welfare information is not exposed to AI unless specifically justified, approved and protected.
- Where consent is used for an optional AI feature, it must be informed and affirmative, taken before the processing happens.
- External AI vendors are reviewed for privacy and security terms, retention, model-training use, sub-processors and regions before any learner data is sent to them.
- Client technology and data policies take precedence wherever they are stricter, confirmed through a pre-delivery review of device, network, approved-tool and security constraints.
- Learner working data is not normally retained beyond 90 days unless a documented legal, contractual, certification or operational reason applies.
What this means for you
What you write in an exercise is not quietly feeding somebody's model. If an optional AI feature would process your material, you are asked first, and you can decline and still do the course.