Last updated: 26 September 2026.
AEES places transparency at the centre of its relationship with visitors, candidates, certificate holders, institutions and partners. This policy describes the data collected, the purposes, recipients, retention periods and the rights you have.
The applicable framework is Regulation (EU) 2016/679 (GDPR) and French Act No. 78-17 of 6 January 1978 on information technology, files and civil liberties. Acceptance of the certification terms is not enough to obtain consent where the law requires it.
1. Controller
Académie Européenne des Études Supérieures, 60 rue François Ier, 75008 Paris, France.
Contact: privacy@aees-edu.eu.
When providers process data on behalf of AEES (hosting, payments, messaging), they act on its instructions and only as far as necessary for the service.
2. Data collected
Depending on the interaction, AEES may collect:
- Identity and contact: name, email, telephone, country, organisation, role.
- Enquiries: contact-form message, any attachments, purpose of the request (approval, verification, partnership).
- Certification file: enrolment, preparatory pathway viewed, assessment attempts, result, certificate issued, order reference.
- Payment: amount, method, transaction reference, status. Card numbers are processed by Stripe or PayPal and are not stored by AEES.
- Technical log: session identifiers, IP address, device and browser type, pages viewed, security logs.
AEES does not ask for health data or political or religious opinions, unless you provide them spontaneously in a message. In that case they are used only to handle your request.
3. Purposes
- to reply to your requests and route the file to the right service;
- to examine an approval, an award verification or a partnership;
- to create an account, provide the preparatory pathway, the assessment and, if successful, the verifiable certificate;
- to collect fees, issue a confirmation and prevent fraud;
- to secure the Site and the continuity of the service;
- to meet legal obligations (accounts, academic evidence, replies to authorities).
4. Legal bases
- performance of a contract or pre-contractual steps (order, account, assessment, certificate);
- a legal obligation (invoicing, retention of certain records);
- AEES’s legitimate interest (security, service improvement, defence of its rights), balanced against yours;
- your consent, where required (non-essential cookies, direct marketing).
5. Recipients
Data are accessible to authorised AEES staff. They may be disclosed, strictly as necessary, to technical providers, to a partner institution if the pathway requires it, or to authorities if the law so requires.
AEES does not sell or rent any file. No data are given to outside advertisers for their own marketing.
6. Transfers outside the EU
Hosting and most processing take place in the European Union or are covered by appropriate safeguards. Some payment providers (Stripe, PayPal) may transfer data outside the EU, framed by the European Commission’s standard contractual clauses or another recognised mechanism.
7. Security
AEES implements reasonable technical and organisational measures: restricted access, HTTPS, role separation, security logs. No system is infallible, so absolute security cannot be guaranteed. If an incident is likely to affect your rights, AEES will endeavour to inform you and, where required, notify the CNIL.
8. Retention
- contact messages: for the time needed to handle them, then limited archiving;
- account, assessment and certificate: duration of the relationship, then the period needed for academic evidence and complaints;
- accounting and payment records: statutory retention periods;
- technical logs: a limited period, unless needed for security or evidence.
9. Direct marketing
AEES does not currently send automated commercial marketing. If programme information were to be sent, each message would include a simple way to opt out, and a separate consent would be collected where required.
10. Your rights
You may request access, rectification, erasure, restriction, objection and, where it applies, portability, and you may withdraw consent free of charge.
Write to privacy@aees-edu.eustating your request and providing an element that allows us to verify your identity. AEES endeavours to reply within one month. Some data (certificates, invoices) may be retained despite an erasure request where the law so requires.
11. Minors
Certifications are intended for adults. If you are the legal representative of a minor and believe an account was created without your agreement, contact us so that we can check and, if appropriate, close it.
12. Cookies
The Site uses cookies necessary for it to operate. Details and browser settings appear on the Cookies.
13. Changes
This policy may be updated to reflect a new processing activity, a provider or a change in the law. The date at the top of the page prevails. In the event of a material change, AEES will endeavour to inform the people concerned.
14. Contact and complaints
privacy@aees-edu.eu — AEES, 60 rue François Ier, 75008 Paris.
You may also refer the matter to the Commission nationale de l’informatique et des libertés (CNIL) if you consider that your rights have not been respected: www.cnil.fr.