BECAUSE TECHNOLOGY MUST NOT TAKE AWAY OUR HUMANITY

Version: 1.0 — Draft for approval

Effective date: To be assigned upon publication

Data Controller: VIENS Krzysztof Siporski / No AI Movement™

 

 

1. About this Privacy Policy

 

1.1. This Privacy Notice / Privacy Policy (“Privacy Policy”) explains how personal data is collected, used, shared, stored and protected in connection with No AI Movement™ and the services operated under that brand.

1.2. It covers the No AI Movement™ website, enquiries and communications, No AI Declaration™, No AI Certification™, No AI Movement™ Membership, public directories and verification tools, and other official services that expressly refer to this Privacy Policy.

1.3. No AI Movement™ may introduce additional services in the future, including No AI Verifier™ and No AI Gateway™. Those services are covered by this Privacy Policy only to the extent that their actual processing is described here. Before a new service collects personal data for an additional purpose or in a materially different way, this Privacy Policy will be updated and any other information or consent required by law will be provided.

1.4. This Privacy Policy is intended for an international audience. The General Data Protection Regulation of the European Union (“GDPR”) applies where relevant, together with other mandatory data-protection laws that apply in a particular situation. A single policy cannot override additional rights or notices required by local law.

 

2. Who is responsible for your data

 

2.1. The Data Controller is:

VIENS Krzysztof Siporski / No AI Movement™

Goździówka 35A

05-304 Stanisławów

Poland

Email: office@noaimovement.com

Website: https://noaimovement.com

2.2. “We”, “us”, and “our” mean the Data Controller acting through No AI Movement™. This notice does not make No AI Movement™ a separate legal person.

2.3. Privacy questions and requests relating to personal data may be sent to the email address above.

 

3. Who and what is covered

 

3.1. This Privacy Policy applies to personal data relating to website visitors, people contacting us, No AI Declaration™ applicants and holders, No AI Certification™ applicants and holders, Membership applicants and Members, people providing contributions or reports, and representatives of organisations and other professional contacts.

3.2. It applies to noaimovement.com and to other official domains, pages, forms or digital services operated by us where this Privacy Policy is made available or expressly linked. An independent third-party website has its own privacy rules.

3.3. Information relating solely to a legal entity is not necessarily personal data. However, a business name, professional email address, name of a representative or information about a sole trader may identify a natural person and may therefore be personal data.

 

4. Personal data we may process

 

4.1. Website and technical data: IP address, device and browser information, approximate location derived from technical data, page interactions, referral source, technical logs, security events and cookie or analytics identifiers where used.

4.2. Contact and enquiry data: name, email address, telephone number, organisation, country, the content of messages and attachments, and correspondence history.

4.3. No AI Declaration™ data: identity of the declaring party; name of an individual or representative, if provided; organisation, country, email address and any other submitted contact details; selected category and subcategory; description of the activity and supporting links or materials; statements and application acknowledgements; publication choice; application correspondence; declaration ID, issue date, status and verification-related information.

4.4. No AI Certification™ data: application and identity details; selected certification scope; professional and organisational information; evidence supplied for an audit; correspondence, review findings, status and certification records; and billing information where a paid service is supplied. We will request information relevant to the particular audit rather than treating every possible category of evidence as automatically required.

4.5. Membership data: applicant or Member identity, Individual or Organization type, organisation and representative details, country, email address, optional website or profile, application and Member IDs, application decisions, membership status and dates, accepted version of the Membership Terms and its timestamp, version of this Privacy Policy acknowledged and its timestamp, optional public-directory choice, and records of contributions, approvals and membership-related correspondence.

4.6. Contributions and reports: ideas, materials, links and other content intentionally submitted for No AI Movement™ activities, and the identity and communications data needed to review such submissions. Reports about misuse or suspected violations may include information about the reporting person and the person or organisation concerned.

4.7. Transactions: where a payable service or other transaction is carried out, we may process the details needed to administer the transaction, issue accounting documents and meet tax or legal obligations. Payment service providers may process additional payment information under their own privacy notices.

4.8. Please do not submit sensitive personal information about yourself or another person unless it is genuinely necessary and we have asked for it using an appropriate process. This includes health, religious or political information, government identification documents and personal data about clients or employees. Where special-category data is exceptionally necessary, it must have a separate valid legal basis and additional protections.

 

5. Where personal data comes from

 

5.1. Most data is provided directly by you through website forms, email, applications, correspondence and materials you submit.

5.2. We may also receive data from an organisation’s authorised representative, a person submitting a report, a professional introduction, supporting materials or a publicly available professional source where relevant to a legitimate No AI Movement™ activity.

5.3. Technical data may be recorded automatically when a website or verification feature is used. Information about any applicable data obtained indirectly will be provided as required by law.

 

6. Why we process personal data and our legal grounds

 

6.1. Operating and protecting websites and services: delivering requested pages and tools, keeping services available, detecting abuse and resolving technical problems. Legal grounds, as applicable: GDPR Article 6(1)(b) (providing a requested service) and Article 6(1)(f) (our legitimate interests in service operation and security).

6.2. Responding to messages and requests: answering enquiries, keeping relevant correspondence and taking steps requested before a possible agreement. Legal grounds: Article 6(1)(b) where relevant, or Article 6(1)(f) for ordinary correspondence and professional relationships.

6.3. No AI Declaration™: receiving and assessing applications, requesting clarifications, issuing or declining declarations, generating documents and marks, keeping accurate records, handling challenges and providing verification. Legal grounds: Article 6(1)(b) for handling a requested declaration service and Article 6(1)(f) for integrity, fraud prevention and the defence of legitimate claims. Any publication based on optional consent uses Article 6(1)(a).

6.4. No AI Certification™: handling applications, carrying out agreed checks or audits, assessing supporting evidence, administering certification status and supplying a paid service where applicable. Legal grounds: Article 6(1)(b), Article 6(1)(f) for maintaining the reliability of certification and protecting against misuse, and Article 6(1)(c) where specific legal or accounting obligations apply. Public disclosure requiring consent is governed by Article 6(1)(a).

6.5. Membership: receiving and evaluating applications, deciding on membership, assigning identifiers, maintaining the internal Members register, administering status, recording the accepted Membership Terms and privacy acknowledgement, managing contributions and communication, and protecting the integrity of the system. Legal grounds: Article 6(1)(b) for requested membership and its administration, and Article 6(1)(f) for legitimate operational, security and record-integrity purposes. Optional public-directory publication uses Article 6(1)(a).

6.6. Legal duties and claims: maintaining accounting records where required, responding to lawful requests, meeting legal duties and establishing, exercising or defending claims. Legal grounds: Article 6(1)(c) and, where applicable, Article 6(1)(f).

6.7. Website analytics and optional communications: analytics or similar non-essential tracking will operate only on an appropriate legal basis and with consent where required by applicable cookie or privacy law. If we introduce optional email updates or marketing that requires consent, we will seek that consent separately. Submitting an application or acknowledging this Privacy Policy does not by itself constitute consent to marketing.

6.8. Where we rely on legitimate interests, we consider the relevant interest, the need for processing and the effects on individuals. You may object to processing based on legitimate interests in the circumstances provided by law.

 

7. Public records, declarations and certifications

 

7.1. No AI Declaration™ and No AI Certification™ include mechanisms intended to make issued documents and their status verifiable. A public entry may identify an individual where the declaring or certified party is a natural person or sole trader.

7.2. No AI Declaration™ publication is optional. An application and its processing are separate from permission to publish identifying details in a public register. An applicant who does not agree to public listing may still be assessed and issued a declaration in accordance with the applicable terms.

7.3. Where the relevant person has given explicit publication consent, publicly available declaration data may include the declaring party, declaration ID, country, category or subcategory, declared scope, issue date, status, verification link and the issued PDF or graphic mark, as applicable to the published record.

7.4. A published PDF or verification page may be copied, downloaded, indexed or retained by others. Withdrawing publication consent stops future publication under our control in accordance with applicable law, but cannot guarantee removal from independent search engines, archives, third-party copies or technically immutable records. We will take reasonable measures within our control where removal is required.

7.5. Requests to withdraw publication consent should be sent to office@noaimovement.com. A withdrawal does not automatically cancel the underlying No AI Declaration™ or No AI Certification™ and does not automatically require us to delete every internal record needed for lawful administration, integrity or legal claims.

7.6. No AI Certification™ may have additional public-verification details depending on the certification model. Before publishing any additional categories of personal data or introducing a new public certification directory, we will provide the specific information and obtain consent where required.

 

8. Digital anchoring and document verification

 

8.1. The No AI Declaration™ document-integrity system uses cryptographic SHA-256 hashes and transaction records on the Polygon blockchain to support verification of a specific PDF version. Blockchain records may include a declaration identifier, a document hash and a timestamp. The full PDF is not stored on the blockchain by this process.

8.2. A hash or identifier may still relate indirectly to an identifiable person if it can be linked to a declaration. Blockchain entries are designed to be persistent and generally cannot be edited or erased in the same way as records held in our internal systems.

8.3. The existing Document Verification process can calculate a selected PDF’s hash locally in the user’s browser and compare it with an available registry; the PDF is not uploaded to our server through that local hashing operation. Accessing external registry or blockchain links may nevertheless involve normal technical data being processed by the providers involved.

8.4. We seek to limit blockchain disclosures to what is necessary for document integrity. Privacy requests affecting related website or register records will be considered separately from the technical limits of public blockchain transactions. We cannot promise the deletion of an already confirmed blockchain transaction.

 

9. Membership records and the public Member directory

 

9.1. The internal Membership register and application records are not the same as the optional public Member directory.

9.2. If a Member gives explicit consent to public listing, the directory may display their public display name, Member ID, country, Member type, joining date and an optional website or profile link.

9.3. The public directory does not display the Member’s email address, internal Member / Active Member engagement classification, contribution history or internal notes.

9.4. A Member may withdraw their consent to public listing without ending membership. Internal records may continue to be processed where another lawful basis applies.

9.5. Acknowledgement of this Privacy Policy is a record that the applicant has received or reviewed the notice. It is not a blanket consent to all forms of personal-data processing or public disclosure.

 

10. Who may receive personal data

 

10.1. Personal data is accessible to the Data Controller and authorised service providers or collaborators to the extent necessary for their assigned tasks and subject to appropriate confidentiality and data-protection requirements.

10.2. Depending on the service, recipients may include providers of website hosting and administration, forms, email, cloud storage, documents and spreadsheets, file hosting, technical maintenance, analytics, payment or accounting services, and professional legal or audit services. The operational environment includes services such as WebWave, Formspree, Google services and Cloudflare; the particular service used depends on the process concerned.

10.3. Data deliberately placed in an optional public directory or public verification page becomes accessible to visitors and other third parties. Public blockchain data can be viewed through the blockchain network and independent explorers.

10.4. Information may be provided to public authorities or other recipients where required by applicable law, or where necessary and legally permitted to establish or defend a claim.

10.5. We do not treat submitting a form as permission to publish its contents or to share it for unrelated promotional purposes.

 

11. International processing and transfers

 

11.1. Our services are operated from Poland for an international audience. Some technical suppliers or their subprocessors may process information in countries outside the European Economic Area.

11.2. Where the GDPR applies to such a transfer, an appropriate transfer mechanism must be in place, for example a European Commission adequacy decision or appropriate contractual safeguards such as the applicable Standard Contractual Clauses, together with additional measures where required. The applicable mechanism depends on the recipient and transfer.

11.3. Information about a particular international transfer or relevant safeguards can be requested at office@noaimovement.com. Publication to a global public directory or a public blockchain has additional practical limitations described in Sections 7 and 8.

 

12. How long personal data is kept

 

12.1. We do not use one universal retention period. Data is kept only for the time justified by the particular purpose, applicable legal obligations, record integrity or legitimate claims, and is then deleted or anonymised where appropriate and technically possible.

12.2. Enquiries and correspondence: for the time needed to answer and complete the matter, with additional retention where necessary for a continuing relationship or legal claims.

12.3. Declaration and certification records: while the application is being considered and, where issued, while records are needed to administer, verify or review the declaration or certification, followed by any applicable legally justified recordkeeping period. The history of an issued identifier may need to be preserved to prevent misidentification or re-use.

12.4. Membership records: during the application process and membership, and afterwards only where necessary for documented administration, legal compliance, claims and the integrity of permanently assigned Member IDs. Rejected or withdrawn applications should not be retained indefinitely without a separate justification.

12.5. Billing records: for the period required under the applicable accounting and tax laws.

12.6. Technical, security and analytics data: according to their purpose, the applicable service settings and the law; consent-based data is subject to the relevant consent choices and lawful retention requirements.

12.7. Publicly distributed copies and confirmed blockchain records may remain outside our direct control as explained in Sections 7 and 8. A request for deletion will be examined in light of these distinctions and applicable law.

 

13. Cookies and analytics

 

13.1. Our websites may use cookies, browser storage or similar technologies for technical operation, security, preferences and, where enabled, audience measurement.

13.2. Technologies that are not strictly necessary will be used only after obtaining any consent required under applicable law. Where a consent preference tool is provided, you can use it to accept, refuse or change eligible settings. You may also manage browser settings, although blocking essential technologies can affect some website functions.

13.3. Website analytics may involve tools such as Google Analytics. The precise technologies, providers, purposes, retention settings and available choices must be reflected in the website’s live cookie information or settings when enabled. This Privacy Policy does not by itself replace any required cookie-consent mechanism.

 

14. Your privacy rights

 

14.1. Where the GDPR applies and subject to its conditions and exceptions, you may request access to your personal data, correction, erasure, restriction of processing and, where relevant, data portability. You may object to processing based on legitimate interests and withdraw consent at any time without affecting processing lawfully carried out before withdrawal.

14.2. You may request information about the purposes of processing, relevant recipients, storage criteria and safeguards for applicable international transfers.

14.3. To exercise your rights, contact office@noaimovement.com. We may need reasonable information to verify your identity and protect another person’s data before fulfilling a request. We will respond within the time limits required by applicable law.

14.4. You may lodge a complaint with a competent data protection authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), https://uodo.gov.pl. You may also have a right to complain to another competent authority under applicable law.

14.5. Where other applicable privacy laws provide additional mandatory rights, we will respect those rights as required. The availability and scope of a particular right may depend on where you are located and on the processing concerned.

 

15. Automated processing and decisions

 

15.1. Technical tools may assist with recordkeeping, website analytics, verification of identifiers and comparison of document hashes. A technical result that a document does or does not match a recorded hash is not, by itself, an assessment of the person who submitted it.

15.2. The established No AI Declaration™ and Membership processes include review and decisions by the Operator. We do not describe those decisions as solely automated. Any future automated decision-making that triggers additional legal information duties will be described before it is introduced.

 

16. Data protection and security

 

16.1. We use administrative and technical arrangements intended to limit access to personal data to what is needed for the relevant service and to reduce risks of unauthorised access, loss, misuse or alteration.

16.2. No internet service or electronic storage is completely risk-free. If we become aware of a personal-data incident, we will assess and address it and provide any notifications required by applicable law.

16.3. Please avoid sending unnecessary private information through open web forms or email, particularly information relating to third parties. If supporting evidence is needed for an audit, we will indicate the appropriate method for submitting it.

 

17. Providing information and other people's data

 

17.1. Providing information is normally voluntary, but some fields are required to answer an enquiry, identify an applicant, assess a declaration or certification, administer Membership or fulfil a legal requirement. Without necessary information, we may be unable to provide the requested service.

17.2. If you act for an organisation or submit personal data about another person, you must have an appropriate basis for doing so and provide that person with the relevant information when required. We may request redaction of unnecessary third-party data from evidence or attachments.

17.3. No AI Movement™ Membership is available to eligible individuals aged 18 or older and to organisations acting through a human representative. The general website is not intended to solicit personal data from children. If an issue involving a child’s personal data arises, contact us.

 

18. Changes and version history

 

18.1. This Privacy Policy uses the version format vMAJOR.MINOR. The first approved version will be v1.0 and will have a defined effective date. Later versions will show their own effective dates, and earlier approved versions will be archived rather than silently overwritten.

18.2. We may update this Privacy Policy to reflect changes in services, suppliers, processing practices or applicable law. Where a change requires additional information or a new legal basis or consent, we will take the required steps before applying it.

18.3. For Membership applications and records, the version of this Privacy Policy acknowledged and the date and time of acknowledgement are recorded separately from consent to public listing and from acceptance of the Membership Terms.

 

19. Contact

 

For questions about this Privacy Policy, use of your personal data, rights requests or withdrawal of optional publication consent, please contact:

VIENS Krzysztof Siporski / No AI Movement™

Goździówka 35A

05-304 Stanisławów

Poland

office@noaimovement.com

https://noaimovement.com

No AI Movement™ Privacy Notice / Privacy Policy

© 2026 No AI Movement™. All rights reserved.

No AI Declaration™ and No AI Certification™ are registered trademarks of the No AI Movement™, operated by VIENS Krzysztof Siporski.
This project, including its structure, content, certification concept, and unique graphic and communication elements, is an original work protected by law.
Any copying, imitation, or use without the explicit permission of the author is prohibited and will be treated as a violation of copyright.


Terms of Electronic Services


www.noaimovement.com
www.noaideclaration.com
www.noaicertification.com