Privacy Policy

This Privacy Policy explains how Oxford Academy of English LTD (“we”, “us”, “our”) collects, uses, stores, and protects personal data.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

Oxford Academy of English LTD is the data controller for personal data collected through our websites and digital platform.

Contact: contacts@oaoe.co.uk

2. Personal Data We Collect

Identity data: name, email address, role, institution.

Technical data: IP address, device information, browser type, usage logs.

Platform activity data: AI interactions, writing submissions, assessments.

Account data: login information, user settings.

Payment data (B2C only): processed securely via third-party payment providers.

3. How We Use Personal Data

To provide access to our AI-assisted educational platform.

To deliver courses, training programmes, and institutional services.

To process payments, subscriptions, and account management.

To improve AI accuracy, platform performance, and user experience.

To ensure security, detect misuse, and prevent unlawful activity.

To communicate service updates and support messages.

4. Legal Basis for Processing

Contract: providing the services you have purchased or accessed.

Legitimate interests: improving system performance, safeguarding users, and analysing usage patterns.

Consent: for optional marketing communications and cookies where required.

Legal obligations: compliance with accounting, tax, and regulatory requirements.


5. Children’s and Student Data

We process student data under authorisation from educational institutions.

Institutional clients remain data controllers for student accounts they create.

Student data is processed solely for educational and safeguarding purposes.

6. Sharing of Personal Data

We do not sell personal data.

We may share data with trusted service providers such as hosting, analytics, and authentication providers.

 All third parties are bound by UK GDPR-compliant Data Processing Agreements

7. International Data Transfers

When data is transferred outside the UK, appropriate safeguards such as adequacy regulations or Standard Contractual Clauses (SCCs) are applied.

8.Data Retention

Personal data is retained only as long as necessary for the purposes collected.

B2C users: account data is deleted within 12 months of account closure.

Institutional users: retention is governed by agreements with the institution.

Some records may be retained longer where legally required.

9. Your Rights Under UK GDPR

Right to access your personal data.

Right to rectification of inaccurate or incomplete data.

Right to erasure (‘right to be forgotten’).

Right to restrict or object to processing.

Right to data portability.

Right to withdraw consent at any time.

Request these by contacting: contacts@oaoe.co.uk.

10. Data Security

We use encryption, access controls, monitoring, and secure hosting environments to protect data.

While we take appropriate measures, no system is completely secure.

11. Cookies and Tracking

Our websites and platform use cookies for authentication, analytics, and service optimisation.

Please review our separate Cookie Policy for more details.

12. Updates to This Policy

We may update this Privacy Policy occasionally.

Continued use of our services constitutes acceptance of any changes.

13. Contact Information

For privacy enquiries, contact: contacs@oaoe.co.uk.

Address: 1&3 Kings Meadow, Oxford, United Kingdom, OX2 0DP.