Legal
Privacy Policy
This policy explains what The Global Association of Certified KYC Specialists (Global AKS) collects about you, why, who else sees it, how long we keep it and what you can require of us. It is written to be read, not to be got past.
Effective 7 October 2026 · Applies to globalaks.com and all Global AKS services
We do not sell your data. Ever.
Global AKS has never sold, rented, traded or otherwise made personal data available to a data broker, an advertiser, a list vendor or anyone else for their own purposes, and we will not. There is no exception to this for a good offer, a partnership or a change of ownership: it is a condition of how this association operates.
Your information is used to deliver the service you enrolled for, to answer you when you write, and to meet obligations the law places on us. Nothing else.
1. Who we are
The Global Association of Certified KYC Specialists ("Global AKS", "we", "us") develops, examines and issues professional certifications in know‑your‑customer, anti‑money laundering, financial crime and fraud compliance. We operate globalaks.com and the learner platform at globalaks.com/learn.
For the purposes of the data protection laws described in section 11, Global AKS is the controller of your personal data — the party that decides what is collected and why. Our certifications are developed in cooperation with ONRIGA, the Organization for Next‑gen Regulatory Intelligence & Global Accreditation, which accredits the credential standard; accreditation does not give ONRIGA access to your personal data.
2. What we collect
Collected automatically when you visit
- IP address, browser type and version, operating system and device type;
- Pages visited, time spent, and the page or search that referred you;
- The approximate country your connection comes from, used to show prices in a sensible currency.
Given by you when you enrol or write to us
- Your name, the name you want printed on your certificate, email address and telephone number;
- Billing address, country and company name, where you give them, for the invoice;
- Professional details you choose to provide, such as your role or organisation;
- Anything you write to us in an enquiry, a support request or a review.
Created as you use the platform
- Which courses you are enrolled on and your progress through the material;
- Your examination sittings: when each was taken, how long it took, the answers you gave and the result;
- The IP address and device used during an examination, kept for examination integrity;
- Certificates issued to you, their credential IDs, scores and dates;
- Orders, invoices, the currency and amount paid, and any refund.
We never see your card. Card numbers, expiry dates and security codes are entered directly with our payment processors and never reach our servers. We hold only what an invoice needs: the amount, the currency, the date and a payment reference.
3. Why we use it
- To open your account, enrol you, give you the study material and let you sit the examinations;
- To mark your papers, issue your certificate and allow anyone you give the credential ID to verify it;
- To raise your invoice, take payment, and handle a refund where one is due;
- To answer you when you write, and to tell you about your account: enrolment, results, expiry and renewal;
- To keep the platform secure, to detect abuse, and to protect the integrity of an examination;
- To understand how the service is used, so the material and the platform get better;
- To meet our legal, tax and accounting obligations.
4. The legal basis for using it
Where the UK or EU General Data Protection Regulation applies, we rely on:
- Performance of a contract — to deliver the certification you enrolled for;
- Legal obligation — to keep invoices, tax records and accounting data;
- Legitimate interests — to keep the platform secure, prevent fraud, protect the integrity of our examinations, and improve what we offer; balanced each time against your interests;
- Consent — for anything optional, such as making a credential publicly listed or receiving non‑essential messages. You may withdraw consent at any time without affecting what was done before.
5. Who else sees it
We share personal data only with providers who help us run the service, and only as much as each one needs. Every provider is bound by contract to use it for that purpose and no other, and none of them may use it for their own ends.
- Our support services provider — receives your name and email address, and handles the support conversations you start, solely to answer you;
- Payment processors — take your payment and hold the card details we never see;
- Hosting and database providers — run the platform your account sits on;
- Our email delivery provider — sends the messages your account requires;
- Analytics and error reporting — tell us how the site performs and where it breaks.
We will also disclose data where the law requires it — a court order, a regulator's lawful demand, or to establish or defend a legal claim.
Credential verification is public by design, and limited. Anyone given your credential ID may confirm that it is genuine. Verification shows the name printed on the certificate, the credential held and its dates. It shows nothing else about you — not your email address, not your score, not your account. A separate public page for a credential is published only if you switch it on yourself.
6. Cookies
We use cookies that the service genuinely needs: one that keeps you signed in, one that remembers the currency you chose, and one that records a partner referral where you arrived through a partner link. Analytics cookies, where used, tell us how pages perform in aggregate.
We do not use advertising cookies and we do not allow third parties to track you across other websites from ours. You can block or delete cookies in your browser, though signing in will not work without the session cookie.
7. How we protect it
- Every page and every form on globalaks.com is served over SSL/TLS encryption. Nothing you send us travels in the clear;
- Card details never touch our servers: they go directly to the payment processor;
- Access to learner data is restricted to the few people who need it, and administrative actions are recorded in an audit log;
- Data is encrypted at rest, backed up, and the platform is monitored for abuse and intrusion;
- Sign‑in is by one‑time code or a verified provider, so there is no password of yours for us to lose.
No system connected to the internet can be guaranteed absolutely secure, and we do not claim otherwise. If a breach ever affects your personal data, we will notify you and the relevant authority within the time the applicable law requires.
8. How long we keep it
- Your account and learning record — while your account is open, and for a reasonable period after you close it;
- Credential records — kept for as long as the credential may need to be verified. A certificate an employer can no longer confirm is worth nothing, so this record is deliberately long‑lived;
- Invoices and payment records — for the period tax and accounting law requires, which we cannot shorten at request;
- Support correspondence — while it is needed to resolve the matter and for a reasonable period afterwards;
- Technical logs — a short period, for security and diagnosis.
When data is no longer needed it is deleted or irreversibly anonymised.
9. Where it is processed
We certify professionals in many countries, and our providers operate internationally, so your data may be processed outside the country you live in. Where personal data protected by the UK or EU GDPR leaves that area, the transfer is made under an approved safeguard — standard contractual clauses or an adequacy decision — so the protection travels with it.
10. Your rights
Whichever law applies to you, write to us and we will honour the rights it gives you. We do not ask you to prove you are covered by one before we help.
GDPR — United Kingdom and European Union
UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679
- Access — a copy of the personal data we hold about you;
- Rectification — correction of anything inaccurate or incomplete;
- Erasure — deletion, where we have no overriding obligation to keep it;
- Restriction — that we hold it but stop using it, while a dispute is settled;
- Portability — your data in a structured, machine‑readable form;
- Objection — to processing we base on legitimate interests;
- Withdrawal of consent — at any time, for anything we do on that basis.
You may also complain to your supervisory authority — in the UK, the Information Commissioner's Office; in the EU, the authority in your member state. We would rather you came to us first, but the right is yours either way.
DPDP Act — India
Digital Personal Data Protection Act, 2023
Global AKS acts as a Data Fiduciary. If you are a Data Principal in India you have the right to:
- Obtain a summary of the personal data we process and of our processing activities;
- Know the identities of the other parties with whom we have shared it, and what was shared;
- Have inaccurate or misleading data corrected, completed or updated;
- Have your personal data erased, unless retention is required by law;
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity;
- A readily available means of grievance redressal, before approaching the Data Protection Board of India.
Grievances may be raised at [email protected] and are acknowledged and answered within the period the Act prescribes.
PDPL — Kingdom of Saudi Arabia
Personal Data Protection Law, Royal Decree M/19
- To be informed — of the legal basis and purpose for which your data is collected;
- To access — your personal data held by us, and to obtain a copy of it;
- To request correction — of data that is inaccurate, incomplete or out of date;
- To request destruction — of personal data that is no longer needed for the purpose it was collected for;
- To withdraw consent — where our processing rests on it.
You may also complain to the Saudi Data & Artificial Intelligence Authority (SDAIA).
11. How to exercise a right
Write to [email protected] from the email address your account is registered under, and say what you want. There is no form and no fee. We answer within one month, and tell you if a request is genuinely complex enough to need longer.
One honest limit on erasure. If you ask us to erase your data and you hold a Global AKS credential, erasing your record means that credential can no longer be verified by anyone. We will tell you that before we act, and we will not act until you confirm. Invoices and tax records we are legally required to keep are retained whatever else is erased.
12. Children
Global AKS certifications are professional qualifications intended for adults working in or entering compliance. Our services are not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have, the account and its data are deleted.
13. Links to other sites
Our pages link to websites we do not run, including accreditation bodies and industry publications. We are not responsible for how those sites handle your data, and we suggest you read their own policies before giving them anything.
14. Changes to this policy
We revise this policy when the law, our providers or our services change. The revised version is published here with a new effective date. Where a change materially affects how your data is used, we tell account holders directly rather than relying on you to notice.
15. Contact us
Questions about this policy, about what we hold, or about a request you have made:
The Global Association of Certified KYC Specialists
Privacy and data protection enquiries: [email protected]
Unresolved matters: [email protected]
Effective 7 October 2026. This policy supersedes all previous versions.