Effective Date: [Month DD, YYYY]
1) Who We Are & Scope
[Company Legal Name] d/b/a [Company Name] (“we,” “us,” “our”) provides student consultancy services. This Privacy Policy covers personal data we collect via our website, portals, and services (the “Services”). We act as the data controller for individual clients; where we serve institutions, we may act as a processor on their instructions.
2) Data We Collect
- Contact: name, email, phone, address.
- Profile & Education: date of birth, nationality, academic history, test scores, CV/resume, goals, preferences.
- Engagement: bookings, session notes, documents you upload (e.g., drafts), communications, consent records; optional session recordings with consent.
- Payments: billing info and transaction details (we don’t store full card numbers; processed by third parties).
- Technical: device data, IP, browser, analytics, cookies, usage logs.
- From third parties: recommenders, referrers, payment processors, analytics tools, or publicly available sources.
- Sensitive data: we do not seek sensitive data (e.g., health, ethnicity, biometrics). If you choose to share it, we process it only with your consent or as permitted by law.
3) How We Use Your Data
- Provide and improve the Services, personalize guidance, and manage bookings.
- Communicate about sessions, updates, and support; send marketing with your consent or as permitted (you can opt out).
- Process payments and prevent fraud/security incidents.
- Comply with legal obligations and enforce our terms.
- With your direction, share materials with institutions or recommenders.
4) Legal Bases (EEA/UK where applicable)
- Contract: to deliver the Services you request.
- Consent: for certain marketing, cookies, or sensitive data.
- Legitimate interests: to operate, secure, and improve our Services (balanced against your rights).
- Legal obligations: accounting, compliance, and recordkeeping.
5) Sharing & Disclosure
- Vendors/Processors: hosting, payments, email/SMS, analytics, video tools—bound by contracts.
- Consultants/tutors under confidentiality as needed to deliver your engagement.
- Schools/universities only with your direction and consent.
- Legal/safety: to comply with law or protect rights and safety.
- Business transfers: in a merger, acquisition, or asset sale.
- Aggregated/de-identified data for statistics and service improvement.
6) International Transfers
Your data may be processed outside your country. Where required, we use lawful safeguards (e.g., Standard Contractual Clauses) and take appropriate measures to protect it.
7) Data Retention
We keep personal data only as long as necessary for the purposes above and to meet legal obligations. We then delete or anonymize it. You may request deletion subject to legal/contractual requirements.
8) Your Rights
- Access, correct, delete, or receive a copy (portability) of your data.
- Object to or restrict certain processing; withdraw consent at any time.
- Opt out of marketing communications via links in emails/SMS or by contacting us.
- EEA/UK: you can complain to your data protection authority.
- US (e.g., CA): you may have rights to know, correct, delete, and opt out of “sale”/“sharing” of personal information; we do not sell personal information in the conventional sense. If applicable, use: Do Not Sell or Share.
To exercise rights, contact us at [privacy@example.com]. We may need to verify your identity and, where allowed, may charge a reasonable fee for repetitive requests.
9) Security
We use reasonable administrative, technical, and physical safeguards to protect personal data. No method of transmission or storage is 100% secure.
10) Children
Our Services are intended for students and parents/guardians as applicable. We do not knowingly collect personal data from children under 13 (or relevant local age) without verifiable parental consent. If you believe a child provided data to us, contact us to request deletion.
11) Cookies & Tracking
We use cookies and similar technologies for functionality, analytics, and (where applicable) advertising. Manage preferences via your browser and our Cookie Preferences. See our Cookie Policy for details.
12) Changes to This Policy
We may update this Policy from time to time. Changes take effect upon posting unless otherwise noted. We will indicate the latest revision date and, if changes are material, provide additional notice.
13) Contact
[Company Legal Name] d/b/a [Company Name]
Address: [Street, City, State/Province, Postal Code, Country]
Email: [privacy@example.com] | Phone: [Phone Number] | Website: www.example.com
EEA/UK inquiries or DPO (if applicable): [DPO/Representative Name & Contact]