Back to home

Privacy Policy

Last updated: 8 July 2026

1. Introduction

The Atlantic School of Global Governance and Leadership ("ASGGL", "we", "us", or "our") is the training arm of Advocacy Unified Network (AUN), headquartered at Fluwelen Burgwal 58, 2511 CJ The Hague, Netherlands. We are committed to protecting your privacy and ensuring the security of your personal data.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website (asggl.org), enrol in our courses, or interact with our services. By using our services, you consent to the practices described in this policy.

ASGGL complies with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and the Dutch Personal Data Protection Act (UAVG). This policy is designed to meet the transparency requirements of Article 13 of the GDPR.

2. Data Controller

ASGGL is the data controller for the personal data collected through this website. If you have questions about how your data is handled, please contact us at info@aunetwork.org or at our postal address: Fluwelen Burgwal 58, 2511 CJ The Hague, Netherlands.

3. Personal Data We Collect

We collect the following categories of personal data:

  • Identification data: First name, last name, and institution/credentials — collected when you enrol in a course. Your name appears on your certificate of completion.
  • Contact data: Email address — used for account management, course progress tracking, certificate delivery, and important course-related communications.
  • Course progress data: Lessons completed, quiz and exam scores, descriptive answers submitted, and certificate numbers — used to track your learning and issue certificates.
  • Waitlist data: Name, email, country, role, and area of interest — collected when you join the Founding Cohort waitlist.
  • Technical data: IP address, browser type, device information, and usage data — collected automatically through cookies and server logs.
  • Chat data: Messages you send to Athena (our AI concierge) or to your school's AI teacher — used to provide real-time responses and improve our AI services.

4. Legal Basis for Processing

Under Article 6 of the GDPR, we process your personal data on the following legal bases:

  • Contract (Art. 6(1)(b)): Processing is necessary to provide you with the courses you have enrolled in, including tracking progress, grading exams, and issuing certificates.
  • Consent (Art. 6(1)(a)): You consent to our use of your data for waitlist registration, AI chat interactions, and marketing communications. You may withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)): We process technical data for security, fraud prevention, and service improvement, balancing our interests against your privacy rights.
  • Legal obligation (Art. 6(1)(c)): We may retain certain data to comply with legal, accounting, or regulatory obligations.

5. How We Use Your Data

We use your personal data for the following purposes:

  • Enrolling you in courses and tracking your learning progress
  • Grading your exams (including AI-assisted grading of descriptive answers) and issuing certificates
  • Providing AI-powered learning support through Athena and school-specific AI teachers
  • Sending you course-related communications, including completion confirmations and certificate delivery
  • Maintaining the integrity of our certificate registry and verification system
  • Analysing aggregate usage data to improve our courses and platform
  • Preventing fraud, abuse, and unauthorised access to our systems
  • Complying with our legal and regulatory obligations

6. AI Processing and Descriptive Exam Grading

When you submit descriptive exam answers, we use a large language model (LLM) to grade your responses against model answers and grading criteria. The AI examiner reads your answers, assigns marks, and generates feedback. Your descriptive answers and the AI's feedback are stored in your enrollment record.

Messages you send to Athena or your school's AI teacher are processed by an LLM to generate responses. These conversations are not stored permanently beyond the current session, unless they result in a certificate issuance or other significant action that is logged for audit purposes.

7. Data Sharing and Recipients

We do not sell your personal data. We share data with the following categories of recipients:

  • Cloud hosting providers: Our database and application are hosted on secure cloud infrastructure. Providers process data only on our instructions and under strict confidentiality obligations.
  • AI service providers: The LLM that powers Athena, the AI teachers, and exam grading processes your chat messages and exam answers. Providers are bound by data processing agreements and do not use your data to train their models.
  • YouTube: Videos embedded in our broadcasting rooms are served by YouTube. YouTube may set cookies and collect data subject to its own privacy policy.
  • Legal authorities: We may disclose data when required by law, court order, or to protect our rights, property, or safety.

8. International Data Transfers

Your data may be processed in countries outside the European Economic Area (EEA), including the United States (where our cloud and AI providers operate). We ensure appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission, and we assess the adequacy of data protection in the recipient country.

9. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes described in this policy:

  • Course enrollment and certificate data: Retained indefinitely, as certificates must remain verifiable and the certificate registry must be maintained permanently.
  • Waitlist data: Retained until you unsubscribe or until the Founding Cohort programme closes.
  • AI chat data: Not retained beyond the current session, except for audit logs of significant actions (e.g., certificate issuance).
  • Technical/server logs: Retained for 90 days for security and debugging purposes.

10. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): You may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You may request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): You may request deletion of your data, subject to legal retention obligations (e.g., certificate registry records cannot be deleted as they must remain verifiable).
  • Right to restrict processing (Art. 18): You may request that we limit our processing of your data in certain circumstances.
  • Right to data portability (Art. 20): You may request your data in a structured, machine-readable format.
  • Right to object (Art. 21): You may object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent (Art. 7(3)): You may withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal.

To exercise any of these rights, email info@aunetwork.org. We will respond within 30 days.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Secure cloud infrastructure with access controls
  • Regular security reviews and updates
  • Strict access controls — only authorised personnel can access personal data
  • Data minimisation — we collect only the data necessary for the stated purposes

12. Cookies

We use cookies and similar technologies on our website. See our Cookie Policy for details.

13. Children's Privacy

Our courses are designed for professionals and are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.

15. Contact and Complaints

If you have questions about this Privacy Policy or how we handle your data, contact us at info@aunetwork.org.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.