Privacy notice
Last updated: 31 July 2026
Subject to our Terms and conditions, this notice explains how Studee collects, uses, stores, sources, retains, discloses and shares personal data, and the rights you have over that data. We've tried to write it in plain English. Where we use legal terms, it's because UK law requires them.
We process personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Use & Access Act 2025 and the Data Protection Act 2018.
Who we are
Studee Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 06842641, and we are registered with the Information Commissioner's Office under data-protection registration number Z2110366. For our registered office, VAT number, and other corporate details, see "Who we are" in our Terms and conditions.
Our Data Protection Officer (DPO) is responsible for overseeing how we handle personal data and how we respond to your requests under UK GDPR. That role is held by Ellie Robertson. You can contact the DPO at [email protected].
What this notice covers
This notice covers your use of the public studee.com website. Anyone can read this site without an account. Following changes we made in 2024, the site is anonymous content and search - there is no end-user sign-in or account on studee.com.
What personal data we collect
We collect a limited amount of information just by you using the site:
- Technical data: your IP address, browser type and version, device type, operating system, and the pages you view. We also record the date and time of your visits and the address you came from (the referring URL). We use this to keep the site running and to protect it from abuse.
- Site-function identifiers: short-lived identifiers such as
studee_browseridandstudee_sessionidthat help the site function across page loads. - Cookie-consent record: your choices in the cookie banner, stored in a first-party cookie called
studee_consent(see "Cookies and similar technologies" below). - Preferences data, where you've consented: small UI-state values we use to honour choices you have made on the site (for example, that you dismissed a promotional banner or modal).
- Analytics data, where you've consented: aggregated information about how visitors use the site so we can improve it.
- Marketing data, where you've consented: identifiers that help us measure marketing campaigns.
- Enquiry data, where you contact us: if you submit an enquiry form, we receive the information you choose to give us (for example, your name, email address, and the content of your message).
We do not knowingly collect more than we need. If you think we hold data we shouldn't, please contact the DPO.
Why we use your data and the lawful basis
UK GDPR Article 6 requires us to identify a lawful basis for each purpose. Our main bases are:
- Legitimate interests - for keeping the site secure, preventing fraud and abuse, and operating the public site as a research and discovery tool. We balance these interests against your rights and only rely on this basis where we can show our interest is not overridden by your interests or fundamental rights.
- Performance of a contract or pre-contractual steps - where you submit an enquiry form, we process the information you give us to respond to your enquiry and take any further steps you have asked for.
- Consent - for non-essential cookies (preferences, analytics, and marketing). You can withdraw consent at any time; see "Cookies and similar technologies" below.
- Legal obligation - where we have to keep records for tax, accounting, or other statutory purposes.
- Vital interests - where processing is necessary in order to protect the vital interests of an individual.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you, within the meaning of Article 22 of the UK GDPR.
Cookies and similar technologies
Cookie use on this site is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) and, where cookies involve personal data, by the UK GDPR, the Data Use & Access Act 2025 and the Data Protection Act 2018. We use cookies and similar technologies on the public site. When you first visit, you'll see a cookie banner with two equally prominent actions: Accept all and Manage preferences. No non-essential cookie loads before you make a choice.
To reject all non-essential cookies, click Manage preferences. The panel that opens has every non-essential category - preferences, analytics, and marketing - already turned off. Click Save preferences without turning any of them on, and we will load only the cookies that are strictly necessary for the site to work. Rejecting takes one extra click compared with accepting, and the panel never pre-selects categories on your behalf.
We organise cookies into four categories:
- Essential - always on; required for the site to function.
- Preferences - off until you consent.
- Analytics - off until you consent.
- Marketing - off until you consent.
Your choice is recorded in a first-party cookie called studee_consent, which is version-tracked and valid for 12 months before we ask you again. The cookie is set with path=/, SameSite=Lax, and (over HTTPS) the Secure flag.
If we materially change the consent policy - for example, by adding a new category or a new cookie - we bump the policy version. When your stored consent is for an older version, the banner reappears so you can make a fresh choice. We don't silently apply your previous choice to a new policy.
You can change your mind at any time using the Cookie preferences link in the site footer. When you revoke consent for a category we'd previously loaded, we delete that category's cookies from your browser and reload the page so the site re-renders without the revoked category's tag snippets.
For full detail of the categories, the specific cookies in each, and how to change your settings, see our Cookies notice. That page lists every first-party cookie Studee writes, organised by category. To change which categories are allowed, open Manage preferences from the cookie banner or from the Cookie preferences link in the site footer.
International transfers
We run our systems to make sure that your data is as safe as possible at all stages, both while it is processed and transferred, and when it is stored. We will not transfer your data to a territory that has not been assessed as providing adequate protection for people's rights and freedoms in respect of their personal data.
Most of our sub-processors operate outside the UK. Where personal data is transferred outside the UK, we currently rely on:
- the UK Extension to the EU-US Data Privacy Framework (commonly the "UK-US Data Bridge") for transfers to participating US-based sub-processors that have certified to it (currently Google, Meta, LinkedIn, Microsoft);
- the UK Addendum to the EU Standard Contractual Clauses for transfers to US-based sub-processors that have not certified to the Data Privacy Framework (currently Amazon Web Services, SendGrid, Slack, ClickUp, Zoom) and other non-UK sub-processors under contract via standard cloud terms; and
- UK adequacy decisions where the destination country is covered.
If you'd like a copy of the safeguard documents, contact the DPO.
How long we keep your data
We keep personal data only for as long as we need it for the purpose we collected it, taking into account the following:
- the purpose(s) and use of your information both now and in the future (such as whether it is necessary to continue to store that information in order to continue to perform our obligations under a contract with you, or to contact you in the future);
- whether we have any legal obligation to continue to process your information (such as any record-keeping obligations imposed by relevant law or regulation);
- whether we have any legal basis to continue to process your information (such as your consent);
- how valuable your information is (both now and in the future);
- any relevant agreed industry practices on how long information should be retained;
- the levels of risk, cost and liability involved with us continuing to hold your information;
- how hard it is to ensure that the information can be kept up to date and accurate; and
- any relevant surrounding circumstances (such as the nature and status of our relationship with you).
As a guide:
- Public-site server logs - up to 6 months from collection, used to keep the site running and to protect it from abuse.
- Public-site analytics and marketing data - retained for 14 months from collection (the Google Analytics 4 default user-data retention period that our configuration matches).
- Cookie-consent record (
studee_consent) - 12 months from your most recent choice, after which the banner reappears. - Enquiry-form correspondence - retained for 24 months from your last contact with us, so we can respond and follow up where needed.
- Records we are legally required to keep (for example, tax records) - retained for the period the relevant law requires.
When the retention period ends, we either delete the data or anonymise it so it can no longer identify you.
Children
The public studee.com site is general-audience research content and we do not target it at children. We have considered whether the site is an "information society service likely to be accessed by children" within the meaning of Article 8 of the UK GDPR, section 9 of the Data Protection Act 2018, and the Information Commissioner's Office Age Appropriate Design Code (the Children's Code).
Our current position is that the public studee.com site is general-audience information about international university study and is not designed to appeal specifically to children. We do not knowingly collect personal data from anyone under 13. The enquiry form is intended for prospective students of higher-education age (16+) and does not ask for age. If you believe a child under 13 has submitted personal data to us through the site, please contact our Data Protection Officer at [email protected], or contact us on +44 (0)20 7666 1222, and we will delete it. We keep this position under annual review.
Data subject rights
Where you submit a data subject rights request, we are required by law to use all reasonable measures to verify your identity before responding. These measures are designed to protect your information and to reduce the risk of identity fraud, identity theft, or general unauthorised access to or deletion of your information.
How we verify your identity
Where we possess appropriate information about you on file, we will attempt to verify your identity using that information.
If it is not possible to identify you from such information, or if we have insufficient information about you, we will require original or certified copies of certain documentation in order to verify your identity before we can respond to your request.
Your rights
Under the UK GDPR, the Data Protection Act 2018 and the Data Use & Access Act 2025, and subject to certain limitations, you have the following rights over your personal data:
- Right to transparency (Article 12) - to have information about our processing provided to you in writing or by other means.
- Right to be informed (Article 13) - where personal data is collected from you.
- Right to be informed (Article 14) - where personal data has not been collected from you.
- Right of access (Article 15) - to ask for a copy of the personal data we hold about you.
- Right to rectification (Article 16) - to ask us to correct data that is inaccurate or incomplete.
- Right to erasure (Article 17) - to ask us to delete your data, in certain circumstances.
- Right to restrict processing (Article 18) - to ask us to pause processing in certain circumstances.
- Right of notification (Article 19) - we will inform you of any rectification, erasure, or restriction of processing where you ask us to.
- Right to data portability (Article 20) - to receive your data in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and carried out by automated means.
- Right to object (Article 21) - to object to processing based on legitimate interests, including direct marketing.
- Rights related to automated decision-making and profiling (Article 22) - the right not to be subject to a decision based solely on automated processing, including profiling. We do not currently make decisions about you using solely automated means that produce legal or similarly significant effects on you.
- Right to complain (section 165 of the Data Protection Act 2018) - a right to complain about how we use your personal information.
To exercise any of these rights, contact the DPO at [email protected]. We'll respond within one calendar month. For complex or numerous requests we may extend that by a further two months, and we'll tell you within the first month if we need to.
There is no fee for most requests. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse to act on it; we'll explain why if so.
Right to complain to the ICO
If you are unhappy with the handling of your data subject rights request, you can request a review within 40 working days of receiving our initial response. If you wish to do this, you must do so in writing, identifying the decision you wish to be reviewed or the aspect of the handling you are unhappy with.
If you are still not happy with how we've handled your personal data, you have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
In accordance with Article 77 of the UK GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, place of work, or of an alleged infringement. However, we'd appreciate the chance to address your concern first, so please consider contacting our DPO before going to the ICO.
Security
We take appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, audit logging, and regular review of our processors. No system is perfectly secure, and we'll notify you and the ICO of any personal data breach where the law requires us to.
Changes to this notice
We review this notice at least once a year and update it when our practices change. Material changes will be communicated by an updated effective_date on this page. The current version of this notice is recorded as version in the page metadata, with the date it took effect as effective_date.
How to contact us
For privacy questions, requests under the rights listed above, or any concerns about how we handle your data, contact our Data Protection Officer at [email protected].
For corporate and contractual questions, including our company-disclosure information, see our Terms and conditions.