Privacy Policy
The Chartered Institute of Lean Six Sigma LLC
https://www.cilsglobal.com
July 23, 2026
July 23, 2026
connect@cilsglobal.com
Plain-language summary
CILS collects the information needed to manage membership, professional profiles, assessments, credentials, events, payments, communications, and security. CILS does not sell personal data and does not use it for targeted advertising. This Policy explains what is collected, why it is used, who may receive it, how long it is kept, and how individuals can exercise privacy rights.
Who We Are and What This Policy Covers
The Chartered Institute of Lean Six Sigma LLC ("CILS," "we," "us," or "our") is a Delaware limited liability company and a global professional body serving Lean Six Sigma practitioners, learners, members, candidates, organizations, partners, assessors, mentors, speakers, and website visitors.
This Privacy Policy explains how CILS collects, uses, discloses, retains, and protects personal information through www.cilsglobal.com and any CILS page, portal, membership application, professional directory, credential-verification service, learning or assessment service, CPD feature, event, publication, communication, AI tool, or other service that links to this Policy (collectively, the "Services"). It covers relevant online and offline information practices.
This Policy does not govern an independent website, payment service, social-media platform, videoconferencing provider, learning platform, or other third-party service that displays its own privacy notice. When CILS processes personal information solely on behalf of an employer, training provider, educational institution, event organizer, or other customer, that organization may be responsible for the information and its own privacy notice may also apply.
Personal Information We Collect
"Personal information" or "personal data" means information linked or reasonably linkable to an identified or identifiable individual. It does not include information that has been lawfully made public or de-identified so that it cannot reasonably be linked to an individual. Depending on how a person uses the Services, CILS may collect the following categories:
| Category | Examples |
|---|---|
| Identifiers and contact details | Name, preferred name, signature, postal or billing address, country, email address, telephone number, date of birth or age confirmation, member/candidate/customer ID, and similar identifiers. |
| Account and authentication data | Username, encrypted or hashed password, account settings, access permissions, verification status, login history, and security or recovery information. |
| Professional, employment, and education data | Employer, job title, industry, professional biography, qualifications, education, experience, CV/résumé, references, skills, projects, profile photograph, and professional interests. |
| Membership and application data | Membership category, application answers, eligibility evidence, supporting documents, referee or sponsor details, review notes, status, renewal history, CPD records, benefits used, and member conduct or disciplinary records where relevant. |
| Assessment and credential data | Exam registrations, candidate records, responses, scores, attempts, assignment or project submissions, assessor feedback, integrity-check information, accommodation requests, certification decisions, digital badge or certificate details, issue and expiry dates, and verification history. |
| Commercial and payment data | Products or services requested, invoices, transaction date and amount, currency, payment status, discounts, refunds, tax information, and limited payment references. Full payment-card details are generally collected directly by the payment provider, not stored by CILS. |
| Communications and participation data | Inquiries, support requests, survey responses, complaints, appeals, correspondence, newsletter choices, event registrations, attendance, mentoring interactions, and audio/video or chat content from an event or meeting when recording is disclosed. |
| Public profile and verification data | Information selected for a member directory or needed to verify a membership or credential, such as name, designation, member or certificate number, category, status, award date, expiry date, and approved profile content. |
| Device and internet activity | IP address, browser and device type, operating system, device or cookie identifiers, referring page, pages viewed, clickstream, session dates and times, error logs, and security events. |
| Location information | Country, region, city, time zone, and approximate location inferred from an IP address. Precise geolocation is collected only when a specific feature requires it, the feature clearly explains it, and any legally required consent is obtained. |
| Sensitive or verification information | Government identification, a facial image or recording used for identity or exam integrity, accessibility or health information needed for an accommodation, and other sensitive data voluntarily provided or specifically required. A biometric template is processed only if a clearly disclosed verification service uses one and applicable consent requirements are met. |
| User content and confidential submissions | Files, written content, project evidence, organizational information, data sets, case studies, publications, comments, and other material submitted for review, assessment, mentoring, publication, support, or use of an interactive tool. |
| Inferences and review outcomes | Eligibility, risk, fraud, integrity, interest, and engagement indicators derived from the information above. Material membership, conduct, or certification outcomes are subject to appropriate human involvement. |
Information We Usually Do Not Request
Unless a particular Service clearly requires it, do not submit Social Security numbers, full payment-card numbers, bank login credentials, medical records, highly sensitive personal information, confidential client information, trade secrets, or personal data about another person. A person who submits information about another individual must have a lawful basis and authority to do so.
How We Collect Personal Information
CILS may collect personal information from the following sources:
- Directly from the individual, including through a form, account, membership or certification application, payment, examination, assignment, event, email, survey, complaint, or other interaction.
- From an organization or person acting with authority, such as an employer, sponsor, training provider, educational institution, referee, assessor, mentor, event organizer, authorized agent, or parent/guardian.
- Automatically through the Services, including cookies, server logs, security tools, analytics technologies, and similar mechanisms.
- From service providers and partners, such as payment processors, identity or exam-integrity providers, learning platforms, communications providers, or event systems.
- From public or professional sources, such as an employer website, professional profile, publication, conference biography, public registry, or information that an individual has intentionally made public.
Why We Use Personal Information
CILS uses personal information for the following business and operational purposes:
- Provide the Services. Create accounts; receive and review applications; deliver membership benefits, learning, examinations, assessments, mentoring, events, resources, and support.
- Administer membership and professional standing. Evaluate eligibility; manage categories, renewals, CPD, designations, directories, complaints, appeals, conduct, and disciplinary processes.
- Administer assessments and credentials. Register candidates; confirm identity; maintain assessment integrity; score or review work; make certification decisions; issue certificates or digital badges; and verify credentials.
- Process transactions. Calculate and collect fees, issue receipts and invoices, process refunds, maintain financial records, and prevent payment fraud.
- Communicate. Respond to inquiries, deliver account and service notices, provide event or program information, request feedback, and send marketing communications where permitted.
- Operate public registers and verification tools. Allow employers, clients, regulators, or members of the public to confirm the authenticity and current status of a membership or credential.
- Protect people, systems, and integrity. Authenticate users, secure accounts, detect malicious activity, investigate suspected fraud or misconduct, enforce rules, protect intellectual property, and preserve examination confidentiality.
- Improve quality and accessibility. Analyze service performance, troubleshoot errors, conduct audits, evaluate program effectiveness, develop resources, and improve user experience. CILS uses aggregated or de-identified information where reasonably possible.
- Meet legal and governance obligations. Comply with tax, accounting, corporate, consumer-protection, privacy, security, sanctions, law-enforcement, accreditation, dispute, and recordkeeping requirements.
- Support organizational changes. Evaluate or complete a merger, reorganization, financing, acquisition, transfer, insolvency, or sale of all or part of the organization, subject to appropriate protections.
Lawful Bases for International Users
Where a law requires CILS to identify a lawful basis, CILS relies as appropriate on: performance of a contract or steps requested before a contract; compliance with legal obligations; legitimate interests in operating a professional institute, maintaining credential integrity, preventing fraud, improving services, and communicating with members; consent; and, in limited cases, the establishment, exercise, or defense of legal claims. Consent may be withdrawn at any time, but withdrawal does not affect processing that was lawful before withdrawal.
When We Disclose Personal Information
CILS does not disclose personal information indiscriminately. It may disclose the minimum information reasonably necessary to the following categories of recipients:
- Technology and hosting providers. Website, application, database, cloud hosting, storage, cybersecurity, authentication, backup, analytics, and technical-support providers.
- Professional-service providers. Accountants, auditors, insurers, attorneys, consultants, accreditation or quality-assurance reviewers, and other advisers bound by appropriate duties.
- Payment and transaction providers. Payment processors, banks, invoicing providers, and fraud-prevention services needed to complete or protect a transaction.
- Assessment and credential providers. Authorized assessors, proctors, identity or integrity-check providers, digital-badge platforms, learning-management systems, certificate-production services, and verification systems.
- Program, event, and communications providers. Email and newsletter services, videoconferencing systems, event platforms, survey tools, mentors, speakers, and authorized program partners.
- Employers, sponsors, and institutional customers. An organization that purchased, sponsored, or legitimately administers an individual's membership, program, assessment, or event, subject to the organization's authority, the individual's expectations, and applicable law.
- The public. Limited data in a credential-verification tool or professional directory, as explained in Section 9. CILS does not publish supporting identity documents, exam responses, payment data, or private contact details.
- Authorities and protected parties. Courts, regulators, law-enforcement bodies, government agencies, or other persons when disclosure is required by law or reasonably necessary to protect rights, safety, systems, users, or the public.
- Transaction counterparties. Potential or actual parties and advisers involved in an organizational transaction, subject to confidentiality and lawful-use restrictions.
- Recipients chosen by the individual. Any person or organization the individual directs or authorizes CILS to contact or disclose information to.
No Sale or Targeted Advertising
As of the effective date of this Policy, CILS does not sell personal information for money or other valuable consideration and does not share personal information for cross-context behavioral advertising or process it for targeted advertising. CILS also does not use personal information to offer a financial incentive based on the value of that information. If these practices materially change, CILS will update this Policy and provide any legally required notice and opt-out mechanism before the new practice begins.
Cookies, Analytics, and Online Tracking
The Services may use cookies, local storage, pixels, software development kits, server logs, and similar technologies. These technologies may be set by CILS or by a service provider and may serve the following purposes:
- Strictly necessary. Enable core functions, maintain sessions, authenticate accounts, balance traffic, process requests, prevent fraud, and protect the Services.
- Preferences and functionality. Remember choices such as language, region, display, or consent preferences.
- Analytics and performance. Understand aggregated use, diagnose errors, measure content or campaign performance, and improve the Services.
- Embedded content and communications. Operate video, maps, forms, social-media content, chat, email, or event features requested by a user.
Do Not Track and Global Privacy Control
Some browsers offer a legacy "Do Not Track" (DNT) setting. Because there is no uniform industry standard for interpreting DNT, the Services do not currently respond to DNT signals. CILS will recognize a legally valid opt-out preference signal, such as Global Privacy Control, where applicable law requires it for a sale, sharing, or targeted-advertising activity. Because CILS does not currently engage in those activities, such a signal does not change CILS's present practices.
CILS does not itself track individuals across unaffiliated websites to build advertising profiles. A third-party analytics, embedded-content, or social-media provider may receive device and activity information when its feature is used and may process that information under its own privacy notice and settings.
AI Tools, Automated Processing, and Human Review
CILS AI Tool Library
The CILS AI Tool Library is designed so that text, files, and other content entered into a tool are processed only during the active session. To generate analysis or insights, inputs are transmitted to a third-party large language model (LLM) API provider for processing. CILS does not sell, store, reuse, or train on those inputs, and the content is automatically cleared when the tool is closed or the page is refreshed. The LLM provider processes inputs under its own enterprise data agreements, which ordinarily prohibit training on API-submitted content. Limited technical and security logs that do not contain the submitted content may be processed to operate and protect the tool.
AI outputs are probabilistic and may contain errors, omissions, bias, or invented information. Outputs must be independently reviewed by a competent person before use in professional, legal, financial, safety, assessment, or employment decisions. Users bear sole responsibility for any data they choose to input and must not enter personally identifiable information, confidential client data, trade secrets, regulated data, or other sensitive information unless they have authority and the specific tool expressly supports that use.
Other Automation
CILS may use automated tools to route applications, identify duplicate or suspicious activity, calculate scores under disclosed rules, support quality checks, or assist authorized reviewers. CILS does not ordinarily make a decision that produces legal or similarly significant effects solely through automated processing. If CILS introduces such processing, it will provide any notice, opt-out, explanation, appeal, or human-review right required by applicable law.
Data Retention
CILS retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including the integrity and verification of professional credentials, and as required by law. Retention may be extended for an active dispute, audit, legal hold, fraud investigation, safety matter, or other lawful need. When information is no longer needed, CILS deletes, anonymizes, or securely isolates it. The following are general periods and may be adjusted when the circumstances or law require:
| Record type | General retention approach |
|---|---|
| Account and membership records | While active, then generally up to 7 years after closure, expiry, or last activity. |
| Membership applications not approved | Generally up to 2 years after the final decision, unless needed for an appeal, fraud prevention, or legal claim. |
| Credential and public verification record | Core verification data may be retained for the life of the credential and indefinitely afterward where necessary to verify authenticity, status, revocation, or historical award. |
| Assessment and supporting evidence | Generally 7 years after the assessment or final activity; shorter for raw proctoring files or identity evidence where feasible. |
| Identity-verification documents | Deleted or de-identified as soon as reasonably practical after verification, generally within 90 days, unless law, an active investigation, dispute, or integrity requirement justifies longer retention. |
| Payment, invoice, and tax records | Generally 7 years after the transaction or longer if required by tax, accounting, sanctions, or legal obligations. |
| Complaints, appeals, and discipline | Generally 7 years after closure; a limited outcome may be retained longer when necessary to protect professional or credential integrity. |
| Support and ordinary correspondence | Generally 3 years after the matter closes, unless linked to a longer-lived membership, credential, contract, or dispute record. |
| Marketing records | Until consent is withdrawn or the person opts out; a minimal suppression record may be retained to honor the opt-out. |
| Website and security logs | Generally up to 12 months, unless a security incident, fraud matter, or legal obligation requires longer. |
| Cookie and analytics identifiers | For the period stated by the relevant tool or cookie setting, generally no more than 24 months unless a longer period is justified and disclosed. |
| AI Tool Library input content | Active session only; input is transmitted to a third-party LLM API provider for processing and is automatically cleared on tool closure or page refresh, as described in Section 7. CILSS does not store or retain the submitted content. |
Public Member Directories and Credential Verification
To protect the public, support professional recognition, and reduce credential fraud, CILS may maintain a public or request-based verification record. The record may show a person's name, approved designation, membership or credential number, category or level, current status, issue date, expiry date, and any minimum status information required for accurate verification.
A broader professional directory profile, biography, photograph, employer, location, or contact link is published only when the member elects or otherwise authorizes publication. A person may ask CILS to correct inaccurate public information or remove optional profile content. CILS may retain and continue to disclose the minimum verification record when reasonably necessary to confirm an authentic, expired, suspended, revoked, or historical credential and prevent misleading claims.
Security and Confidentiality
CILS uses reasonable administrative, technical, and physical safeguards appropriate to the nature and volume of the information processed. Measures may include access controls, role-based permissions, encryption in transit, secure hosting, authentication controls, logging, backups, vendor review, confidentiality obligations, staff awareness, incident response, and data minimization.
CILS limits access to examination materials, candidate records, personal information, project evidence, client information, and other confidential content to persons with a legitimate need. Where practicable, project and case-study data should be anonymized before being used for learning, quality review, or publication.
No method of transmission, storage, or security is completely reliable. CILS cannot guarantee absolute security. Users are responsible for keeping passwords confidential, using strong and unique credentials, signing out of shared devices, and promptly reporting suspected unauthorized access to connect@cilsglobal.com.
Privacy Rights and Choices
Depending on residence and applicable law, an individual may have some or all of the following rights:
- Confirm and access. Confirm whether CILS processes personal information and obtain access to it, subject to lawful exceptions.
- Know. Receive information about categories collected, purposes, sources, categories disclosed, and categories of third parties.
- Correct. Request correction of inaccurate personal information.
- Delete. Request deletion, subject to exceptions such as completing a transaction, maintaining credential integrity, security, legal obligations, and claims.
- Portability. Receive certain information in a portable and, where technically feasible, readily usable format.
- Third-party categories. Request a list of categories of third parties to which personal data has been disclosed, where applicable law provides that right.
- Opt out. Opt out of sale, targeted advertising, cross-context behavioral advertising, or qualifying profiling. CILS does not currently engage in these activities.
- Limit or withdraw consent. Limit certain uses of sensitive information or withdraw consent where processing is based on consent.
- Object or restrict. Object to or request restriction of certain processing where applicable outside the United States.
- Appeal. Appeal CILS's refusal to act on an eligible privacy request.
- Non-discrimination. Exercise privacy rights without unlawful denial of service, retaliation, or discriminatory price or quality.
- Complaint. Complain to an applicable privacy or consumer-protection authority.
How to Submit a Request
Email connect@cilsglobal.com with the subject line "Privacy Request" or use the contact form on www.cilsglobal.com. State the right being exercised, the jurisdiction of residence, the email address or account involved, and enough information to locate the relevant record. A person is not required to create a new account to submit a request.
CILS will use reasonable methods to verify identity and authority, proportionate to the sensitivity of the request. CILS may ask for information already associated with the account and should not be sent unnecessary identity documents. CILS will use verification information only for the request and security purposes.
Where applicable, CILS will respond without undue delay and generally within 45 days. If reasonably necessary, CILS may extend the response period by up to 45 additional days and will explain the extension. Requests are ordinarily free. CILS may decline or charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests where the law allows. CILS will explain a denial and any available appeal process.
Authorized Agents
An authorized agent may submit a request where applicable law permits. CILS may require proof that the individual authorized the agent and may ask the individual to confirm the request directly, unless a valid power of attorney or another legal exception applies. A parent, guardian, conservator, or other legally authorized representative may act for an individual as permitted by law.
Appeals
To appeal a decision, email connect@cilsglobal.com with the subject line "Privacy Appeal" within 60 days after receiving the decision and explain the reason for the appeal. CILS will review the appeal through a person not solely responsible for the original decision where practicable and will provide a written outcome generally within 60 days. If a Delaware appeal is denied, the response will explain how to contact the Delaware Department of Justice where that right applies.
Delaware Privacy Notice
CILS makes this Policy conspicuously available to describe its practices under the Delaware Online Privacy and Protection Act and, where its applicability thresholds are met, the Delaware Personal Data Privacy Act (DPDPA). Sections 2 through 6 identify the categories of personal data processed, purposes, categories disclosed, categories of recipients, review and correction process, change-notice process, effective date, online tracking disclosures, and contact mechanism.
A Delaware consumer may, where the DPDPA applies, confirm and access processing, correct inaccuracies, request deletion, obtain portable data, obtain categories of third parties, and opt out of targeted advertising, sale, or qualifying profiling. CILS obtains consent before processing sensitive data when required, allows consent to be revoked, and does not knowingly sell or use for targeted advertising the data of a person known to be between 13 and 17 years old without legally required consent.
The request, response, verification, authorized-agent, and appeal procedures are stated in Section 11. Delaware residents may also obtain information from the Delaware Department of Justice Personal Data Privacy Portal at attorneygeneral.delaware.gov/fraud/personal-data-privacy-portal/.
California and Other U.S. State Privacy Disclosures
Notice for California Residents
For purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), Sections 2 through 6 describe the categories of personal information collected during the preceding 12 months, categories of sources, business or commercial purposes, and categories of third parties. The categories may include identifiers; customer-record information; protected-classification information if voluntarily provided or needed for an accommodation; commercial information; internet or electronic-network activity; approximate geolocation; audio, electronic, visual, or similar information; professional, employment, and education information; sensitive personal information; and inferences.
During the preceding 12 months, CILS may have disclosed the categories above for the business purposes described in this Policy to the recipient categories in Section 5. CILS has not sold personal information or shared it for cross-context behavioral advertising during that period. CILS does not use or disclose sensitive personal information for the purpose of inferring characteristics beyond purposes permitted by applicable law. CILS does not knowingly sell or share the personal information of consumers under 16.
California residents may have rights to know, access, correct, delete, and obtain portable information; opt out of sale or sharing; limit certain uses of sensitive information; and receive equal service and price. Section 11 explains how to exercise those rights. CILS will honor a valid Global Privacy Control signal where required, although CILS does not currently sell or share personal information. CILS does not provide a financial incentive in exchange for personal information.
Residents of Other U.S. States
Residents of Colorado, Connecticut, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with applicable comprehensive privacy laws may have similar rights, subject to the scope, effective date, thresholds, and exceptions of each law. CILS will apply the procedures in Section 11 and honor rights required by the law applicable to the request. Nothing in this Policy limits a right that cannot lawfully be limited.
Direct Marketing Disclosure Requests
CILS does not disclose personal information to third parties for their own direct-marketing purposes without appropriate authorization. A California resident may send a request about such disclosures to connect@cilsglobal.com.
Children and Teenagers
The Services are intended primarily for adults and professionals and are not directed to children under 13. CILS does not knowingly collect personal information online from a child under 13 without verifiable parental consent as required by the Children's Online Privacy Protection Act (COPPA). If CILS learns that it collected such information without required consent, it will take reasonable steps to delete it.
A person under 18 may use a Service only when the relevant program permits and with the authorization of a parent or lawful guardian where required. Parents or guardians may contact connect@cilsglobal.com to ask about, review, correct, or request deletion of a child's information. CILS does not knowingly sell a minor's information or use it for targeted advertising.
Education Records and Institutional Programs
CILS is a professional institute and is not necessarily an educational agency or institution subject to the U.S. Family Educational Rights and Privacy Act (FERPA). When CILS receives FERPA-covered education records from a school or institution as an authorized service provider, CILS processes those records only as permitted by the applicable agreement and law, maintains appropriate controls, and does not use or redisclose them for an independent purpose unless authorized or legally permitted.
Marketing Communications
CILS may send news, event notices, professional resources, membership information, and service offers when permitted by law. A recipient may unsubscribe through the link in a marketing email or by contacting connect@cilsglobal.com. CILS will process the request promptly and maintain a minimal suppression record so the preference is respected. An opt-out from marketing does not stop transactional or service communications such as account, payment, membership, exam, certificate, security, or legal notices.
International Data Transfers
CILS operates from the United States and serves an international community. Personal information may be processed in the United States and in other countries where CILS, its authorized personnel, partners, or service providers operate. Privacy laws in those countries may differ from the law in the individual's country.
Where required, CILS uses an appropriate transfer mechanism or safeguard, such as contractual data-protection terms, recognized standard contractual clauses, adequacy decisions, consent, or another lawful basis. CILS also applies the purpose limitation, security, retention, and access controls described in this Policy to transferred information.
Data Incidents
CILS maintains processes to assess and respond to suspected unauthorized access, use, modification, disclosure, loss, or destruction of personal information. If an incident requires notice under applicable law, CILS will notify affected individuals and relevant authorities within the legally required period and provide information reasonably necessary to understand the incident and protective steps.
Third-Party Links and Services
The Services may link to or integrate independent websites and services. CILS does not control their privacy, security, availability, or content. Users should review the privacy notice and settings of each third party before providing information. A link or integration does not mean that CILS is responsible for the third party's practices.
Changes to This Policy
CILS may update this Policy to reflect changes in the Services, technology, law, or organizational practices. The revised Policy will be posted with a new "Last updated" date. For a material change, CILS will provide additional notice reasonably appropriate to the change, such as a prominent website notice, account notice, or email, before the change takes effect where required. Earlier versions may be requested through the contact details below.
Contact and Complaints
For privacy questions, requests, complaints, or security concerns, contact:
The Chartered Institute of Lean Six Sigma LLC
Privacy Office
Email: connect@cilsglobal.com
Website: https://www.cilsglobal.com
Jurisdiction of formation: Delaware, United States
CILS will make reasonable efforts to resolve a complaint. An individual may also contact the privacy, consumer-protection, or data-protection authority with jurisdiction over the matter. Delaware residents may contact the Delaware Department of Justice; California residents may contact the California Privacy Protection Agency or California Attorney General.