Privacy policy
How Oxford Global Education collects, uses, protects and shares personal information.
Last updated: 29 August 2026
Oxford Global Courses Ltd, trading as Oxford Global Education ("Oxford Global Education", "we", "us" or "our"), respects your privacy and is committed to handling personal information fairly, lawfully and securely.
This Privacy Policy explains how we collect and use personal information when you:
- visit
https://oxfordglobaleducation.comor use our online forms; - enquire about, apply for, enrol on or participate in one of our programmes;
- book a consultation, interview, tutorial, event or other appointment;
- pay us or receive a refund;
- communicate with us, our staff or our authorised representatives;
- work with us as a parent, guardian, school, agent, partner, tutor, speaker, contractor or supplier;
- attend an online, residential or in-person programme or event; or
- otherwise interact with Oxford Global Education.
It applies to our website, the Oxford Summer Academy, the 1-Year Masterclass, executive and global programmes, Delta-related assessments and reports, consultations, events, alumni activities and related educational services. A more specific privacy notice may also be provided where a particular activity requires additional information. If that notice conflicts with this one, the more specific notice will apply to that activity.
A short summary for students and families
We need some information about students and their families to consider applications, provide teaching, arrange accommodation and travel support, take payment, and keep students safe. This can include school records, contact details, health or dietary information, and emergency contacts.
We use only information we reasonably need. We do not sell personal information. We may give necessary information to people who help us run a programme, such as tutors, accommodation or transport providers, payment companies and welfare staff. We take extra care with information about children and with health, welfare and safeguarding information.
Students have privacy rights of their own. A parent or guardian can help a child exercise those rights, but a parent does not automatically have an unrestricted right to all information about a child. We consider the child's age, understanding, safety and best interests.
Questions, rights requests and privacy complaints can be sent to info@oxfordglobaleducation.com.
1. Who is responsible for your information
The controller responsible for the processing described in this policy is:
Oxford Global Courses Ltd, trading as Oxford Global Education
Company number: 16731259
Registered in England and Wales
Registered office: 127a Westbury Road, Westbury-on-Trym, Bristol, England, BS9 3AP
Website: https://oxfordglobaleducation.com
Email: info@oxfordglobaleducation.com
Telephone: +44 (0) 1865 679 010
WhatsApp: +44 (0) 7496 769116
"Controller" means that we decide why and how personal information is used. In some relationships, another organisation, such as a school, educational agent, accommodation provider, payment provider or programme partner, may be an independent controller for its own use of the information. Where we and another organisation jointly determine the purposes and means of processing, we will explain the arrangement where required.
We have not named a statutory data protection officer in this policy. Privacy enquiries should be directed to the email address above.
2. Personal information we collect
Depending on your relationship with us, we may collect the following categories.
Identity and contact information
- name, title, preferred name, signature and pronouns;
- date of birth, age, sex or gender where relevant to welfare or accommodation;
- home address, country of residence, nationality and languages;
- email address, telephone number, WhatsApp or other contact details;
- parent, guardian, payer and emergency-contact details; and
- passport, visa, immigration, travel or other official identification details where necessary.
Application, admissions and education information
- chosen programme, subjects, dates and accommodation requirements;
- school, university, year group, qualifications, grades, transcripts and school records;
- academic interests, goals, written answers, personal statements and samples of work;
- interview notes, recordings where notified, tutor observations and references;
- admissions-test information and other academic evidence;
- English-language ability and support needs;
- application decisions, offers, enrolment status and reasons recorded by our academic team; and
- assessments, scores, indicators, comparisons, inferences and reports created through our academic or Delta processes.
Programme and service records
- attendance, timetables, tutorial records, assignments, research papers, feedback and certificates;
- accommodation, rooming, meal, activity and transport arrangements;
- arrival and departure information, flight details and transfer requests;
- communications with students, families, schools, agents and programme staff;
- alumni and ambassador participation; and
- event, webinar, consultation and appointment details.
Welfare, health and safeguarding information
- allergies, medical conditions, medications and health-care instructions;
- dietary, religious, accessibility, disability, neurodiversity and learning-support needs;
- parental permissions and information about a student's independence or supervision needs;
- wellbeing, pastoral, behavioural, disciplinary and safeguarding records;
- incident, accident, first-aid, insurance and emergency records; and
- information about concerns, allegations or risks involving a student or another person.
Some of this is special category information and is given extra protection under data protection law. Safeguarding or vetting records may also include criminal-offence information.
Payment and commercial information
- payer name, billing address, invoices, receipts, fees, discounts and scholarships;
- payment status, transaction references, bank details used for transfers or refunds, and limited payment-card information supplied by a payment provider;
- contractual records, orders, cancellations, complaints, disputes and debt information; and
- records needed for accounting, tax, audit and fraud prevention.
We do not intend to store full payment-card numbers or card security codes on our own systems. Card details are handled by the relevant payment provider.
Communications, media and feedback
- emails, letters, messages, call notes and other correspondence;
- survey responses, reviews, testimonials and feedback;
- photographs, video, audio and programme recordings; and
- marketing choices, consent records, unsubscribe requests and suppression records.
Please do not send highly sensitive information through ordinary email or WhatsApp unless we ask you to and the method is appropriate. We may provide a more secure route where necessary.
Website, device and security information
- IP address, browser, operating system, device type and language;
- page paths, referral source, approximate location derived from an IP address, timestamps and interactions;
- performance information such as page-load and core web-vital measurements;
- cookie, local-storage and consent choices;
- form-submission metadata and anti-spam or bot-detection signals; and
- security logs, fraud indicators and records of attempts to access our systems.
Professional and partner information
If you work with us, we may collect your organisation, job title, professional biography, qualifications, experience, availability, payment details and communications. Separate workforce or contractor notices may apply to staff, tutors and applicants for roles.
3. How we obtain information
We collect information:
- directly from you, including through forms, applications, interviews, calls, messages, payments, programme activities and consent forms;
- from a parent, guardian or payer acting for or supporting a student;
- from schools, universities, agents, referees and educational partners involved in an enquiry, application or programme;
- from tutors, programme staff, accommodation providers, transport providers and welfare professionals involved in delivering or safeguarding a programme;
- from payment, booking, form, website, email, communications and other service providers;
- from publicly available sources, such as professional profiles, institutional websites or published academic information, where relevant and lawful; and
- through our own observations and analysis, including interview notes, academic assessments and website-security records.
If you give us information about another person, you should have authority to do so and, where appropriate, make this policy available to them. If we obtain personal information from someone other than the person concerned, we will provide privacy information within the period required by law unless an exception applies.
4. Why we use information and our lawful bases
UK data protection law requires us to identify a lawful basis for each use. The applicable basis depends on the context. "Legitimate interests" means a genuine and proportionate organisational or third-party interest that is not overridden by the person's rights and interests. We carry out and document balancing assessments where appropriate.
| Purpose | Typical information | UK GDPR lawful basis |
|---|---|---|
| Answer enquiries, provide prospectuses, arrange calls and discuss suitability | Identity, contact, communications and programme interests | Steps at your request before a contract; legitimate interests in responding and operating our organisation |
| Review applications, conduct interviews and decide whether to offer a place | Identity, education, application, interview and assessment information | Steps before a contract; legitimate interests in fair admissions, academic quality and programme planning |
| Enrol students and deliver teaching, mentoring, events, reports, accommodation and activities | Identity, contact, education, programme and logistics information | Contract; legitimate interests where the contract is with a parent, school or partner rather than the student |
| Personalise teaching and produce academic or Delta assessments and reports | Education records, work, observations, assessment outputs and inferred information | Contract; legitimate interests in providing evidence-led and tailored education |
| Arrange travel, accommodation, catering, accessibility and student support | Identity, programme, travel, welfare and support information | Contract; legitimate interests; legal obligation where applicable |
| Protect students and others, respond to emergencies and fulfil safeguarding duties | Welfare, health, location, attendance, emergency-contact, incident and safeguarding information | Legal obligation; vital interests; legitimate interests in safety and safeguarding; contract where appropriate |
| Process payments, refunds, scholarships and financial administration | Identity, payment, transaction and contractual information | Contract; legal obligations for tax and accounting; legitimate interests in fraud prevention and debt recovery |
| Operate, protect, troubleshoot and improve our website and systems | Device, usage, security, form and communications information | Legitimate interests in secure and effective services; legal obligation where applicable; consent where required for storage or access technologies |
| Run surveys, analyse outcomes and improve programmes | Feedback, programme and usage information | Legitimate interests in evaluation and improvement; consent where participation or publication is optional and consent is appropriate |
| Carry out research, statistics and model improvement | Academic, assessment, outcome and programme information, preferably anonymised or pseudonymised | Legitimate interests in research and service improvement; consent or another Article 9 condition if identifiable special category information is used |
| Create and use photographs, video, recordings and testimonials | Images, voice, opinions and programme information | Consent for promotional use, particularly involving children; legitimate interests for proportionate documentary, security or internal programme uses where appropriate |
| Send marketing about relevant programmes, events and opportunities | Contact details, relationship, interests and marketing choices | Consent where required; otherwise legitimate interests, subject in every case to the Privacy and Electronic Communications Regulations (PECR) and an easy opt-out |
| Maintain alumni, ambassador, school, agent and partner relationships | Contact, professional, programme and communications information | Consent where appropriate; legitimate interests in maintaining relevant relationships and networks |
| Manage complaints, legal claims, insurance, audits and regulatory requests | Relevant identity, communications, transaction, welfare and incident records | Legal obligation; legitimate interests in establishing, exercising or defending legal rights |
| Recruit staff, tutors, speakers and contractors | Identity, contact, professional, reference and vetting information | Steps before a contract; legal obligation; legitimate interests in recruitment and safeguarding |
| Manage organisational changes | Relevant business and relationship records | Legitimate interests in reorganisation, investment, merger or transfer, subject to appropriate confidentiality safeguards |
Where we rely on consent, giving consent is voluntary and you may withdraw it at any time. Withdrawal does not make earlier processing unlawful. Where processing is necessary for a contract or legal requirement, we may be unable to accept an application, enrol a student, provide a particular service or safely accommodate a need if the required information is not provided. We will explain this when it matters.
We do not change a purpose in a way that is incompatible with the original purpose without giving further information and, where necessary, identifying a new lawful basis.
5. Special category and criminal-offence information
Health, disability, religion, ethnicity and certain other sensitive information are "special category" data. We process these only when an Article 6 lawful basis above and a further condition under Article 9 UK GDPR both apply. Depending on the circumstances, that condition may be:
- explicit consent;
- protection of vital interests where a person cannot consent;
- establishment, exercise or defence of legal claims;
- provision or management of health or social care by, or under the responsibility of, an appropriate professional;
- reasons of substantial public interest under the Data Protection Act 2018, including safeguarding children or individuals at risk; or
- another condition expressly permitted by law.
We process criminal-offence information only where authorised by law and with an appropriate Data Protection Act 2018 condition, for example for safeguarding, prevention of unlawful acts, regulatory requirements or legal claims. Where the law requires an appropriate policy document, we maintain one.
We try to collect only the details needed to make a safe, reasonable adjustment or welfare plan. A dietary preference that reveals religion or health information will be treated according to its actual sensitivity.
6. Children and young people
Many of our services are intended for young people, including children aged 13 to 17. We therefore:
- put the child's best interests first when designing services and deciding how to use information;
- use age-appropriate, clear explanations and provide shorter notices at relevant points;
- avoid collecting more information than reasonably needed;
- use high-privacy defaults where appropriate;
- assess significant processing involving children, including profiling, new technologies and welfare information;
- take particular care before sharing or publishing a child's image, testimonial, location or contact details; and
- make it possible for a child, as well as a parent or guardian, to ask questions and exercise privacy rights.
For an online service offered directly to a child in the UK, a child aged 13 or over may generally consent to consent-based data processing for that service. Different ages may apply elsewhere. This does not mean that consent is always the correct basis, or that a student can enter a programme contract without any required parent or guardian involvement.
When a parent or guardian makes a request concerning a child, we may consider the child's age, maturity, wishes, safety and capacity, who provided the information, and any duties of confidentiality. We may ask for evidence of identity, parental responsibility or authority. We will not disclose information if doing so would be unlawful or contrary to the child's best interests.
Safeguarding can justify necessary and proportionate information sharing. Data protection law does not prevent us from sharing information required to protect a child or another person from harm.
7. Admissions analysis, profiling and automated decisions
We may organise, compare and evaluate academic information to understand a student's profile, tailor teaching, prioritise development and produce assessments or reports. This may amount to profiling. It can include the use of structured criteria, statistical methods or software-assisted analysis.
Admissions, safeguarding and other decisions with significant effects are reviewed by appropriately authorised people. We do not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects for a person. If that changes, we will provide specific information about the logic involved, the significance and likely consequences, and the applicable rights to human intervention and challenge before the processing begins.
Models, probability estimates and academic indicators are aids to judgement. They are not guarantees of admission to Oxford, Cambridge or any other institution.
8. Who we share information with
We share only what is reasonably necessary for the relevant purpose. Recipients may include:
- directors, employees, admissions staff, tutors, mentors, lecturers, speakers, residential deans, welfare staff and authorised contractors;
- parents, guardians, payers and emergency contacts where appropriate;
- schools, universities, educational agents, referral organisations and programme partners;
- Oxford colleges, accommodation providers, venues, caterers and facilities providers;
- travel, transport, visa-documentation, activity and event providers;
- medical, first-aid, insurance, welfare, safeguarding and emergency-service providers;
- banks, payment processors, accountants, auditors and financial advisers;
- website hosting, content-delivery, security, analytics, form, anti-spam, booking, email, cloud-storage, CRM, productivity, communications and IT-support providers;
- professional advisers, insurers, debt-recovery providers and dispute-resolution bodies;
- regulators, accreditation bodies, tax authorities, courts, law enforcement and public authorities where disclosure is required or lawful; and
- a prospective buyer, investor or successor in connection with a confidential reorganisation, merger, sale or transfer of all or part of our organisation.
Current website services include Cloudflare for website delivery, security and privacy-focused web analytics; Elfsight for website forms; Google reCAPTCHA Enterprise within Elfsight forms for spam and abuse prevention; Calendly for booking consultations; and Google Fonts for website typefaces. These providers may receive technical information when their resources or embedded services load. Elfsight also stores information submitted through its forms on our behalf. Calendly processes information entered when a booking is made.
Service providers acting as processors are required by contract to handle information only on documented instructions, keep it secure, assist us with legal obligations and delete or return it as agreed. Some recipients act as independent controllers and apply their own privacy notices.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. If our practices change, we will update this policy and provide any legally required choice before the change applies.
9. International transfers
We work internationally, and some students, families, schools, agents, staff, partners and suppliers are outside the United Kingdom. Some technology providers may also process information in the United States, European Economic Area or other countries.
When a transfer from the UK is restricted under UK GDPR, we use a lawful transfer mechanism. Depending on the destination and recipient, this may include:
- UK adequacy regulations, including an applicable UK-US Data Bridge certification;
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to the European Commission's Standard Contractual Clauses;
- another legally approved safeguard; or
- a limited legal exception where appropriate.
Where required, we carry out a transfer risk assessment and apply supplementary contractual, technical or organisational safeguards. For transfers governed by EU GDPR, we use an EU adequacy decision, EU Standard Contractual Clauses or another permitted mechanism, and conduct any required transfer assessment.
You may contact us for further information about the transfer mechanism relevant to your information and, subject to lawful redactions, a copy of the applicable safeguard.
10. Retention
We keep information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, safeguarding and reporting requirements. We consider the amount, nature and sensitivity of the information, the risk from unauthorised use, the purpose, whether that purpose can be achieved another way, and applicable limitation periods.
Our normal retention approach is:
| Record | Normal period or criterion |
|---|---|
| General enquiries and consultation records where no application follows | Up to 24 months after the last substantive contact, unless the record is needed for a complaint, safeguarding concern or legal claim |
| Unsuccessful or withdrawn applications | Normally up to 2 years after the relevant admissions cycle; longer only where justified, for example by a dispute, safeguarding issue or consent to remain in contact |
| Enrolment, contract, core programme and academic-delivery records | Normally 6 years after the end of the programme or relationship, with selected academic or certificate records kept longer where needed to verify an award or provide alumni services |
| Finance, invoice, payment and tax records | Normally 6 years after the end of the relevant financial year, or longer where tax or legal rules require |
| Routine travel, accommodation, dietary and health logistics | Deleted or minimised after the programme once no longer needed, normally within 12 months, unless connected with an incident, claim, ongoing support or legal requirement |
| Safeguarding, serious welfare, accident, disciplinary and insurance records | For the period set by our safeguarding and insurance retention schedule, taking account of the person's age, seriousness, statutory guidance and relevant legal limitation periods; these records may need to be kept substantially longer |
| Complaints, disputes and legal claims | Normally 6 years after closure, or for the applicable limitation period if longer, including extended periods that can apply to claims involving children |
| Marketing contact records | Until consent is withdrawn, an objection is made, or our review shows there is no longer a current relationship or reasonable interest; we periodically review inactive contacts |
| Marketing suppression records | A minimal record may be retained for as long as needed to ensure we respect the opt-out |
| Promotional photographs, recordings and testimonials | For the stated campaign, archive or consent period and subject to periodic review; removed from future use following valid withdrawal where consent is the basis, although prior lawful publication cannot always be recalled |
| Recruitment records for an unsuccessful candidate | Normally 6 to 12 months after the process, unless consent is given for a longer talent-pool period or a dispute requires retention |
| Website and security logs | According to short operational and security periods set by the relevant system; longer where needed to investigate an incident |
We may retain anonymised information indefinitely because it no longer identifies a person. We may preserve relevant records if litigation, an investigation, a safeguarding matter or a legal hold is anticipated or underway.
11. Marketing and service communications
We may send programme news, event invitations, prospectuses and similar communications where:
- you have given valid consent;
- the PECR "soft opt-in" applies because we obtained your details during a sale or genuine negotiation for our own similar services, offered a clear opt-out when collecting them, and offer an opt-out in every message; or
- the communication is to a corporate contact and is otherwise lawful, proportionate and relevant.
The rules for sole traders and some partnerships can differ from those for companies. We apply the rule appropriate to the recipient. We do not rely on a parent or agent's consent as consent by a child unless that is valid for the particular processing.
You can stop direct marketing at any time by using the unsubscribe link or emailing info@oxfordglobaleducation.com. The right to object to direct marketing is absolute. We may keep a minimal suppression record so that we do not contact you again by mistake.
Opting out of marketing does not stop essential communications about an application, booking, payment, programme, safety issue or existing service.
12. Cookies, embedded services and similar technologies
Cookies are small files stored on a device. Similar technologies include local storage, pixels, scripts, tags and other ways of storing or accessing information on a device.
We use or may use:
| Service or category | Purpose and information | Consent position |
|---|---|---|
| Strictly necessary website and security technologies, including Cloudflare security features | Deliver pages, balance traffic, detect bots, remember security challenges and protect the website. Depending on the security features triggered, Cloudflare cookies can include __cf_bm or cf_clearance. | Used where strictly necessary or another PECR exception applies; no optional advertising purpose |
| Cloudflare Web Analytics | Measures page views, referral paths, page performance and core web vitals. Cloudflare states that this service does not use cookies or local storage and does not fingerprint visitors for analytics. | We use it on the basis that it does not store or access analytics identifiers on the device; related personal-data processing, if any, is based on legitimate interests in website measurement |
| Elfsight Form Builder | Displays application and enquiry forms and handles submissions. Elfsight may use elfsight_viewed_recently; form widgets use Google reCAPTCHA Enterprise, which may set _GRECAPTCHA and process device, interaction and anti-abuse signals. | Form and anti-abuse functions may be necessary when you choose to use a form; any non-exempt storage or access technology must be withheld until valid consent is obtained |
| Calendly | Displays appointment availability, handles bookings and may use cookies or local storage for functionality, preferences, measurement and service security. | Non-essential Calendly technologies must be withheld until consent; a click-to-load approach may be used |
| Google Fonts | Downloads website typefaces from Google's servers, which exposes ordinary request data such as IP address and browser information to Google. | No cookie is required for the font request; personal-data processing is based on legitimate interests. We may instead host fonts locally to reduce third-party requests |
| Consent preferences | Remembers whether you accepted, rejected or configured optional technologies. | Exempt where strictly necessary to remember the privacy choice, provided required information and controls are supplied |
Where consent is required, optional technologies must not load before consent. Consent must be a clear affirmative choice, granular where appropriate, and as easy to withdraw as to give. You can change your choice through the Cookie settings control on the website. Browser settings can also block or delete cookies, but may not provide the same control and may affect functionality.
Some statistical and service-improvement technologies may qualify for an exception from consent under PECR as amended by the Data (Use and Access) Act 2025. We rely on an exception only where all legal conditions are satisfied, including transparency, appropriate safeguards and a simple means of objecting where required.
The exact names, providers, purposes and lifetimes of technologies in use should be shown in the website's cookie settings interface, which is the most current source because providers can change their technologies. This policy does not authorise a provider to use information for its own unrelated advertising.
13. Security and personal-data breaches
We use technical and organisational measures proportionate to the nature and risk of the information. Depending on the system, these include access controls, multi-factor authentication, encryption in transit, secure cloud services, backups, device and account security, staff confidentiality, role-based access, vendor review, safeguarding controls and incident-response procedures.
Access to sensitive welfare and safeguarding records is restricted to people with a legitimate need to know. We review access and delete or anonymise information when it is no longer required.
No internet or storage system is completely secure. If a personal-data breach occurs, we assess the risk, take containment and remedial action, document the incident, and notify the Information Commissioner's Office and affected people where the law requires. A notifiable UK breach is reported to the ICO without undue delay and, where feasible, within 72 hours after we become aware of it.
If you believe information has been sent to the wrong person, an account has been compromised or another privacy incident has occurred, contact info@oxfordglobaleducation.com promptly.
14. Your rights
Depending on the circumstances and applicable law, you may have the right to:
- be informed about how we use your information;
- obtain confirmation that we process your information and receive a copy;
- correct inaccurate information and complete incomplete information;
- have information erased in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive information you provided in a structured, commonly used and machine-readable format and transmit it to another controller where portability applies;
- withdraw consent at any time where consent is the basis;
- ask for human intervention and challenge certain solely automated decisions; and
- complain to us and to a data protection regulator.
These rights are not absolute. For example, we may retain information required by law, needed for safeguarding, or necessary for legal claims. The rights that apply can depend on our lawful basis and the type of information.
To exercise a right, email info@oxfordglobaleducation.com and describe your request. You do not normally have to pay. We may ask for proportionate information to verify identity or authority, especially where the request concerns a child or sensitive information. We normally respond within one month after receiving a valid request, subject to lawful extensions for complex or multiple requests. We will explain any extension or refusal and the right to complain.
15. Privacy complaints
Please send a privacy complaint to info@oxfordglobaleducation.com with enough information for us to understand the concern. We will:
- provide a clear way to complain;
- acknowledge a data protection complaint within 30 days;
- take appropriate steps to investigate without undue delay;
- keep you informed where appropriate; and
- explain the outcome without undue delay.
You may also complain to the UK Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
If EU GDPR applies, you may complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred. People elsewhere may contact their local privacy or data protection authority where applicable.
16. Information for people outside the United Kingdom
Our services are international. We apply the core protections in this policy regardless of location, while recognising that local law may create additional requirements.
European Economic Area and Switzerland
Where EU GDPR or Swiss data protection law applies, references in this policy to UK GDPR concepts should be read to include the equivalent local concept. EU GDPR rights include access, correction, erasure, restriction, objection, portability, consent withdrawal and protections concerning automated decisions. Our UK contact details above remain the first point of contact.
If Article 27 EU GDPR requires us to designate an EU representative, the representative's identity and contact details must be added to this section and made available to relevant individuals. This operational requirement must be confirmed before actively and repeatedly offering services to people in the EEA.
United States and other jurisdictions
Residents of certain US states and other countries may have additional rights, which can include rights to know or access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising or certain profiling, limit particular uses of sensitive information, and appeal a refusal. We honour these rights to the extent the relevant law applies to us and the processing.
As stated above, we do not sell personal information or share it for cross-context behavioural advertising. We do not discriminate unlawfully against a person for exercising a privacy right. An authorised agent may make a request where local law permits, subject to verification of the agent's authority and, where allowed, the person's identity.
Because privacy laws apply based on facts such as location, targeting, business size and processing volume, this general policy may be supplemented by a jurisdiction-specific notice when required.
17. Third-party websites and platforms
Our website may link to third-party websites, social networks, messaging services, payment pages or other platforms. Those organisations control their own services and may collect information under their own privacy notices. We are not responsible for their independent practices. Please review their notices before submitting information.
Using WhatsApp or another messaging platform also gives information to the platform provider under its own terms. Do not use social media or messaging for urgent safeguarding communications unless we have designated that channel for the purpose.
18. Changes to this policy
We review this policy regularly and update it when our services, providers or legal obligations change. The "Last updated" date shows when the published version was most recently revised. If a change materially affects how we use information, we will provide a more prominent notice or seek fresh consent where required.
Older versions may be requested by emailing us.
19. Contact us
For privacy questions, rights requests or complaints, contact:
Oxford Global Courses Ltd, trading as Oxford Global Education
Email: info@oxfordglobaleducation.com
Telephone: +44 (0) 1865 679 010
Registered office: 127a Westbury Road, Westbury-on-Trym, Bristol, England, BS9 3AP