Legal

Privacy Policy

How AExA collects, uses, shares, stores, and protects personal information across the website, entrant and reviewer portals, submissions, payments, evaluation, and public winner records.

Privacy at a glance

Information handled with purpose, restraint, and accountability.

AExA uses personal information to operate secure accounts, administer entries and nominations, arrange independent review, process payments, provide support, protect programme integrity, and publish approved winner records. Submission evidence is not made public unless it is authorised for publication or included in an approved winner profile.

Your privacy matters to AExA. This policy explains what personal information we collect, why we use it, who may receive it, how long it may be retained, and the choices and rights available to you. Please do not upload confidential or sensitive information unless it is relevant, necessary, and lawfully authorised.

1. Overview and scope

This Privacy Policy applies to the AExA website, entrant portal, reviewer portal, award entries, nominations, evidence uploads, account verification, communications, payments, evaluation administration, public winner records, partner interactions, and related support services operated under the AExA — Arcturus Excellence Awards name.

“Personal information” and “personal data” mean information about an identified or reasonably identifiable individual. This policy does not apply to information that has been irreversibly anonymised or to independent third-party websites and services governed by their own privacy notices.

2. Who is responsible for your information

The AExA entity identified in the relevant quotation, invoice, order confirmation, authorised-partner arrangement, or direct engagement communication is normally responsible for the personal information processed for that engagement. Where no separate entity is identified, the operator of the AExA website is responsible for the processing described in this policy.

Authorised partners may process information on behalf of AExA or, in some circumstances, for their own independently determined purposes. Where a partner acts independently, its own privacy notice will also apply. Questions can be submitted through the official AExA Contact page using the privacy contact details displayed beside this policy.

3. Personal information we collect

Depending on how you interact with AExA, we may collect the following categories of information:

  • Identity and contact information: name, business email, telephone number, job title, organisation, country, and account display information.
  • Account and authentication information: username, encrypted password, email-verification status, one-time-code request records, login events, password-reset activity, account role, and security preferences.
  • Entry and nomination information: entry title, organisation or client details, selected category and award, written responses, public-profile text, declarations, named contacts, references, and nomination details.
  • Evidence and supporting material: documents, reports, datasets, images, links, testimonials, calculations, correspondence, and other files uploaded to support an entry.
  • Evaluation information: reviewer assignments, conflict declarations, scores, comments, moderation records, eligibility checks, status changes, decision records, and audit logs.
  • Winner and recognition information: client or organisation name, logo, short biography, award title, achievement level, citation, measurable outcomes, approved quotation, and publication preferences.
  • Partner and reviewer information: professional biography, expertise, organisation, profile image, sectors, regions, availability, account details, and administrative communications.
  • Payment and transaction information: billing contact details, invoice information, payment status, transaction references, order records, and authorised-partner payment information. Where an online payment provider is used, payment-card details are generally processed by that provider rather than stored in full by AExA.
  • Support and communications: enquiries, emails, notices, support requests, complaints, preferences, and records of operational communications.
  • Technical and usage information: IP address, browser and device type, operating system, timestamps, referring pages, session data, cookies, security logs, error information, and website or portal interactions.

4. Where information comes from

We collect information directly from you when you create an account, verify an email address, submit or nominate an entry, upload evidence, make or arrange a payment, contact support, act as a reviewer, publish a profile, or otherwise use the website and portals.

We may also receive information from your organisation, a nominator, an authorised partner, a payment or email provider, assigned reviewers, named referees, publicly available professional sources, or another person authorised to act for you. Anyone providing another person’s information must have a lawful basis and appropriate authority to do so and should direct that person to this policy where required.

5. How we use personal information

We use personal information where reasonably necessary to:

  • create, verify, administer, secure, and support entrant, reviewer, partner, and staff accounts;
  • save drafts, receive entries and nominations, protect evidence uploads, and maintain submission records;
  • check eligibility, allocate independent reviewers, manage conflicts, calculate scores, conduct moderation, verify claims, and issue decisions;
  • generate invoices, confirm or reconcile payments, maintain transaction records, and support payments made directly to AExA or through authorised partners;
  • communicate about accounts, submissions, evidence requests, payments, support, results, recognition, and security;
  • create and maintain approved public winner records, reviewer profiles, and partner profiles;
  • detect fraud, misuse, unauthorised access, manipulation, security incidents, and breaches of the Terms;
  • operate, troubleshoot, measure, improve, back up, and protect the website, portals, and related services;
  • maintain audit trails, defend legal claims, comply with lawful requests, and meet accounting, tax, regulatory, or other legal obligations;
  • produce aggregated or anonymised programme insights that do not identify individuals; and
  • send marketing or thought-leadership communications where permitted and in accordance with your choices.

7. Sensitive and third-party information

AExA does not generally require special-category or highly sensitive personal information. Do not include health information, identity documents, financial-account credentials, biometric data, children’s information, protected characteristics, confidential employment records, or similar material unless it is strictly necessary, specifically requested, and lawfully authorised.

Entrants should redact irrelevant personal information from evidence and use aggregated or anonymised data where possible. AExA may remove, restrict, quarantine, or request replacement of material that appears excessive, unsafe, unlawful, or unrelated to the evaluation.

8. Human-led evaluation and automated tools

AExA may use software to save data, calculate weighted totals, route applications, check completeness, support moderation, generate notifications, and identify unusual activity. Award outcomes are not intended to be made solely by automated decision-making. Eligible submissions are reviewed through human-led evaluation and governance processes.

9. Who may receive personal information

Access is limited according to role and need. We may share relevant information with:

  • AExA personnel and authorised administrators responsible for operations, support, finance, evaluation, governance, security, or communications;
  • independent reviewers and moderators assigned to assess eligible submissions, subject to confidentiality and conflict-of-interest controls;
  • authorised partners assisting with entrant support, local administration, invoicing, payment collection, or approved programme activity;
  • service providers supporting hosting, private file storage, email and OTP delivery, backups, security, analytics, customer support, document generation, payment processing, accounting, and website operation;
  • professional advisers, insurers, auditors, and consultants where reasonably necessary and subject to appropriate duties;
  • regulators, courts, law-enforcement bodies, payment providers, or other parties where disclosure is legally required or reasonably necessary to protect rights, safety, security, and programme integrity; and
  • a successor organisation in connection with a restructuring, merger, transfer, financing, or sale of relevant operations, subject to lawful safeguards.

AExA does not sell or rent personal information as a commercial data product.

10. Authorised partners and payment providers

Payments may be made directly to AExA or through an authorised AExA partner. The party receiving a payment may collect billing and transaction information needed to issue an invoice, confirm payment, satisfy legal obligations, and administer the related entry. Where a partner or payment provider determines its own processing purposes, its privacy notice will apply in addition to this policy.

AExA may receive payment status, transaction references, payer details, invoice details, and reconciliation information. Entrants should use only official payment instructions issued by AExA or a formally authorised partner.

11. Public reviewer, partner, and winner records

Published reviewer profiles may include a reviewer’s name, photograph, professional title, organisation, biography, expertise, sectors, and regions. Published partner profiles may include the partner’s name, logo, summary, category, website, and approved public details.

If recognition is awarded, a public winner record may include the client or organisation name, logo, short public profile supplied in the entrant portal, individual award, achievement level, citation, measurable outcomes, approved quotation, sector, region, and related recognition details. Entrants must ensure that this information is suitable for public use and that all necessary permissions have been obtained.

Submission evidence, confidential reviewer comments, internal scores, conflict declarations, and private contact details are not published merely because recognition is awarded. AExA may edit approved public material for grammar, length, consistency, clarity, and house style without materially changing its meaning.

12. International processing and transfers

AExA is an international awarding body and may use personnel, reviewers, authorised partners, infrastructure, and service providers in more than one country. Personal information may therefore be accessed, hosted, backed up, or otherwise processed outside the country where it was collected.

Where applicable law requires additional protection for an international transfer, AExA will use appropriate contractual, organisational, or technical safeguards and will remain accountable for information processed by service providers acting on its behalf.

13. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including account administration, evaluation, winner verification, audit, dispute resolution, security, backup, accounting, tax, regulatory, and legal requirements.

Retention periods vary according to record type and context. Draft and unsuccessful entry records may be retained for operational follow-up, audit, and dispute purposes before being deleted or anonymised. Financial and contractual records may be kept for statutory periods. Public winner records may be retained as part of AExA’s historical recognition archive unless correction, removal, or another lawful action is appropriate.

When information is no longer required, we take reasonable steps to delete, anonymise, or securely dispose of it, subject to backup cycles and lawful retention obligations.

14. Security and confidentiality

AExA uses administrative, technical, and organisational measures designed to protect personal information. Measures may include role-based access, secure authentication, email verification, encrypted transmission, protected upload storage, logging, monitoring, backups, staff and reviewer confidentiality controls, and supplier due diligence.

No internet service can guarantee absolute security. You are responsible for protecting your password, using a secure device, keeping account details current, and notifying AExA promptly if you suspect unauthorised access. Confidential evidence should be uploaded through the secure portal rather than sent through public social-media channels.

If a personal-data incident occurs, AExA will investigate, contain, document, and notify affected individuals or authorities where required by applicable law.

15. Cookies, logs, and analytics

The website and portals may use cookies and similar technologies that are necessary for login sessions, security, preferences, shopping or payment functions, form continuity, and site operation. Optional analytics or marketing technologies may also be used where enabled and legally permitted.

You can control many cookies through browser settings and, where provided, the site’s consent controls. Blocking essential cookies may prevent account login, saved applications, checkout, or other portal functions from working correctly. Third-party embedded content or services may set their own cookies under their own notices.

16. Service and marketing communications

We send service communications needed to verify accounts, administer entries and nominations, request evidence, arrange payments, provide support, assign reviews, notify results, protect security, and maintain recognition records. These communications are necessary while the relevant account, submission, review, or transaction is active.

Where permitted, AExA may also send newsletters, insights, category updates, or partnership communications. You can unsubscribe from marketing using the method provided in the message or by contacting AExA. Unsubscribing from marketing does not stop essential operational communications.

17. Your privacy rights and choices

Depending on where you are located and which law applies, you may have rights to:

  • know whether and how your personal information is processed;
  • request access to personal information held about you;
  • request correction of inaccurate or incomplete information;
  • request deletion or anonymisation where the information is no longer required or processing is unlawful;
  • request restriction of processing or object to particular uses, including direct marketing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • ask for information about international transfers and relevant safeguards; and
  • make a complaint to AExA or an applicable privacy or data-protection authority.

These rights may be subject to legal exceptions, identity verification, the rights of others, confidentiality, fraud prevention, legal claims, and lawful retention requirements. AExA will respond within the period required by applicable law and may ask for information reasonably needed to verify your identity and request.

18. Account controls and corrections

Registered users can update certain profile information and change their password through the Account & Security area of the relevant portal. Entrants should update application information before submission and contact AExA promptly if a submitted record, public winner profile, reviewer profile, or partner profile requires correction.

Changing an account email, removing a submitted entry, deleting evidence, or changing a published recognition record may require administrator assistance and may be limited where records must be retained for security, audit, payment, dispute, or legal purposes.

19. Children and minors

The entrant and reviewer portals are intended for adults acting in a professional or organisational capacity and are not directed to children under 18. Do not create an account for a child or submit a child’s personal information unless the information is genuinely necessary, lawful, appropriately authorised, and protected.

If you believe that a child’s information has been provided without appropriate authority, contact AExA so that the matter can be reviewed.

21. Changes to this Privacy Policy

AExA may update this policy to reflect changes in law, services, technology, security, partners, or information-handling practices. The revised policy will be published with an updated date. Material changes may also be communicated through the website, portal, or registered contact details where reasonably appropriate.

22. Privacy questions, requests, and complaints

Privacy questions, rights requests, or complaints should be submitted through the official AExA Contact page using the privacy contact details displayed beside this policy. Please describe the request clearly and identify the account, application, profile, transaction, or communication concerned.

AExA may need to verify your identity before releasing, changing, or deleting personal information. If you are not satisfied with the response, you may have the right to complain to the privacy or data-protection authority responsible for your jurisdiction.