Privacy Policy
Last updated: . Effective from:
The Law for AI Safety Institute (“Law for AI Safety”, “we”, “us”, “our”) takes the protection of your privacy seriously and handles your personal data (“your data”) with care.
This policy explains what data we collect through lawforaisafety.org, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers the two things you can do on this site: applying to work with us, and subscribing to our newsletter.
If you have any questions after reading this policy, please get in touch.
1. Who we are
The Law for AI Safety Institute is currently in the process of being established in Belgium and is not yet registered. It is the controller of the personal data described in this policy. This means we determine the purposes and the means of the processing. If you have questions about this policy or how we handle your data, contact us at info@lawforaisafety.org. We will add our legal form, enterprise number, and registered office here once registration is complete.
2. What data we collect
What we hold depends on how you interact with us. Below is the full set.
If you apply to work with us
You verify your identity through one of three routes, and we collect different data depending on which one you use:
- LinkedIn sign-in: we receive your name, email address, and profile photo directly from LinkedIn once you confirm on their site. We never see your password. This data is provider-verified.
- Google sign-in: as above, with your name, email address, and profile photo coming directly from Google.
- Name and email only, with no identity verification: if you don't use LinkedIn or Google, you can type your name and email directly. We email a link to that address, and your application is only submitted once you open the link and confirm. That shows you can read mail at the address and nothing more. Your name is self-reported and unverified. We have no proof it's accurate, and our reviewers are told to treat it that way.
If you use LinkedIn or Google, you sign in on their site rather than ours, and they confirm those details back to us. They act as controllers of your data in their own right, under their own privacy policies, rather than on our instructions. We never send them your application, but signing in does tell them you have used your account here.
Alongside identity verification, the application form collects:
- Organisation or firm (optional, self-reported)
- LinkedIn profile URL (optional, self-reported)
- A CV/résumé file, PDF only, up to 5 MB (optional)
- A written position statement describing your role and relevance (optional)
- General comments (optional)
- Whether you'd like to also join our newsletter
You must provide at least one of a LinkedIn URL, a CV, or a position statement, so we have something to assess your professional background against.
If you subscribe to our newsletter only
Just your email address, plus the confirmation status and timestamp of your double opt-in click.
Technical and anti-abuse data
- Your IP address, used for rate-limiting and passed to Cloudflare Turnstile (see below) to verify you're not a bot. We never store the address itself. To count requests we keep a keyed one-way hash of it for up to an hour, then delete it.
- Signals collected by Cloudflare Turnstile as part of its bot challenge, governed by Cloudflare's own privacy policy.
3. CVs and application materials
If you upload a CV, it is validated server-side before storage and kept in private object storage. It is never publicly accessible. Reviewers view it through a sandboxed, in-browser viewer rather than downloading it. Your CV is deleted automatically as soon as a decision is made on your application, or after 24 hours if you never complete the sign-in or email confirmation step.
4. Why we collect your data
We process your data only for the purposes set out below:
- To assess and decide on applications to work with us
- To notify you of the outcome of your application by email
- To add you to our mailing list and send you our newsletter, if you've opted in
- To detect duplicate or repeat submissions, and to give reviewers context if you've applied before
- To protect the site against spam and automated abuse
- If your application is approved, to invite you to our Slack workspace
We do not use your data for automated decision-making or profiling. Every application is read and decided by a person.
5. Our legal basis for processing
- Consent: newsletter signups, whether standalone or via the application form's opt-in checkbox, confirmed by double opt-in for standalone signups. You can withdraw consent at any time by unsubscribing.
- Legitimate interests: assessing applications from legal professionals wanting to work with us, and preventing fraudulent or automated submissions, weighed against your interests and rights.
- Legal obligations: where we are required to retain or disclose data by law.
6. How long we keep your data
We do not keep your data longer than is necessary for the purpose it was collected for. In practice:
- Started but never completed an application, meaning sign-in or email confirmation was not finished: deleted automatically after 24 hours, including any uploaded CV.
- Newsletter signup you never confirmed: deleted automatically once the confirmation link expires, after 7 days.
- Application awaiting review: kept until a reviewer makes a decision.
- Decided, whether approved or rejected: your full application record (name, email, CV, profile photo, everything you submitted) is deleted immediately once the decision is made and you've been notified. We retain only a one-way cryptographic hash of your email address, together with the outcome, so we can recognise a repeat application. The hash cannot be reversed back to your email address, though it still counts as data about you, and if you ask us to erase your data we delete the hash as well. For rejections only, the reviewer's internal notes are kept alongside the hash and are deleted with it; reviewers are instructed not to include your name or other identifying details in those notes. We also keep an internal record of which reviewer made the decision and when, linked to the same hash. If you ask us to erase your data, that link is removed along with the hash.
- Newsletter subscribers: your email is kept for as long as you remain subscribed. You can unsubscribe at any time via the link in any newsletter email.
- Rate-limiting counters, keyed by a one-way hash of your IP address: deleted within an hour.
8. International data transfers
Some of our processors are outside the EEA, and our email provider uses sub-processors that are. Every such transfer is covered by a legal safeguard:
- Our bot-protection, hosting, and team messaging providers are certified under the EU-US Data Privacy Framework, and each falls back on the European Commission's Standard Contractual Clauses if that certification ceases to apply.
- Our email provider builds the Standard Contractual Clauses into its data processing agreement for transfers to its sub-processors outside the EEA. Its own servers are within it; the transfers arise from a handful of its suppliers.
10. How we protect your data
We take appropriate technical and organisational measures to secure your data against loss, theft, and unauthorised access:
- Data in transit is encrypted (HTTPS/TLS).
- Uploaded CVs are validated server-side (file signature, size cap) before storage, and viewed by reviewers only through a sandboxed in-browser viewer, not downloaded to a reviewer's device.
- Access to the internal system where applications are reviewed is restricted to a specific list of authorised people, each signed in to an authenticated session.
- Automated submissions are filtered by bot-detection and rate limiting before they reach our systems.
- Decisions and erasures made by reviewers are recorded in an internal audit log, so any action can be traced to the person who took it.
11. Your rights
Subject to applicable law, you have the following rights in relation to your data:
- Right of access: you can ask what data we hold about you.
- Right to rectification: you can have inaccurate or incomplete data corrected.
- Right to erasure: you can ask us to delete your data.
- Right to restriction: you can ask us to limit how we process your data.
- Right to object: you can object to our processing of your data where we rely on legitimate interests, which is the basis on which we assess applications.
- Right to data portability: where we rely on your consent, which currently means the newsletter, you can ask for a copy of that data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: where we rely on consent, you can withdraw it at any time, without affecting processing that already took place.
12. How to exercise your rights
To exercise any of these rights, contact us at info@lawforaisafety.org.
Before we act on a request to see or delete your data, we need to know it really comes from you, so that we don't hand over or destroy someone else's data on a stranger's say-so. Your email address is the only identifier we hold for you, so showing that you control it is enough: normally that just means writing to us from that address, or confirming a one-time code we send to it. We will not ask you for a copy of a passport or identity card to deal with a request about data you gave us by email.
We will respond within one month. If a request is unusually complex we may take up to two further months, and we will tell you inside the first month if that happens.
13. Complaints
If you are unhappy with how we handle your data, please tell us first. We would rather fix it directly. You also have the right to complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), and to take legal action if you believe your rights have been infringed.
- Address: Drukpersstraat 35, 1000 Brussels, Belgium
- Email: contact@apd-gba.be
- Website: www.dataprotectionauthority.be
14. Children's data
This site is intended for legal professionals and is not directed at children. We do not knowingly collect data from children.
15. Changes to this policy
We may update this policy from time to time. Changes are published on this page and take effect from the date of publication, which is shown as the “Last updated” date at the top.
16. Contact us
Questions about this policy or how we handle your data: info@lawforaisafety.org.