Privacy Policy

Last updated: . Effective from:

The Law for AI Safety Institute (“Law for AI Safety”, “we”, “us”, “our”) takes the protection of your privacy seriously and handles your personal data (“your data”) with care.

This policy explains what data we collect through lawforaisafety.org, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers the two things you can do on this site: applying to work with us, and subscribing to our newsletter.

If you have any questions after reading this policy, please get in touch.

1. Who we are

The Law for AI Safety Institute is currently in the process of being established in Belgium and is not yet registered. It is the controller of the personal data described in this policy. This means we determine the purposes and the means of the processing. If you have questions about this policy or how we handle your data, contact us at info@lawforaisafety.org. We will add our legal form, enterprise number, and registered office here once registration is complete.

2. What data we collect

What we hold depends on how you interact with us. Below is the full set.

If you apply to work with us

You verify your identity through one of three routes, and we collect different data depending on which one you use:

  • LinkedIn sign-in: we receive your name, email address, and profile photo directly from LinkedIn once you confirm on their site. We never see your password. This data is provider-verified.
  • Google sign-in: as above, with your name, email address, and profile photo coming directly from Google.
  • Name and email only, with no identity verification: if you don't use LinkedIn or Google, you can type your name and email directly. We email a link to that address, and your application is only submitted once you open the link and confirm. That shows you can read mail at the address and nothing more. Your name is self-reported and unverified. We have no proof it's accurate, and our reviewers are told to treat it that way.

If you use LinkedIn or Google, you sign in on their site rather than ours, and they confirm those details back to us. They act as controllers of your data in their own right, under their own privacy policies, rather than on our instructions. We never send them your application, but signing in does tell them you have used your account here.

Alongside identity verification, the application form collects:

  • Organisation or firm (optional, self-reported)
  • LinkedIn profile URL (optional, self-reported)
  • A CV/résumé file, PDF only, up to 5 MB (optional)
  • A written position statement describing your role and relevance (optional)
  • General comments (optional)
  • Whether you'd like to also join our newsletter

You must provide at least one of a LinkedIn URL, a CV, or a position statement, so we have something to assess your professional background against.

If you subscribe to our newsletter only

Just your email address, plus the confirmation status and timestamp of your double opt-in click.

Technical and anti-abuse data

  • Your IP address, used for rate-limiting and passed to Cloudflare Turnstile (see below) to verify you're not a bot. We never store the address itself. To count requests we keep a keyed one-way hash of it for up to an hour, then delete it.
  • Signals collected by Cloudflare Turnstile as part of its bot challenge, governed by Cloudflare's own privacy policy.

3. CVs and application materials

If you upload a CV, it is validated server-side before storage and kept in private object storage. It is never publicly accessible. Reviewers view it through a sandboxed, in-browser viewer rather than downloading it. Your CV is deleted automatically as soon as a decision is made on your application, or after 24 hours if you never complete the sign-in or email confirmation step.

4. Why we collect your data

We process your data only for the purposes set out below:

  • To assess and decide on applications to work with us
  • To notify you of the outcome of your application by email
  • To add you to our mailing list and send you our newsletter, if you've opted in
  • To detect duplicate or repeat submissions, and to give reviewers context if you've applied before
  • To protect the site against spam and automated abuse
  • If your application is approved, to invite you to our Slack workspace

We do not use your data for automated decision-making or profiling. Every application is read and decided by a person.

6. How long we keep your data

We do not keep your data longer than is necessary for the purpose it was collected for. In practice:

  • Started but never completed an application, meaning sign-in or email confirmation was not finished: deleted automatically after 24 hours, including any uploaded CV.
  • Newsletter signup you never confirmed: deleted automatically once the confirmation link expires, after 7 days.
  • Application awaiting review: kept until a reviewer makes a decision.
  • Decided, whether approved or rejected: your full application record (name, email, CV, profile photo, everything you submitted) is deleted immediately once the decision is made and you've been notified. We retain only a one-way cryptographic hash of your email address, together with the outcome, so we can recognise a repeat application. The hash cannot be reversed back to your email address, though it still counts as data about you, and if you ask us to erase your data we delete the hash as well. For rejections only, the reviewer's internal notes are kept alongside the hash and are deleted with it; reviewers are instructed not to include your name or other identifying details in those notes. We also keep an internal record of which reviewer made the decision and when, linked to the same hash. If you ask us to erase your data, that link is removed along with the hash.
  • Newsletter subscribers: your email is kept for as long as you remain subscribed. You can unsubscribe at any time via the link in any newsletter email.
  • Rate-limiting counters, keyed by a one-way hash of your IP address: deleted within an hour.

7. Who we share your data with

We don't sell your personal data. We share it only:

  • Within our own team, with the reviewers and staff who need access to do their work.
  • With processors: service providers acting on our instructions and contractually obliged to protect your data. These are listed below.
  • With third parties, where legally required or necessary to provide the service you asked for.

The kinds of processor we use, each for the specific purpose described:

  • A bot-protection provider, to check that submissions to our forms are not automated.
  • An email provider, to send transactional emails (your application outcome, newsletter confirmation) and to manage our newsletter mailing list. You can unsubscribe from the newsletter at any time using the unsubscribe link in any newsletter email.
  • A team messaging provider, which hosts the workspace you are invited to if your application is approved. Before inviting you, a reviewer checks whether you are already a member.
  • A hosting provider, which runs this site, holds application data in a managed database, and keeps uploaded CVs in private object storage.

8. International data transfers

Some of our processors are outside the EEA, and our email provider uses sub-processors that are. Every such transfer is covered by a legal safeguard:

  • Our bot-protection, hosting, and team messaging providers are certified under the EU-US Data Privacy Framework, and each falls back on the European Commission's Standard Contractual Clauses if that certification ceases to apply.
  • Our email provider builds the Standard Contractual Clauses into its data processing agreement for transfers to its sub-processors outside the EEA. Its own servers are within it; the transfers arise from a handful of its suppliers.

9. Cookies

The public site sets no analytics, advertising, or tracking cookies.

  • Cloudflare Turnstile may set its own cookies as part of its bot challenge, governed by Cloudflare's privacy policy.
  • If you apply using LinkedIn or Google sign-in, we set one strictly necessary cookie when you submit the form. It holds a random value that lets us check the sign-in is completed in the same browser that started it, so nobody else's application can be attached to your identity. It contains no personal data, is not used for tracking, and expires within an hour.

10. How we protect your data

We take appropriate technical and organisational measures to secure your data against loss, theft, and unauthorised access:

  • Data in transit is encrypted (HTTPS/TLS).
  • Uploaded CVs are validated server-side (file signature, size cap) before storage, and viewed by reviewers only through a sandboxed in-browser viewer, not downloaded to a reviewer's device.
  • Access to the internal system where applications are reviewed is restricted to a specific list of authorised people, each signed in to an authenticated session.
  • Automated submissions are filtered by bot-detection and rate limiting before they reach our systems.
  • Decisions and erasures made by reviewers are recorded in an internal audit log, so any action can be traced to the person who took it.

11. Your rights

Subject to applicable law, you have the following rights in relation to your data:

  • Right of access: you can ask what data we hold about you.
  • Right to rectification: you can have inaccurate or incomplete data corrected.
  • Right to erasure: you can ask us to delete your data.
  • Right to restriction: you can ask us to limit how we process your data.
  • Right to object: you can object to our processing of your data where we rely on legitimate interests, which is the basis on which we assess applications.
  • Right to data portability: where we rely on your consent, which currently means the newsletter, you can ask for a copy of that data in a structured, commonly used, machine-readable format.
  • Right to withdraw consent: where we rely on consent, you can withdraw it at any time, without affecting processing that already took place.

12. How to exercise your rights

To exercise any of these rights, contact us at info@lawforaisafety.org.

Before we act on a request to see or delete your data, we need to know it really comes from you, so that we don't hand over or destroy someone else's data on a stranger's say-so. Your email address is the only identifier we hold for you, so showing that you control it is enough: normally that just means writing to us from that address, or confirming a one-time code we send to it. We will not ask you for a copy of a passport or identity card to deal with a request about data you gave us by email.

We will respond within one month. If a request is unusually complex we may take up to two further months, and we will tell you inside the first month if that happens.

13. Complaints

If you are unhappy with how we handle your data, please tell us first. We would rather fix it directly. You also have the right to complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), and to take legal action if you believe your rights have been infringed.

14. Children's data

This site is intended for legal professionals and is not directed at children. We do not knowingly collect data from children.

15. Changes to this policy

We may update this policy from time to time. Changes are published on this page and take effect from the date of publication, which is shown as the “Last updated” date at the top.

16. Contact us

Questions about this policy or how we handle your data: info@lawforaisafety.org.