Privacy Policy

Privacy Policy

Effective date: July 11, 2026

At AGS, privacy isn't an afterthought — it's part of our profession. We publish documentation toolkits for standards like ISO/IEC 27001 and ISO/IEC 27701, so we hold ourselves to the same discipline we help our customers implement. This Privacy Policy explains, in plain language, what personal data we collect when you visit our store or purchase our products, why we collect it, how we protect it, and the rights you have over it.

This policy applies to our online store, our digital products, and all related communications. References to "AGS," "we," "our," or "us" mean the operator of this store. By using our website or purchasing our products, you agree to the practices described here.

1. Information We Collect

We collect only what we need to serve you — nothing more.

Information you provide directly

  • Identity and contact details — your name, organization name, email address, phone number, and billing address, provided when you place an order, create an account, or contact us.
  • Order information — the products you purchase, your order history, invoices, and download activity.
  • Communications — the content of emails, contact-form submissions, and support requests you send us, including any pre-sales questions about standards and certification.
  • Payment information — processed entirely by our PCI DSS–compliant payment providers. We never see, collect, or store your card numbers. We receive only confirmation that payment succeeded, along with the payment method type.

Information collected automatically

  • Technical data — IP address, browser type and version, device and operating system, time zone, and language settings.
  • Usage data — the pages you visit, products you view, referral source, and how you navigate our store.
  • Cookies and similar technologies — see Section 7 for details.

What we deliberately do not collect: we have no need for — and do not request — sensitive personal data such as government identifiers, health information, or financial account details beyond what payment processing requires.

2. How We Use Your Information

We use your personal data for the following purposes, each resting on a lawful basis:

  • To fulfill your orders — processing payment, delivering your download links, maintaining your account, and providing access to your purchased toolkits (performance of a contract);
  • To provide support — answering your questions about products, licensing, downloads, and how our toolkits map to standards (performance of a contract / legitimate interest);
  • To notify you of important product information — such as an updated toolkit edition when a standard is revised, or corrections to a product you own (legitimate interest);
  • To send marketing communications — news about new toolkits, standards updates, and offers, in accordance with Section 3 (consent / soft opt-in where permitted);
  • To improve our store and products — analyzing which products and pages are most useful, diagnosing technical issues, and understanding what our customers need next (legitimate interest);
  • To protect the business and comply with law — preventing fraud and abuse, enforcing our Terms of Service and license restrictions, maintaining accounting records, and meeting tax and legal obligations (legal obligation / legitimate interest).

We do not use your personal data for automated decision-making that produces legal effects, and we never sell your personal data to anyone.

3. Marketing Communications

  • If you make a purchase or inquiry, we may send you communications about similar AGS products and services — for example, letting an ISO 9001 customer know when our integrated IMS toolkits are updated — under the "soft opt-in" principle where applicable law permits.
  • Every marketing email contains an unsubscribe link. One click and you're out — no accounts to log into, no questions asked, and your transactional emails (order confirmations, download links, support replies) continue unaffected.
  • We will never share or sell your contact details to third parties for their marketing.
  • Where the law of your country requires opt-in consent before any marketing, we follow it.

4. How We Share Information

We share personal data only with the service providers who make our store work, and only to the extent necessary:

  • E-commerce platform and hosting providers — to operate the store and deliver your downloads;
  • Payment processors — to process transactions securely (they handle your card data under their own PCI DSS–certified environments);
  • Email service providers — to send order confirmations, download links, support replies, and (where permitted) marketing;
  • Analytics providers — to understand store performance in aggregate;
  • Professional advisers and authorities — accountants, lawyers, or public authorities where required for legal compliance, tax, fraud prevention, or the defense of legal claims;
  • Business transfers — if AGS undergoes a merger, acquisition, or sale of assets, customer data may transfer as part of that transaction, and this policy will continue to protect it.

Each provider is bound by contractual and legal obligations to process your data only on our instructions and to protect it appropriately.

5. International Transfers

We serve customers worldwide — from the Gulf to Europe, Asia, Africa, and the Americas — and our service providers may process data in countries other than your own. Where data is transferred internationally, we rely on appropriate safeguards such as the providers' recognized transfer mechanisms (for example, standard contractual clauses) and select providers with strong, independently audited security practices.

6. Data Security & Retention

  • All traffic between your browser and our store is encrypted using TLS.
  • Payment card data is handled exclusively by PCI DSS–compliant processors; it never touches our systems.
  • Access to customer data within AGS is limited to those who need it to serve you.
  • We retain personal data only as long as necessary for the purposes described above: order and invoice records are kept for the period required by tax and commercial law; account data is kept while your account remains active; marketing data is kept until you unsubscribe or we no longer have a lawful basis to use it. When data is no longer needed, we delete or anonymize it.

No system on earth is perfectly secure, but we apply the same risk-based security thinking to our own operations that our ISO/IEC 27001 toolkit teaches — because we'd be embarrassed not to.

7. Cookies

Our store uses cookies and similar technologies for three purposes:

  • Essential cookies — shopping cart, checkout, login, and security. The store cannot function without these.
  • Analytics cookies — aggregate, non-identifying insight into how the store is used, so we can improve it.
  • Marketing cookies — where applicable, to measure the effectiveness of our campaigns.

Where required by law, we ask for your consent to non-essential cookies via a banner when you first visit, and you can change your preferences at any time. You can also control or delete cookies through your browser settings; blocking essential cookies may prevent checkout from working.

8. Your Rights

Depending on your location, you have some or all of the following rights over your personal data, and we honor them for all our customers as a matter of good practice:

  • Access — request a copy of the personal data we hold about you;
  • Correction — ask us to fix inaccurate or incomplete data;
  • Deletion — ask us to erase your data, subject to records we must legally retain (such as tax invoices);
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict processing while a concern is resolved;
  • Portability — receive the data you provided to us in a structured, machine-readable format;
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing;
  • Complain — lodge a complaint with the data protection authority in your jurisdiction. We'd appreciate the chance to resolve your concern directly first — we take these matters seriously.

For customers in the EU/EEA and UK, these rights arise under the GDPR. For California residents, the CCPA/CPRA provides rights to know, delete, correct, and opt out of the sale or sharing of personal information — and since we do not sell or share personal information as defined by that law, no opt-out is needed. For customers in the Gulf region, we respect the applicable data protection frameworks, including the UAE Personal Data Protection Law and Saudi PDPL, where they apply.

To exercise any right, contact us using the details in Section 11. We will verify your identity and respond within the timeframe required by applicable law.

9. Children

Our store sells professional business documentation and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time as our services, providers, or legal obligations evolve. The current version, with its effective date, will always be published on this page, and material changes will be highlighted on the store or notified by email where appropriate. Your continued use of the store after an update constitutes acceptance of the revised policy.

11. Contact Us

For any privacy question, request, or concern — or simply to understand better how your data is handled — contact the AGS team by email or via the Contact Us page on our store. We treat privacy requests with the same care we put into our toolkits — thoroughly, promptly, and documented.

This Privacy Policy was last updated on July 11, 2026.