Introduction
The International Academy of Aesthetic Innovation (IAAI) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your data when you visit our website, enroll in our courses, or use any of our services.
By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this policy, please do not access or use our services.
Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide when you register on our platform, enroll in courses, fill out forms, subscribe to our newsletter, or submit course evaluations. This includes:
- Full name and professional title
- Email address and phone number
- Professional credentials and qualifications
- Billing and shipping address
- Medical practice details and specialization
Automatically Collected Information
When you access our platform, we automatically collect certain technical information, including:
- IP address and geographic location
- Browser type and version
- Device type and operating system
- Pages visited and time spent on each page
- Referral source and exit pages
Course & Learning Data
To deliver and improve our educational services, we collect data related to your learning activities:
- Course enrollment history and progress
- Quiz and assessment results
- Certificates earned and completion dates
- Video watch history and engagement metrics
- Forum participation and discussion contributions
Payment Information
Payment processing is handled securely through our trusted payment partners, CCAvenue and Stripe. We collect and store:
- Transaction IDs and payment confirmation details
- Billing name and address
- Last four digits of your payment card (for reference only)
- Payment method type and currency
We never store full credit card numbers, CVV codes, or other sensitive payment credentials on our servers.
How We Use Your Information
We use the information we collect for the following purposes:
Course Delivery
To provide, manage, and personalize your learning experience across our training programs.
Communication
To send enrollment confirmations, course updates, schedule changes, and certificate notifications.
Payment Processing
To process transactions, issue invoices, manage refunds, and maintain billing records.
Platform Improvement
To analyze usage patterns, improve our platform, and develop new features and courses.
Compliance
To verify professional credentials and ensure compliance with medical education standards.
Marketing (with consent)
To send promotional materials, newsletters, and course recommendations only when you have opted in.
Security
To detect, prevent, and respond to fraud, abuse, security risks, and technical issues.
Legal Obligations
To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
We will NEVER sell, rent, or trade your personal information to third parties for their marketing purposes.
How We Share Your Information
We may share your information with the following categories of recipients, only as necessary:
Service Providers
Trusted third-party providers who assist us with payment processing (CCAvenue, Stripe), cloud hosting, email delivery, and analytics. These providers are contractually obligated to protect your data.
Certification Bodies
Accrediting organizations and certification authorities to verify and issue professional certifications and continuing education credits.
Instructors
Course instructors may access limited student information (name, enrollment status, assessment results) to facilitate effective teaching and evaluation.
Legal Requirements
We may disclose your information when required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of the business transaction. You will be notified of any such change.
Your Privacy Rights
Depending on your location and applicable laws (including GDPR and CCPA), you may have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Correction | Request correction of inaccurate or incomplete personal data. |
| Deletion | Request deletion of your personal data, subject to legal retention requirements. |
| Restriction | Request restriction of processing of your personal data in certain circumstances. |
| Portability | Request your data in a structured, commonly used, machine-readable format. |
| Object | Object to processing of your personal data for direct marketing or legitimate interest purposes. |
| Opt-Out | Opt out of the sale or sharing of your personal information (CCPA). |
| Complaint | Lodge a complaint with a supervisory authority if you believe your rights have been violated. |
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
International Data Transfers
IAAI operates training centers and maintains infrastructure across multiple jurisdictions, including Turkey, the United Arab Emirates, and Italy. Your personal data may be transferred to and processed in these countries.
When we transfer your data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Compliance with applicable data protection frameworks and regulations
- Ensuring equivalent security measures are maintained across all locations
Data Security
We implement robust technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
- Encryption in transit using SSL/TLS protocols for all data transmissions
- Role-based access controls limiting data access to authorized personnel only
- Secure cloud servers with enterprise-grade infrastructure and firewalls
- Regular security audits and vulnerability assessments
- Password protection using industry-standard bcrypt hashing algorithms
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Cookies and Tracking
Our platform uses cookies and similar tracking technologies to enhance your experience. For detailed information about our cookie practices, please visit our Cookie Policy.
We use the following types of cookies:
Essential
Required for platform functionality, authentication, and security. Cannot be disabled.
Analytics
Help us understand how visitors interact with our platform to improve our services.
Preference
Remember your settings, language choices, and personalization preferences.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period |
|---|---|
| Active Account Data | For the duration of your active account |
| Course Records & Certificates | 7 years after course completion |
| Payment & Transaction Records | 7 years (legal/tax compliance) |
| Marketing Preferences | Until you opt out or withdraw consent |
| Inactive Account Data | 3 years after last activity, then deleted |
Children's Privacy
Our services are intended for individuals who are at least 18 years of age. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will take immediate steps to delete such information from our records. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will notify you through:
- Posting the updated policy on this page with a revised "Last Updated" date
- Sending an email notification to your registered email address for material changes
- Displaying an in-platform notification upon your next login
Your continued use of our services after any changes to this policy constitutes your acceptance of the updated terms.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us:
Email: [email protected]
Subject Line: Privacy Inquiry
Response Time: We aim to respond to all privacy-related inquiries within 30 days.