Legal

Privacy Notice

Last updated 18 August 2026

01Who is responsible for your data

Illicit financial flows, trading as VERITAS AML Academy, publisher of illicitfinancialflows.org, is the data controller for personal data processed through this site. Contact us at the correspondence address in the footer.

02What we collect and why

  • Account data — name, email address, password hash, institution. Used to create and secure your account and to give you access. Legal basis: performance of a contract.
  • Learning data — lesson progress, quiz attempts and scores, essay submissions, certificate and CPD records. Used to deliver the programme, mark work and issue verifiable certificates. Legal basis: performance of a contract.
  • Institutional data — cohort membership, seat allocation and aggregate completion reporting shared with the organisation that bought your seat. Legal basis: contract and legitimate interests of the institution.
  • Subscription records — plan, status, billing period and the subscription and customer identifiers returned by our payment provider. We do not receive or store card details. Legal basis: contract.
  • Support messages — correspondence you send us. Legal basis: legitimate interests in answering you.
  • Technical and usage data — IP address, device and browser information, request logs and error reports. Used for security, abuse prevention and improving the materials. Legal basis: legitimate interests.

We do not sell personal data and we do not use your essay submissions to train commercial AI models.

03Who we share it with

  • hosting, database, authentication and email infrastructure providers;
  • Paddle.com, our Merchant of Record, for the sale of memberships and seat licences, subscription management, payments, tax compliance and invoicing;
  • the institution that purchased your seat, for cohort and completion reporting;
  • professional advisers (legal, accounting) where necessary;
  • public authorities where we are required by law to disclose.

04International transfers

Our providers may process data outside the EEA/UK. Where that happens we rely on adequacy decisions or the European Commission's Standard Contractual Clauses, together with encryption in transit and at rest.

05How long we keep it

Account and learning records are kept while your account is active and for 24 months afterwards, so that certificates and CPD claims remain verifiable. Certificate verification records are retained in a minimised form for 5 years. Billing records are kept for the period required by tax law. Technical logs are kept for up to 12 months. After that, data is deleted or anonymised.

06Your rights

You have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent where processing rests on consent. We respond within one month. You may also complain to your data protection supervisory authority — in Germany, the state authority for North Rhine-Westphalia.

07Security

Access to learner data is protected by authenticated sessions and row-level database policies, administrative material is held in a private store behind short-lived signed links, and traffic is encrypted in transit. Access is limited to those who need it to run the programme.

08Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, remember your progress and secure checkout. We do not run advertising or cross-site tracking cookies. You can clear or block storage in your browser, but signed-in features will stop working.

09Children

The programme is intended for university students and working professionals. We do not knowingly collect data from children under 16.