IASS Logo
Establishing Secure Connection
Data Protection & Compliance

Privacy Policy

Last Updated: September 2026

At International Academy for Strategic Security (IASS) ("we," "our," or "us"), accessible via https://iass-academy.com/, we prioritize the confidentiality and security of the personal and organizational data of our trainees, clients, website visitors, and corporate partners.

This Privacy Policy outlines how we collect, use, process, and safeguard your information in compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR) and international data protection standards aligned with our ISO/IEC 27001 (Information Security Management) frameworks.

1. Information We Collect

We collect information necessary to deliver high-level security consulting, tactical and cyber training, certificate verification services, and operational communications.

A. Personal Data You Provide Voluntarily

Identity & Contact Data: Full name, job title, company name, phone number, email address, national identity or passport details (required for course registration, background checks, or credentialing).

Academic & Professional Data: Verification inquiries, certificate tracking numbers, educational background, and training course enrollments.

Inquiry & Consultation Data: Information submitted via our online consultation forms, contact requests, or project brief requests.

B. Technical & Usage Data (Automated Collection)

Device & Log Data: IP address, browser type, operating system, access times, pages viewed, and referral URLs.

Cookies & Tracking: We use essential and analytical cookies to optimize website performance and secure navigation. You can manage cookie preferences through your browser settings.

2. How We Use Your Information

We process personal data strictly for lawful operational, training, and compliance purposes:

Course Administration & Certification: To process course registrations, verify student certificates, issue accredited credentials, and maintain official training records.

Service Delivery: To respond to consultations, execute operational inquiries, and fulfill requests for strategic defense services.

Security & Identity Verification: To conduct required verification procedures for access to restricted training modules or high-security services.

Compliance & ISO Audits: To meet legal, regulatory, and quality audit requirements under our ISO management standards (e.g., ISO 27001, ISO 9001, ISO 18788).

System Security & Monitoring: To detect, prevent, and respond to cyber threats, security incidents, or unauthorized access to our digital infrastructure.

3. Data Protection & Security Controls

In alignment with ISO/IEC 27001, we implement rigorous physical, technical, and administrative security measures:

Encryption: Data transmitted to and from our website is protected using Transport Layer Security (TLS/SSL). Sensitive database records are protected with AES-256 encryption.

Access Control: Access to personal and corporate data is restricted strictly to authorized personnel bound by signed Non-Disclosure Agreements (NDAs).

Proactive Defense: Our internal systems and Security Operations Center (SOC) continually monitor network traffic to protect against unauthorized access, loss, or manipulation.

4. Disclosure & Data Sharing

We do not sell, rent, or trade your personal data. We may share data only under the following limited conditions:

Accreditation & Certification Bodies: To verify training credentials or fulfill international audit requirements associated with ISO and tactical accrediting authorities.

Service Providers: Trusted third-party vendors who assist in website hosting, secure infrastructure, or administrative operations under strict data processing agreements.

Legal & Security Obligations: When required by law, court order, or official governmental request to protect public safety, comply with legal process, or enforce our operational terms.

5. International Data Transfers

As a global institution, information collected through this website may be processed or transferred outside your home country. We ensure all cross-border data transfers adhere to recognized international protection mechanisms (such as Standard Contractual Clauses) to maintain data security regardless of location.

6. Your Data Rights

Depending on your location and applicable privacy laws, you have the following rights regarding your personal data:

Access & Rectification: Request a copy of the personal data we hold about you or request corrections to inaccurate records.

Erasure: Request the deletion of your personal data, subject to statutory record-retention requirements for accredited certifications.

Restriction of Processing: Request that we limit how we process your data in specific scenarios.

Data Portability: Request a copy of your data in a structured, machine-readable format.

To exercise any of these rights, please contact our Data Protection Officer using the details below.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes outlined in this policy, complete academic/training record keeping, comply with legal obligations, and satisfy ISO audit cycles.

8. External Links

Our website may contain links to third-party portals or partner sites. IASS is not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of any site you visit.

9. Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in legal, operational, or technical requirements. Updates will be posted directly to this page with an updated "Last Updated" date.

10. Contact Us

For questions regarding this Privacy Policy, your data privacy rights, or data security matters, contact our data protection team:

International Academy for Strategic Security (IASS)

Website: https://iass-academy.com/

Inquiries & Compliance: info@iass-academy.com