APPLIED POLICY ARTIFICIAL INTELLIGENCE COUNCIL
AP Ai Council
Human Intelligence First
Privacy Policy
An India-led, multi-jurisdiction statement of how APAiCouncil collects, uses, and protects personal data.
Effective Date: 01 March 2026
Last Updated: 28 May 2026
This document is a defensively-drafted template prepared for the Applied Policy Artificial Intelligence Council ("AP Ai Council", "the Council", "we", "us", "our"). It reflects accepted international practice as at the effective date above and is intended to support the Council’s compliance posture across India (the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025), the European Union and the United Kingdom (the General Data Protection Regulation and the UK GDPR), the State of California (the California Consumer Privacy Act as amended by the California Privacy Rights Act), and other applicable data-protection regimes. The Council recommends qualified legal review prior to publication. Bracketed placeholders must be completed.
This Privacy Policy (the "Policy") describes how Applied Policy Artificial Intelligence Council ("APAiCouncil", "we", "us", "our") collects, uses, discloses, retains, and protects Personal Data when you visit www.apaicouncil.org, any sub-domains, mobile or other digital interfaces operated by the Council (collectively, the "Website"), when you subscribe to our communications, complete a contact form, register for an event, submit an awards nomination, make a donation, apply for a programme, or otherwise interact with the Council (together, the "Services"). Capitalised terms are defined in Section 2.
The Council is constituted in India and is the "Data Fiduciary" within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") in respect of the Personal Data described in this Policy. For users in the European Economic Area, the United Kingdom, and other jurisdictions whose data-protection laws use the controller/processor taxonomy, the Council acts as the "Controller". For California consumers, the Council acts as the "Business" within the meaning of the CCPA/CPRA.
By using the Services, you acknowledge that you have read, understood, and, where lawful basis requires it, freely and expressly consented to the practices described in this Policy. If you do not agree with this Policy, do not use the Services.
· "Personal Data" / "Personal Information" means any information relating to an identified or identifiable natural person, including a Data Principal under the DPDP Act, a Data Subject under the GDPR/UK GDPR, and a Consumer under the CCPA/CPRA.
· "Processing" means any operation performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, retrieval, use, disclosure, restriction, erasure, or destruction.
· "Data Fiduciary" / "Controller" / "Business" - the entity that determines the purpose and means of Processing. Within the scope of this Policy, that entity is the Council.
· "Data Processor" / "Service Provider" - a third party that Processes Personal Data on the Council’s behalf and under its instructions.
· "Sensitive Personal Data" - categories of Personal Data afforded heightened protection under applicable law, including biometric, health, financial, genetic, racial or ethnic origin, religious belief, political opinion, sexual orientation, trade-union membership, and children’s data.
· "Cookies" - small data files stored on your device by your browser or other technologies. See the Council’s Cookie Notice.
· Newsletter subscription - your name (optional), email address, country (optional), and stated areas of interest.
· Contact and general inquiries - your name, email, organisation, role, country, and the contents of your message.
· Event registration - name, email, organization, role, dietary or accessibility requirements (only if you choose to share these), photograph if you submit one for an attendee badge.
· Awards and programme submissions - nominee/applicant details, supporting materials, references, biographical information, and any documents you choose to upload.
· Donations - donor name, email, billing address, country of residence, donation amount, payment instrument details (handled by authorised payment service providers; the Council does not store full payment instrument numbers), and information required to comply with the Foreign Contribution (Regulation) Act, 2010 ("FCRA") and applicable tax law.
· Correspondence - emails, postal mail, call notes, and any other content you share when you communicate with the Council.
· Device and connection data - IP address, approximate location (derived from IP), browser type and version, operating system, device identifiers, language preferences, referring URL, and access timestamps.
· Usage data - pages visited, time spent on pages, links clicked, scroll depth, navigation paths, downloads, search terms entered on the Website, and similar interaction data.
· Cookies and similar technologies - see Section 11 and the Cookie Notice.
· Server and security logs - including diagnostic data, error traces, and information necessary to detect, prevent, and respond to attempted fraud, abuse, or unauthorised access.
· Third-party identity providers, payment processors, and event platforms that you use to interact with the Services.
· Publicly available sources where the Council relies on lawful basis for due diligence or anti-fraud purposes.
· Partner organisations that co-host events or programmes, where you have consented to such sharing.
We Process Personal Data only for specified, explicit, and legitimate purposes. The lawful basis for each purpose under the relevant regime is identified below:
· To operate, maintain, and improve the Services - performance of a contract (GDPR Art. 6(1)(b)); legitimate interests (GDPR Art. 6(1)(f)); legitimate use under Section 7 of the DPDP Act.
· To deliver the communications you have subscribed to - your consent (GDPR Art. 6(1)(a); DPDP Act Section 6).
· To respond to inquiries, applications, nominations, and event registrations - performance of a contract, your consent, or legitimate interests, as applicable.
· To process donations and meet legal obligations relating to such donations - compliance with a legal obligation (GDPR Art. 6(1)(c)); compliance with the FCRA, the Income-tax Act, 1961, and the rules thereunder.
· To analyse and improve content, audience reach, and Service usage in aggregate or de-identified form - legitimate interests; legitimate use.
· To protect the security of the Services, prevent and investigate fraud or abuse, and enforce our Terms of Use - legitimate interests; compliance with legal obligations.
· To comply with applicable law, including responses to lawful requests by public authorities - compliance with a legal obligation.
· To exercise or defend legal claims - legitimate interests; performance of a legal claim.
Where the Council relies on your consent as the lawful basis, you have the right to withdraw consent at any time, without affecting the lawfulness of Processing carried out before withdrawal. Withdrawal of consent may limit the Council’s ability to provide certain Services.
We do not sell or rent Personal Data. We disclose Personal Data only as described below:
We engage trusted third-party service providers to support the operation of the Services, under written agreements that obligate them to Process Personal Data only on documented instructions, to apply appropriate technical and organisational measures, and to assist the Council with its compliance obligations. Current categories include:
· Website hosting and domain services - GoDaddy.com, LLC and its affiliates ("GoDaddy"), which provides hosting infrastructure on which the Website operates.
· Analytics - Google LLC ("Google"), through Google Analytics, which assists us in understanding aggregate Service usage. Google may further process data in accordance with its own policies and the data-processing terms agreed with the Council.
· Email and communications platforms used to deliver newsletters and respond to inquiries.
· Payment processors authorised under applicable financial regulation to process donations.
· Event management and registration platforms.
· Professional advisors (auditors, lawyers, accountants) and information-security service providers.
We may disclose Personal Data when we believe in good faith that disclosure is required or permitted by law, including in response to lawful requests from courts, regulators, law-enforcement agencies, the Data Protection Board of India, supervisory authorities under the GDPR/UK GDPR, the California Privacy Protection Agency, or other competent authorities, or where necessary to protect the rights, property, or safety of the Council, our users, or others.
If the Council undergoes a merger, amalgamation, restructuring, acquisition of all or substantially all of its assets, dissolution, or similar event, Personal Data may be transferred as part of the transaction, subject to obligations of confidentiality and compliance with applicable data-protection law.
We may share Personal Data with co-organisers of joint events or programmes, only with your knowledge and, where required, your consent.
The Council is headquartered in India. Service providers and infrastructure on which the Services depend may be located in India, the United States, the European Union, the United Kingdom, and other jurisdictions. By using the Services, you understand that your Personal Data may be transferred to, stored in, and Processed in jurisdictions other than your own.
Where Personal Data is transferred outside India, the Council acts in accordance with Section 16 of the DPDP Act and any notifications issued by the Central Government thereunder. Where Personal Data of EEA, UK, or Swiss Data Subjects is transferred to a country that has not been recognised as providing an adequate level of protection, the Council relies on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and additional supplementary measures where necessary.
We retain Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, tax, or reporting requirements, and to enforce or defend legal claims. Indicative retention periods are as follows; the Council reserves the right to extend a retention period where applicable law so requires:
· Newsletter subscription - until you unsubscribe or three years of inactivity, whichever is earlier.
· Contact form correspondence - up to three years from the close of the matter to which the correspondence relates.
· Event registration data - up to three years from the date of the event.
· Donation records - for the period required by the FCRA, the Income-tax Act, 1961, and applicable accounting law, which may extend to eight years or more.
· Analytics data - typically de-identified or aggregated; identifiable analytics data retained no longer than 14 months absent legal need.
· Security and server logs - typically up to 180 days, longer where required for security investigations or legal compliance.
On expiry of the applicable retention period, Personal Data is deleted, destroyed, or irreversibly anonymised, except where retention is required by applicable law or necessary for the establishment, exercise, or defence of legal claims.
The Council implements reasonable and appropriate technical and organisational measures designed to safeguard Personal Data against unauthorised or unlawful Processing, accidental loss, destruction, or damage. These measures include access controls, encryption in transit, vendor due diligence, security logging, and personnel training. No method of transmission over the internet or method of electronic storage is wholly secure, and the Council cannot guarantee absolute security.
Where the Council becomes aware of a Personal Data breach that is required to be reported under the DPDP Rules, the GDPR, the UK GDPR, the CCPA/CPRA, or other applicable law, the Council will notify the Data Protection Board of India, the relevant supervisory authority, and, where required, affected Data Principals or Data Subjects in the manner and within the time frames prescribed by such law.
Subject to the DPDP Act and the DPDP Rules, you have the following rights:
· Right to information about the Processing of your Personal Data.
· Right to correction, completion, updating, and erasure of your Personal Data.
· Right of grievance redress with the Council and, where applicable, with the Data Protection Board of India.
· Right to nominate another individual to exercise your rights in the event of death or incapacity.
· Right to withdraw consent at any time, where Processing is based on consent.
If you are in the EEA, the United Kingdom, or Switzerland, you have, in addition:
· Right of access to your Personal Data.
· Right to rectification of inaccurate or incomplete data.
· Right to erasure (the "right to be forgotten"), subject to applicable exceptions.
· Right to restriction of Processing.
· Right to object to Processing based on legitimate interests, and to object to direct marketing at any time.
· Right to data portability in respect of data Processed by automated means on the basis of consent or contract.
· Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
· Right to lodge a complaint with a supervisory authority, including the Information Commissioner’s Office (United Kingdom) or the data-protection authority of your habitual residence.
If you are a California consumer, you have, subject to the CCPA/CPRA:
· Right to know what categories and specific pieces of Personal Information have been collected, the sources of collection, the purposes for collection, and the categories of third parties with whom Personal Information has been shared.
· Right to delete Personal Information collected from you, subject to applicable exceptions.
· Right to correct inaccurate Personal Information.
· Right to opt out of any "sale" or "sharing" of Personal Information. The Council does not sell Personal Information for monetary consideration. If our use of analytics constitutes "sharing" under the CPRA, you may exercise this right as described below.
· Right to limit the use and disclosure of Sensitive Personal Information.
· Right to non-discrimination for exercising any rights under the CCPA/CPRA.
You may exercise these rights by contacting the addresses in Section 16. You may also designate an authorised agent.
The Council honours equivalent or analogous rights granted under other applicable data-protection laws, including those of Brazil (LGPD), Australia (Privacy Act 1988), Singapore (PDPA), Japan (APPI), and Canada (PIPEDA), to the extent applicable to the relevant Processing.
To exercise any of the rights above, please write to the Council’s Data Protection Officer at [dpo@apaicouncil.org] or to the Grievance Officer at [grievance@apaicouncil.org]. We may need to verify your identity before acting on your request. We endeavour to respond within the timelines prescribed by applicable law and, in any event, no later than thirty (30) days from receipt, subject to extensions permitted by law.
The Services are not directed to children under the age of 18 years (in India, in accordance with the DPDP Act) or under the age of 16 years (in the European Economic Area, unless a Member State law specifies a lower age) or under the age of 13 years (in the United States, under the Children’s Online Privacy Protection Act). The Council does not knowingly collect Personal Data from such children without verifiable consent of a parent or lawful guardian. If you are a parent or guardian and believe your child has provided Personal Data without your consent, please contact us and we will take appropriate steps to delete such information.
The Website uses cookies and similar technologies. For full information on the cookies used, their purposes, durations, and how to manage them, please refer to the Council’s Cookie Notice, available at www.apaicouncil.org/legal/cookies.
The Council is bound by the Foreign Contribution (Regulation) Act, 2010 and the rules made thereunder in respect of contributions of foreign origin. Where a donation falls within the scope of the FCRA, additional information may be required by law, and Processing of such information is necessary for compliance with a legal obligation. Where applicable, donations may be receipted under Section 80G of the Income-tax Act, 1961; receipt issuance requires Processing of your PAN and other prescribed details. All payment instrument data is Processed by authorised payment service providers and is not stored by the Council in unredacted form.
Some browsers transmit "Do Not Track" signals. There is no universally accepted standard for responding to such signals, and the Council does not currently respond to them. You may exercise opt-out rights as described in this Policy and the Cookie Notice.
The Services may contain links to third-party websites, services, or content. The Council is not responsible for the privacy practices of such third parties. Their Processing of your Personal Data is governed by their own privacy policies.
The Council may revise this Policy from time to time. The Effective Date and the Last Updated date at the head of this document indicate when this Policy was most recently revised. Material changes will be communicated through the Website or by direct communication where required by law. Continued use of the Services after revisions take effect constitutes acceptance of the revised Policy.
Applied Policy Artificial Intelligence Council
Registered Office:
RTIH, IIDT campus TIRUPATI, Tirupati Airport Road,
Near Celkon Company, Renigunta, Andhra Pradesh, India
Registration/CIN: U72200AP2026NPL124380
General contact: info@apaicouncil.org
The Council has appointed a Data Protection Officer for queries relating to the Processing of Personal Data. The DPO may be contacted at dpo@apaicouncil.org
In accordance with the DPDP Act, the DPDP Rules, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Council’s Grievance Officer may be contacted at grievance@apaicouncil.org . Complaints will be acknowledged within twenty-four (24) hours and addressed within fifteen (15) days, or such other period as may be prescribed.
Where the Council is required to designate a representative under Article 27 of the GDPR or the UK GDPR, the representative’s contact details will be published on the Website.
You have the right to lodge a complaint with the Data Protection Board of India, the data-protection authority of your habitual residence in the EEA, the UK Information Commissioner’s Office, the California Privacy Protection Agency, or any other competent authority. The Council requests that you contact the DPO or Grievance Officer first, so that we have an opportunity to address your concerns.
© 2026-27 Applied Policy Artificial Intelligence Council. All Rights Reserved.
Human Intelligence First
Copyright © 2026 . All rights reserved. Applied Policy Artificial Intelligence Council (APAiC) Uses Trademarks.
Content is licensed under CC BY-NC-ND 4.0. To view a copy of this license Click Here
Global Ai Governance Council

Welcome to a global initiative dedicated to Artificial Intelligence governance, ethics, and policy research.
Our mission is to promote Human Intelligence First by encouraging responsible innovation, ethical AI systems, and transparent digital governance.
We work with researchers, policymakers, technologists, and institutions to develop trustworthy AI frameworks, responsible technology standards, and public policy guidance that protects society while advancing innovation.
Explore our research, policy initiatives, and global collaborations shaping the future of ethical artificial intelligence.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.