2. Types of Data We Collect and How It Is UsedTo help you understand how your data is handled, here is a summary of the types of data we may collect, their purposes, whether they are used in AI training, and our disclosure policy.
Type of Data / Purpose of Collection / Analyzed via AI- Full Name / Enrollment, certification, communication / No
- Email Address / Course communication, updates, follow-ups, regulatory compliance / No
- Phone Number, Mailing Address / Contact for support and scheduling, regulatory compliance / No
- Payment Details / Tuition processing / No
- Job Title, Employer / Contextualizing learning, reporting anonymized sector trends / No
- Reflective Journal Entries / Supporting knowledge retention, program design / Yes – anonymized only
- Feedback (Pre & Post-Course) / Quality assurance, content improvement / Yes – anonymized only
- Erickson + Platform Interactions / Enhancing client experience, feature improvement / No
- Website Usage Data (pages visited, etc.) / Improving navigation and educational relevance / Yes – anonymized only
- IP Address, Browser, and Device Info / Website functionality and security monitoring / No
- Audio/Video Recordings (Course Sessions) / Quality review, optional replay for learners / No (unless anonymized for research)
3. Our Approach to AI and Data AnonymizationWe use AI responsibly to enhance learning while protecting your privacy:
- No personally identifiable data (PII) is processed by AI systems
- Only aggregated, anonymized data is used for analysis
- All identifiers are removed or encrypted before processing
- Data is stored securely with access controls and regular audits
4. Legal Basis for ProcessingWe process your data based on:
✓
Contractual necessity (to deliver our services)
✓
Legal compliance (under UAE PDPL and other regulations)
✓
Legitimate interest (service improvements with minimal privacy impact)
✓
Explicit consent (where required by law)
5. Data Sharing and Third PartiesWe may share data with:
-
Payment processors (UAE-licensed providers)
-
Cloud service providers (with data centers meeting UAE standards)
-
Accreditation bodies (e.g., ICF for certification verification)
-
Government authorities (when legally required)
All third parties must comply with:
- Strict confidentiality agreements
- UAE PDPL requirements
- Our data protection standards
6. International Data TransfersWhen transferring data outside UAE:
- We use
PDPL-approved mechanisms (standard contractual clauses)
- Ensure
equivalent protection standards- Maintain
transparency about storage locations
7. Data Security MeasuresWe implement:
-
Encryption (in transit and at rest)
-
Access controls (role-based permissions)
-
Regular security audits-
Staff training on data protection
8. Your Rights Under UAE PDPLYou have the right to:
✓ Access your personal data
✓ Request correction of inaccurate data
✓ Withdraw consent (where applicable)
✓ Request deletion (subject to legal requirements)
✓ Object to processing
✓ Request data portability
Response time: We will address all requests within
30 days as required by UAE law.
9. Data Retention PeriodWe retain data:
-
For active clients: Duration of service + 5 years
-
For financial records: 7 years (as required by UAE law)
-
Anonymized data: May be retained indefinitely for research
10. Cookies and Tracking TechnologiesWe use:
-
Essential cookies (for website functionality)
-
Analytics cookies (anonymized data only)
-
Marketing cookies (only with consent)
You can manage preferences via:
- Browser settings
- Our cookie consent banner
11. Children's PrivacyOur services are not designed for users under 18. If we inadvertently collect a minor's data, we will
delete it immediately upon notification.
12. Policy UpdatesWe will:
- Notify users of
material changes- Post updates on our website
- Update the "Last Revised" date
13. Contact InformationFor privacy requests or questions:
Email: admin@erickson.ae
Phone: +971507603664