Privacy notice

Privacy notice

This notice explains how personal data is collected, used, stored, shared and deleted when you use anything Studee runs, and the rights you have over that data. It covers two things:

  • the public studee.com website: programme pages, search, guides, counsellor and university information, and our other research content, which anyone can read without an account; and
  • the University Application Workspace (the "Workspace"): our separate, signed-in service for students and staff at participating schools.

We have tried to write it in plain English. Where we use legal terms, it is because UK law requires them.

Our Terms and conditions cover your use of the website and the Workspace. This notice is not part of them, and there is nothing in it for you to accept. Accepting the terms is a separate act, and it is not consent to the processing described here.

We process personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025. Our use of cookies and similar technologies is also governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426) ("PECR"), read with Article 7 of the UK GDPR on consent.

Sections that name the website apply to the public site. Sections that name the Workspace apply to Workspace accounts and Workspace features, and they are the ones that govern if a general statement and a Workspace statement could both be read to apply.

Who we are

Studee Ltd operates studee.com and the Workspace. We are registered in England and Wales under company number 06842641, and we are registered with the Information Commissioner's Office under data-protection registration number Z2110366. For our registered office, VAT number, and other corporate details, see "Who we are" in our Terms and conditions.

Our Data Protection Officer (DPO) oversees how we handle personal data and how we respond to your requests under the UK GDPR. That role is held by Ellie Robertson.

Email [email protected] to contact our Data Protection Officer.

Which law applies

Studee Ltd is established in the United Kingdom, so the UK GDPR and the Data Protection Act 2018 apply to everything we do with personal data, wherever in the world you live and wherever your school is. Where the law of the country you are in also applies to a particular activity, we comply with that too, and nothing in this notice removes rights you have under the law that applies to you locally. Your school may also be subject to the data protection law of its own country; your school's privacy notice explains that.

Who is responsible for your data

On the public website, Studee is the data controller. We decide why and how the personal data described in the website sections of this notice is used.

In the Workspace, your school is the controller for the student, parent or guardian, and staff personal data that it and its users put in. That covers profiles, applications, tasks, documents, grades, and the parent or guardian email addresses it records. Your school decides why and how that data is used, who at the school can see it, and how long it is kept.

Studee acts as your school's processor for that data, under Article 28 of the UK GDPR and a written data processing agreement with the school. We process it on the school's documented instructions.

Studee is an independent controller for a smaller set of processing, where the school's agreement with us gives us our own purpose rather than instructing us:

  • keeping your account secure, verifying who you are at sign-in, and recording sign-ins;
  • sending you the service communications we decide to send for our own account-security and contract purposes, such as one-time sign-in codes; we also email each participating school's registered main contact when we publish a material change to the terms, which is a notice to the school rather than to you; invitations are sent on your school's instruction, and we send those as the school's processor;
  • handling the fact of a support request and how we resolve it; the school records quoted inside a support message stay your school's data, and we handle those as your school's processor;
  • keeping the record of your acceptance of the terms and of which version of this notice was shown to you when you accepted them;
  • developing and improving the AI models and AI-assisted features we use for the Workspace, which has its own section below; and
  • meeting our own legal obligations.

Where this notice says "we" or "us" about a purpose, the section makes clear which role we are acting in.

No statute requires you to provide Workspace data. Your school requires it so that it can give you a Workspace account, and we require it so that we can operate that account and hold evidence that you accepted the terms. If it is not provided, an account cannot be created or used. This paragraph is given under Article 13(2)(e) of the UK GDPR.

Where your data comes from

On the public website, almost everything comes from you: from your browser as you use the site, or from you emailing us. The one exception is a meeting booking. You enter your details on HubSpot's booking page, and HubSpot passes them to us.

In the Workspace, personal data reaches us in five ways. Four of them come from outside the Workspace:

  • From you. What you type into the Workspace, the files you upload, and what you send us when you ask for help.
  • From school staff. What counsellors, teachers and administrators record about you in the Workspace.
  • From your school's information system. Where your school has connected its management information system through Wonde, Wonde passes us roster data on the school's behalf and as the school's data source. Your school decides what is shared and can stop the connection.
  • From lists your school uploads. School staff can create accounts by uploading a spreadsheet of students; the rows of that upload are stored.

The fifth is the Workspace itself, which creates records as you use it: sign-in records, acceptance records and the audit trail described below.

We tell you where data came from because Article 14(2)(f) of the UK GDPR requires us to name the source of personal data we did not get from you directly.

What personal data we collect on the public website

Simply reading the site generates a limited amount of information about you. We also receive information if you choose to contact us or book a meeting. This is what we collect:

  • Technical data: your IP address, browser type and version, device type, operating system, and the pages you view. We also record the date and time of your visits and the address you came from (the referring URL). We use this to keep the site running and to protect it from abuse.
  • Error-monitoring and performance data: the page visited, error details, page-load timings, and technical details about your browser and device. We use Sentry to collect this information so that we can find faults and measure how quickly pages load. Sentry does not receive form contents or uploaded documents, and it does not store the user's IP address with the event. If you are signed in to the Workspace while using the site, the limited account context described under "Error monitoring and product feedback" below may also be included.
  • Site-function identifiers: studee_browserid, which lasts 12 months, and studee_sessionid, which lasts until you close your browser, let the site recognise the same browser across page loads. studee_session_resolution, which lasts until you close your browser, carries the session details our server worked out for your visit - your IP address, your browser's user-agent string and, where you arrived through one of our own referral links, the page you came from - to the app running in your browser. StudeeActivity, which lasts until you close your browser, holds the time you were last active.
  • Cookie-consent record: your choices in the cookie banner, stored in a first-party cookie called studee_consent for 12 months (see "Cookies and similar technologies" below).
  • Signed-in session data, if you have a Workspace account: if you are signed in to the Workspace and then read a public page, your browser stores a record of that session in local storage under the keys studee.website-auth.snapshot.v1, studee.website-auth.inactivity.v1 and workspace.auth.sessionLifecycleMode.v1, so that the site knows you are signed in and can sign you out after 60 minutes of inactivity. This storage is strictly necessary to provide the signed-in service you asked for, so regulation 6(4)(b) of PECR does not require us to ask for your consent for it. It is removed when you sign out. The Cookies notice describes what each key holds.
  • Preferences data, where you have consented: small interface choices you have made, such as dismissing a promotional panel, so that we do not show it to you again.
  • Analytics data, where you have consented: records of the pages you view and the actions you take on the site, linked to a pseudonymous identifier stored in the _ga cookies so that those records can be tied to the same browser. Google Analytics collects this for us and reports it to us in aggregate, so that we can improve the site. We do not use it to identify you by name.
  • Marketing data, where you have consented: identifiers that help us measure how our marketing campaigns perform.
  • Correspondence data: if you email one of our published addresses, we receive whatever you choose to tell us, for example your name, your email address and the content of your message. There is no enquiry form on the public site.
  • Meeting-booking data: some of our counsellor pages link out to a booking page at meetings.hubspot.com, which is operated by HubSpot. If you book a meeting there, HubSpot receives the details you enter and passes them to us so that we can hold the meeting. HubSpot's own privacy notice applies to that page as well as this one.

Every public page checks whether you are signed in to the Workspace, so that pages which offer to save a programme to your shortlist know whether you have an account. If you are signed in, your shortlist and everything else you do in the Workspace are covered by the Workspace sections of this notice.

We do not knowingly collect more than we need. Contact [email protected] if you think we hold data we should not.

What personal data is processed in the Workspace

Data your school controls

  • Account and profile data: name, preferred name, school email address, a separate email address for applications where one is recorded, mobile number, date of birth, gender, up to three countries of citizenship, school year, the student reference used by your school's own management information system, the reference of the system the record was imported from where it came from one, a flag showing whether the student is under 18, and the parent or guardian email address, with a flag showing whether the school communicates with them.
  • Study preferences: preferred countries, universities, subjects, qualification types and delivery methods, preferred currency, intakes, budget, course duration and expected fees.
  • The assigned counsellor for a student, and the student groups a student belongs to.
  • Aspirations, funding and grades: free text about the countries, universities and careers a student is aiming for and their plans after graduating, what funding they are looking for, the credits they hold, whether anyone outside the school is helping with their applications, and their expected grades.
  • Application data: the universities and programmes a student is applying to, intake and qualification details, status and history.
  • Tasks: task details, who they are assigned to, due dates and outcomes.
  • Saved programmes: the programmes a student has saved.
  • Documents: the files uploaded to the Workspace, their content, and the record we keep about each file (type, size, version, who uploaded it and when, status, and the result of the malware scan we run on it).
  • Upload and roster records: the rows of any student list a school uploads, and the roster data Wonde passes us for the school (name, email addresses, date of birth, gender, year group and the identifier used by the school's management information system).
  • School staff accounts: the name, work email address and role at the school of each counsellor, teacher, administrator or other staff member, whether the account is active or archived, and the record of when the school invited them and how many times.

The Workspace has no notes feature, no data export function and no facility for sending student data to a university. Documents are read by downloading them, and every download is checked against your permissions before the file is sent.

Special category data, as defined in Article 9 of the UK GDPR, is not collected as a structured field in the Workspace. It may still appear inside an uploaded document or in free text, where your school chooses to record it. Your school is the controller for that content and is responsible for having a lawful basis and an Article 9 condition before recording it. Tell your school before you upload health, religious or similar information about yourself.

Data Studee controls

  • Sign-in data: the email address on your account and the one-time codes we send to it. If you use Google sign-in, Google returns a signed identity token that confirms who you are. We check the token, then store the account identifier Google gives us on your Studee account so that we recognise you the next time you sign in with Google. We do not store the token itself.
  • Sign-in records: the date and time of each sign-in, the sign-in method, the account used and the IP address the request came from. These are written to our audit trail so that we can detect misuse and investigate security incidents. We also keep the date of your last sign-in, and the one before it, on your account record, so that you and your school can see when the account was last used.
  • Audit records of actions: the audit trail also records other significant actions in the Workspace, with the date and time, the account that acted, and the IP address the request came from.
  • Session data: the authentication cookie and the browser storage described in our Cookies notice, which keep you signed in and remember choices you make in the Workspace.
  • Acceptance records: which version of the terms you accepted, when you accepted it, the account and role you accepted with, your school where your account has one, and which version of this notice was shown to you at the time. The acceptance record itself holds no IP address. The audit event written at the same moment does record the IP address the acceptance came from, in the same way as every other audited action.
  • Support correspondence: what you or your school send us when you ask for help, and our replies. We are the controller for the fact of the request and how we handle it. Where a message contains records from your school's Workspace - a student profile, an application, a task or a document - that content stays your school's data and we handle it as your school's processor.
  • Error-monitoring, performance and feedback data: the page visited, error details, page-load timings and technical details about your browser and device, together with the limited account context described under "Error monitoring and product feedback" below. If you choose Give feedback, this also includes the message you type.

We do not use data from the Workspace for advertising or marketing.

Why we use your data and the lawful basis

Article 6 of the UK GDPR requires a lawful basis for each purpose.

On the public website

Each purpose below has one basis, which is the basis we rely on for it:

  • Keeping the site secure and preventing abuse - technical data and site-function identifiers - legitimate interests, Article 6(1)(f).
  • Operating the public site as a research and discovery tool - technical data and site-function identifiers - legitimate interests, Article 6(1)(f).
  • Finding errors, measuring page-load performance and improving the service - error-monitoring, performance and feedback data - legitimate interests, Article 6(1)(f).
  • Loading a video you came to watch on one of our pages - your IP address and browser information, sent to YouTube as the page loads - legitimate interests, Article 6(1)(f). See "Embedded video" below.
  • Replying to an email you send us - correspondence data - legitimate interests, Article 6(1)(f).
  • Arranging a meeting you book through one of our counsellor pages - meeting-booking data - steps taken at your request before entering into a contract, Article 6(1)(b).
  • Storing preferences, analytics and marketing cookies on your device, and reading them back - the storage itself - your consent, Article 6(1)(a), which is also what regulation 6 of PECR requires. Our tag container does not yet apply your choice tag by tag, so allowing analytics can still load a marketing tag, as we explain under "Cookies and similar technologies". That is a defect we are fixing. It is not a basis we rely on, and it does not make marketing storage lawful without your consent.
  • Remembering the interface choices you make on the site - preferences data - your consent, Article 6(1)(a).
  • Understanding how visitors use the site so that we can improve it - analytics data - your consent, Article 6(1)(a).
  • Measuring how our marketing campaigns perform - marketing data - your consent, Article 6(1)(a).
  • Keeping tax, accounting and other statutory records - whatever the relevant law requires us to keep - legal obligation, Article 6(1)(c).

You do not have to give us any personal data in order to read the public site.

Withdraw your cookie consent at any time from the Cookie preferences link in the footer. Article 7(3) of the UK GDPR gives you that right, and withdrawing your consent does not make anything we lawfully did with your data before you withdrew it unlawful.

In the Workspace, where your school is the controller

The school identifies the lawful basis for the processing it instructs us to carry out, and its own privacy notice explains that basis. We process that data on the school's instructions, as Article 28 requires. Ask your school which basis it relies on.

In the Workspace, where Studee is the controller

  • Performance of a contract (Article 6(1)(b)) - to provide the Workspace to you under our terms, including keeping you signed in and sending one-time codes. Where you are a school's registered main contact, it also covers the notice we send you when we publish a material change to the terms. We do not send that notice to every user.
  • Legitimate interests (Article 6(1)(f)). We rely on this basis for six things: keeping the Workspace and your account secure; preventing and investigating misuse; finding errors, measuring page-load performance and improving the service through feedback; providing support; holding evidence of which version of the terms you accepted and which version of this notice you were shown; and developing and improving the AI models and AI-assisted features we use for the Workspace. Our use of this basis requires a documented balancing test for each purpose that gives particular weight to children aged 13 to 17 and their differing ages and development needs.
  • Legal obligation (Article 6(1)(c)) - where we must keep records or respond to a lawful request.

Where we rely on legitimate interests, we weigh our interest against your interests, rights and freedoms, and we rely on that basis only where our interest is not overridden by them.

Automated decision-making

We do not make decisions about you using solely automated processing that produces legal effects or similarly significant effects on you, within the meaning of Article 22 of the UK GDPR. Automation in the Workspace is limited to making tasks visible on their start date and marking a task's reminder as due.

Error monitoring and product feedback

We use Sentry, provided by Functional Software, Inc., on the public website and in the Workspace to detect errors and measure page-load performance. For a signed-in Workspace user, the event context is limited to their role or persona, their school, the page visited and technical details about their browser. For a school user, it also includes their name and email address. For a student, it includes no name, email address or account identifier.

We do not send form contents or uploaded documents to Sentry, and Sentry does not store the user's IP address with an event. This monitoring is not used for marketing or automated decision-making.

If you choose Give feedback, Sentry receives the message you type and the same limited context. A school user can ask us to delete their feedback by emailing [email protected]. Student feedback is not linked to a name, email address or account identifier.

How we use Workspace data to develop our AI features

Studee is the independent controller for this processing. We train, fine-tune, test, evaluate, validate, secure and improve the AI models and AI-assisted features we use for the Workspace, for the Workspace generally and not only for your school's use of it. Your school's agreement with us permits this processing and records that Studee acts as an independent controller for it, rather than acting on the school's instructions.

Our lawful basis is legitimate interests under Article 6(1)(f): our interest in building features that help students find and apply to suitable courses, balanced against your interests, rights and freedoms. This basis requires a documented balancing test that gives extra weight to children aged 13 to 17 and their differing ages and development needs.

We use the minimum personal data reasonably needed for that purpose. The data we use is limited to structured Workspace records: profile and school-year data, study preferences, applications and programme records, tasks, expected grades, and saved programmes. We do not use the documents uploaded to the Workspace, and we do not use the free text you or your school write in the Workspace, to develop our AI features.

We keep uploaded documents and free text out of this data set on purpose. Your school decides what is recorded in them, so they can contain special category data as defined in Article 9 of the UK GDPR. Article 9 prohibits processing that data unless one of the conditions in Article 9(2) applies. Your school's agreement with us makes your school responsible for identifying an Article 9 condition for the data it records; it does not give Studee a condition for our own development purpose. Excluding documents and free text keeps this purpose inside the structured fields listed above, and the Workspace does not collect special category data into a structured field.

We apply these safeguards:

  • we use the minimum personal data reasonably needed for the purpose;
  • we pseudonymise or de-identify the data before use wherever that is reasonably practicable;
  • access is limited to authorised Studee engineering, security, service-quality and support staff, is granted for a defined development purpose, is limited to what that purpose needs, and is logged where practicable; no member of our staff has standing general access to identifiable school data;
  • we do not permit a third-party AI provider to train or improve its own models or services on this data; it may use the data only to provide its service to us;
  • outputs are never used to make decisions that have legal effects or similarly significant effects on you;
  • the data is never used for marketing;
  • we apply data minimisation and access controls to the data set throughout;
  • we keep the data for this purpose only as long as we need it for the documented purpose, and then delete or anonymise it; and
  • you can object by emailing [email protected], and we assess and act on that objection as explained below.

How to object. Email [email protected] and say that you object to AI development. Our Data Protection Officer records and assesses your objection. We stop processing your personal data for this purpose unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. Where the objection is upheld, we exclude your personal data from new data sets and take reasonable, technically feasible steps in relation to data sets already assembled. Information that has been irreversibly anonymised so that nobody can identify you is no longer personal data; pseudonymised data remains personal data. We will explain the outcome to you and tell you about your right to complain to the ICO.

Cookies and similar technologies

Cookie use is governed by regulation 6 of PECR and, where cookies involve personal data, by the UK GDPR (including the conditions for consent in Article 7), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

Your cookie choice is one choice for the whole of studee.com, including the Workspace. It is recorded in the first-party cookie studee_consent, which is version-tracked and lasts 12 months before we ask you again. It is set with path=/, SameSite=Lax and, over HTTPS, the Secure flag. If we materially change the consent policy, for example by adding a category or a new cookie, we raise the policy version; when your stored consent is for an older version, we ask you again rather than silently applying your previous choice to a new policy.

For every cookie we set, its purpose and how long it lasts, see our Cookies notice.

On the public website

When you first visit, you see a cookie banner with two equally prominent actions: Accept all and Manage preferences. No non-essential cookie set by Studee is placed on your device before you make a choice.

To reject all non-essential cookies:

  1. Click Manage preferences in the cookie banner.
  2. Leave every category switched off.
  3. Click Save preferences.

Rejecting takes one extra click compared with accepting, and the panel never pre-selects a category on your behalf.

We organise cookies into four categories:

  • Essential - always on. They are strictly necessary to provide the site you asked for, so regulation 6(4)(b) of PECR does not require your consent for them. Their purposes and lifetimes differ, and the Cookies notice lists each one with its own lifetime.
  • Preferences - off until you consent.
  • Analytics - off until you consent.
  • Marketing - off until you consent, subject to the note on tag delivery below.

Marketing can only be turned on together with analytics. If you turn analytics off, marketing is turned off with it.

studee_browserid lasts 12 months, which is longer than a browsing session. It is issued by our API and links the requests your browser makes, so that the site keeps your context between visits. We treat it as strictly necessary for the service you have asked for, so we do not ask for your consent for it under regulation 6(4)(b) of PECR, and we keep that classification under review.

Our analytics and marketing tags are delivered through a single Google tag container. The container loads once you allow analytics. Google's own tags are then told, category by category, what you allowed, and they follow that signal. We are completing the work that applies the same per-tag control to every other tag in the container. Until that work is finished, allowing analytics may load a marketing tag from one of the advertising partners named below, even if you have not allowed marketing.

Click Cookie preferences in the site footer to change your choice at any time. When you withdraw consent for a category we had loaded, we delete the cookies for that category that were set on studee.com and reload the page, so that the site re-renders without that category's tags. Cookies that an advertising company set on its own web address are outside our control; use your browser's settings or that company's privacy notice to remove those.

Embedded video

Some of our pages include video hosted by YouTube. The player loads from YouTube's privacy-enhanced domain, youtube-nocookie.com, as the page opens. That happens before you make a cookie choice, and the cookie banner does not prevent it. YouTube therefore receives your IP address, the address of the page you are viewing and basic information about your browser, even if you never press play. We rely on our legitimate interest in showing you the video you came to watch, under Article 6(1)(f) of the UK GDPR. Google acts as its own controller for what it receives, under Google's privacy policy, and the transfer is covered by the UK Extension to the EU-US Data Privacy Framework. Privacy-enhanced mode means YouTube does not set advertising cookies unless you play the video. The player can still write technical entries to your browser's storage when it loads, and regulation 6 of PECR covers that storage as well as cookies.

Block third-party content from youtube-nocookie.com to stop your browser contacting YouTube.

In the Workspace

The Workspace loads no product-analytics or marketing tags. It uses one authentication cookie and a small number of cookies and browser storage keys that hold interface choices you made yourself. It also uses the diagnostic Sentry error monitoring and page-load performance measurement described above; Sentry does not use cookies or browser storage for that monitoring. Storage that is strictly necessary to provide the service you asked for is exempt from the consent requirement under regulation 6(4)(b) of PECR.

You are still offered the studee.com cookie choice inside the Workspace, in two places: on the review screen you see when you are asked to accept the terms, where it is an optional and separate choice that never blocks acceptance; and from the Cookie preferences link in the Workspace footer. Both write the same studee_consent cookie, so a choice you make in either place applies on the public site too, and a choice you made on the public site is shown to you in the Workspace. Allowing analytics or marketing changes nothing inside the Workspace itself, because the Workspace loads no tags in either category.

Google sign-in. If you choose Continue with Google, Google receives the technical and account information needed to provide its sign-in service and may use cookies or similar storage under its own terms and privacy information. Google returns a signed identity token to us so that we can authenticate you. The available sign-in methods and implementation may change; this notice describes the personal data Studee receives and uses rather than promising a particular script-loading sequence.

Every cookie and storage key the Workspace uses, with its purpose and lifetime, is listed in the Cookies notice.

Who we share your data with

We share personal data only where we need to. We do not sell it.

On the public website

  • Our service providers. Each acts as our processor under a written data processing agreement and may only act on our instructions:
    • Amazon Web Services (AWS) - cloud hosting and infrastructure. The studee.com systems run in AWS's London region; AWS is a US company.
    • Cloudflare, Inc. - authoritative DNS for studee.com. Cloudflare answers the domain-name lookups your browser's resolver makes for our web address; it does not sit in front of our site as a proxy, and the pages you request do not pass through it (US).
    • Twilio SendGrid - transactional email delivery (US).
    • Google LLC - Google Tag Manager and Google Analytics (US).
    • Google Workspace - inbound email to our @studee.com addresses, and document hosting (US).
    • HubSpot, Inc. - the meeting-booking pages linked from our counsellor pages, and the record of a meeting you book (US).
    • Microsoft Corporation - Outlook and Teams email and conferencing (US).
    • Slack Technologies / Salesforce - internal collaboration, which may include the content of emails (US).
    • ClickUp - internal task management (US).
    • Zoom Video Communications - video conferencing (US).
    • Sentry (Functional Software, Inc.) - error monitoring, page-load performance measurement and product feedback. Sentry stores this data in Frankfurt, Germany.
  • Advertising partners. Where you have allowed marketing cookies, our advertising tags share identifiers with Google LLC (Google Ads), Meta Platforms, LinkedIn Corporation and Microsoft Corporation (the Bing tag), all in the US. These companies decide their own purposes for the data they receive as well as ours, so they are independent or joint controllers for it, not our processors, and their own privacy notices apply alongside this one. Where we and an advertising partner decide together how your data is used, we are joint controllers: you may exercise your rights against either of us, and you can email [email protected] for the essence of that arrangement, as Article 26 of the UK GDPR requires.
  • Embedded video. Google LLC receives your IP address, the page address and basic browser information when a page containing a YouTube video loads, as its own controller. See "Embedded video" above.

Withdraw marketing consent from the Cookie preferences link in the footer to stop the advertising sharing. Because our tag container does not yet apply your choice tag by tag, turning analytics off as well is what reliably stops any marketing tag the container has loaded.

Where you allow marketing cookies, the advertising partners named above receive identifiers that they also use for their own advertising purposes, as described above.

In the Workspace

  • Your school. School users see student data in line with the roles and permissions the school has set. Students see only their own records.
  • Sub-processors. Each is bound by a written data processing agreement and may act only on our instructions. Our current sub-processors for the Workspace are:
    • Amazon Web Services (AWS) - hosting, database, document storage and logs. Workspace data at rest is held in the AWS London region (eu-west-2).
    • Twilio SendGrid - transactional email: invitations, one-time sign-in codes and notices about changes to the terms (US).
    • Front - the support tool we use to handle messages you or your school send us (US).
    • Cloudflare, Inc. - authoritative DNS for studee.com. Cloudflare answers the domain-name lookups your browser's resolver makes for our web address; it does not sit in front of the Workspace as a proxy, and the pages and files you request do not pass through it (US).
    • Google Workspace - the email service that carries messages you send to our addresses.
    • Sentry (Functional Software, Inc.) - error monitoring, page-load performance measurement and product feedback. Sentry stores this data in Frankfurt, Germany.
  • Google LLC (Google sign-in). If you choose Google sign-in, Google acts as a separate data controller for the information it collects to provide that service, under its own privacy policy. Google returns a signed identity token to us; from that point we are the controller for what we do with it (US).

Advertising partners receive no Workspace data. The Workspace loads no advertising or product-analytics technology. Its diagnostic Sentry monitoring is used only to find errors, measure page-load performance and handle feedback as described above.

In both

  • Professional advisers and authorities. We may share data with our auditors, our legal advisers, or law-enforcement bodies where we are legally required to, or where we have a clear lawful basis.

Who at Studee can see your data

Inside Studee, access to personal data is limited to the staff who need it for their role. Authorised staff can see Workspace data where they need it to run the service, to support your school, to investigate a security or safety issue, or to carry out the school's instructions. Access is controlled by role, and significant actions are recorded in the audit trail.

International transfers

Workspace data is stored in the United Kingdom. Several of our suppliers are outside the United Kingdom, mainly in the United States, and personal data reaches them when they perform their service. We do not transfer personal data outside the UK without a lawful transfer mechanism in place. The mechanisms we currently rely on are:

  • a UK adequacy decision, where one covers the destination country;
  • the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge"), which takes effect through the Data Protection (Adequacy) (United States of America) Regulations 2023 (SI 2023/1028), made under section 17A of the Data Protection Act 2018, for US suppliers certified to it, currently Google, Meta, LinkedIn, Microsoft and Sentry. We rely on this for Google sign-in, Google Workspace email, Google Tag Manager and Google Analytics, the advertising partners named above, and any transfer to Sentry in the United States; and
  • the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018 and relied on as an appropriate safeguard under Article 46(2) of the UK GDPR, or the Information Commissioner's International Data Transfer Agreement, for our remaining non-UK suppliers, currently Amazon Web Services, Twilio SendGrid, Front, Cloudflare, HubSpot, Slack, ClickUp and Zoom. The UK Addendum to the Standard Contractual Clauses is also our fallback safeguard for Sentry.

Amazon Web Services stores Workspace data at rest in the London region, so that data is not transferred out of the UK for storage. Where support or operational work outside the United Kingdom involves that data, we rely on the International Data Transfer Addendum or the International Data Transfer Agreement.

We check which mechanism applies when we take on a supplier and when our contract with them changes.

Email [email protected] to ask which mechanism applies to a supplier, or for a copy of the safeguards we rely on.

How long we keep your data

We keep personal data only for as long as we need it for the purpose we collected it for, taking into account:

  • the purposes and use of your information, now and in the future;
  • whether we have a legal obligation to keep it, such as a record-keeping rule;
  • whether we still have a lawful basis to keep it, such as your consent;
  • how valuable the information is, now and in the future;
  • any relevant agreed industry practice on retention periods;
  • the risk, cost and liability of continuing to hold it;
  • how hard it is to keep it accurate and up to date; and
  • the nature and status of our relationship with you.

Public website data

  • Analytics and marketing data - 14 months from collection, which is the retention period set on our Google Analytics property.
  • Cookie-consent record (studee_consent) - 12 months from your most recent choice, after which we ask you again.
  • Meeting-booking records - 24 months from the meeting, unless you go on to become a customer, in which case our record of our dealings with you applies.
  • Error events and feedback sent through Sentry - up to 90 days.
  • Page-load performance spans sent through Sentry - up to 30 days.
  • Correspondence - we keep emails for as long as we need them to deal with what you contacted us about and any follow-up, and we delete them when that is no longer the case. We aim to hold them for no more than 24 months from your last contact.
  • Records we are legally required to keep, such as tax records - for the period the relevant law requires.

Workspace data your school controls

Your school decides how long its Workspace data is kept, and the Workspace does not delete it automatically. In particular, nothing is deleted simply because a student leaves the school, and there is no automatic anonymisation and no automatic account closure. Nothing in the Workspace decides on its own that an account has ended.

  • Deletion on the school's instruction. When your school asks us to delete a student's data, Studee staff carry out the deletion through our support procedure. Ask your school to contact us if you want your data deleted.
  • End of service. When a school's agreement with us ends, the school chooses within 90 days whether we return its Workspace personal data or delete it. We delete or anonymise the school's data in our live systems within 90 days of the service ending. Backups are overwritten on our ordinary backup cycle, and we keep the records the law requires us to keep.
  • Document files. When a document, a document record or a student is deleted, the files concerned are deleted from our document store. We do not keep earlier versions of uploaded files.

Workspace data Studee controls

  • Acceptance records, and the audit entries about accepting the terms - kept for as long as your account exists and normally for six years after it is closed. We retain this evidence to establish, exercise or defend legal claims. The time limit for a particular claim depends on the claim and when the relevant cause of action arose; account closure does not determine that date in every case. We review and delete the evidence when it is no longer reasonably needed, subject to any legal hold or longer period required by law.
  • The audit trail, including sign-in records - every other audit record stays in the live system for 90 days, is then moved to an archive, and is deleted once the record is 24 months old. The 24 months are counted from the moment the recorded action happened, not from the moment the record was archived.
  • The date of your last sign-in and the one before it - held on your account record for as long as the account exists, so that you and your school can see when it was last used.
  • The Google account identifier, where you use Google sign-in - held on your account record for as long as the account exists, so that we recognise you at each Google sign-in.
  • Data used to develop our AI features - kept only for as long as we need it for the documented purpose, and then deleted or anonymised. An objection is assessed and acted on as described under "How to object" above.
  • Support correspondence - kept for as long as we need it to answer you and deal with any follow-up, and reviewed regularly so that it is not kept longer than that.
  • Error events and feedback sent through Sentry - up to 90 days. A school user can ask us to delete their feedback by emailing [email protected]. Student feedback is not linked to a person.
  • Page-load performance spans sent through Sentry - up to 30 days.
  • Records we are legally required to keep - kept for the period the relevant law requires.

Technical copies

Deleted data can survive in these copies after it has gone from the live systems. Each copy has its own retention:

  • database backups - 35 days;
  • deleted document files - up to 2 days, while our storage provider completes the deletion;
  • application logs - 90 days, with copies that are no longer current kept for up to a further 30 days;
  • database audit and error logs - 30 days;
  • malware-scanning queues - 14 days; and
  • hosting access logs - kept for as long as we need them to investigate security problems. We have not yet set an automatic deletion period for these logs.

When a retention period ends, we delete the data.

Children

Workspace accounts

Student accounts in the Workspace are for people aged 13 or over. Users aged 13 to 17 are children; users aged 18 or over are adults. Your school is responsible for authorising eligible student accounts. For users under 18, any authorisation required by applicable law must be obtained from the school, parent or guardian, as applicable. School authorisation does not replace parental authorisation where the law requires it. We do not carry out age verification in the Workspace. Your date of birth is recorded by your school for its own purposes, not as an age check by us. We do not rely on your consent for any processing in the Workspace, so the age at which a child can consent under Article 8 of the UK GDPR and section 9 of the Data Protection Act 2018 does not arise.

We have designed the Workspace with the Information Commissioner's Office Age Appropriate Design Code (the Children's Code) in mind. The Workspace's data protection impact assessment must account for children aged 13 to 17 and their differing ages and development needs, as Standard 2 of the Code requires. We treat the best interests of users under 18 as a primary consideration when we design changes to it. The Workspace loads no analytics, advertising or marketing technology, does not profile users, and does not use Workspace data for any purpose other than those described in this notice.

The public website

We have considered whether the public site is an information society service likely to be accessed by children, within the meaning of section 123 of the Data Protection Act 2018 and the Children's Code. Our audience includes children aged 13 to 17 researching future study, and they are children for the purposes of that Code.

We therefore apply the Code's standards to the public site. We collect the minimum data we need. We set no non-essential cookie of our own without your consent, with one exception we are fixing: our tag container does not yet apply your choice tag by tag, so allowing analytics can still load a marketing tag from one of the advertising partners named above. We describe that under "Cookies and similar technologies", and turning analytics off stops it. We do not profile visitors by default. The cookie panel never turns a category on for you, although refusing all non-essential cookies currently takes one more click than accepting them.

The public pages do not ask for your date of birth or your age, and no page asks you for personal details in a form. Where a page offers to save a programme to your shortlist, it does so by signing you in to the Workspace, whose student accounts are for people aged 13 or over, as described in the Workspace sections of this notice. Public browsing is available without an account. The site is not aimed at children under 13. Under Article 8 of the UK GDPR and section 9 of the Data Protection Act 2018, a child in the UK can consent to an information society service from the age of 13, and we do not knowingly collect personal data from anyone under 13. We review this position at least once a year.

Email [email protected] if you believe a child under 13 has sent us personal data. We will delete it.

Your rights

You can tell us to stop using your data for direct marketing, at any time, and we must stop. Article 21(2) of the UK GDPR gives you that right and there is no exception to it. Click Cookie preferences in the site footer to turn marketing off, or email [email protected] and we will stop.

Under the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, and subject to certain limits, you have the following rights over your personal data:

  • Right to transparency (Article 12) - to have information about our processing given to you clearly and in writing.
  • Right to be informed (Articles 13 and 14) - where personal data is collected from you, and where it is not.
  • Right of access (Article 15) - to ask for a copy of the personal data held about you.
  • Right to rectification (Article 16) - to ask for data that is inaccurate or incomplete to be corrected. Many Workspace profile fields can be corrected directly by you or your school.
  • Right to erasure (Article 17) - to ask for your data to be deleted, in certain circumstances.
  • Right to restrict processing (Article 18) - to ask for processing to be paused, in certain circumstances.
  • Notifying others (Article 19) - when we correct, delete or restrict your data we tell each organisation we shared it with, unless that is impossible or would take disproportionate effort. Ask us and we will tell you who those organisations are.
  • Right to data portability (Article 20) - to receive your data in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and is carried out by automated means.
  • Right to object (Article 21(1)) - to object to processing based on legitimate interests. We stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. Where an objection to our use of Workspace data to develop AI features is upheld, we exclude your personal data from new data sets and take the reasonable, technically feasible steps described above.
  • Right to object to direct marketing (Article 21(2)) - to object at any time to your data being used for direct marketing. We stop, with no exception.
  • Right to withdraw consent (Article 7(3)) - where we rely on your consent, to withdraw it at any time, without affecting what we lawfully did with your data before you withdrew it.
  • Rights related to automated decision-making and profiling (Article 22) - the right not to be subject to a decision based solely on automated processing. We do not make decisions of that kind about you.
  • Right to complain to us (section 164A of the Data Protection Act 2018) - to complain to Studee about how we use your personal data, before or instead of going to the ICO.
  • Right to complain to the ICO (Article 77 of the UK GDPR and section 165 of the Data Protection Act 2018) - to complain about how we use your personal data.

Where to send your request

For public-website data, and for anything else where Studee is the controller, email [email protected] and tell us which of these rights you want to use.

For Workspace data, two organisations are involved, so the destination depends on the data:

  • Contact your school about school data: profile, applications, tasks, documents, grades and parent or guardian details. School staff should also contact their school about their own account data.
  • Email [email protected] about Studee data: sign-in data and records, acceptance records, AI development, and the fact of a support request and how we handled it. Ask your school about the school records quoted inside a support message; your school is the controller for those, and we handle them as its processor.

If you are not sure, email [email protected]. We will route your request, or point you to the right person at your school. Where your school handles the request, we help it, including by producing a copy of the data we hold and by making corrections, restrictions or deletions on its instruction, as our agreement with the school requires.

We respond within one calendar month, as Article 12(3) requires. If your request is complex, or if you make several requests, we may extend that by a further two months, and we will tell you within the first month if we need to.

There is no fee for most requests. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse to act on it, as Article 12(5) allows, and we will explain why. If we refuse a request, we will tell you why, and we will tell you that you can complain to the ICO and can apply to a court.

How we verify your identity

We check who you are before we act on a request, so that we do not disclose your data to someone else or delete it on a stranger's say-so.

Where we already hold information about you, we use that to confirm your identity. Where we have reasonable doubts about who you are, we may ask you for further information, as Article 12(6) allows. We ask only for what is proportionate to the request and to the risk, and we do not require certified copies of identity documents as a matter of course.

Send us only the information we ask for.

Complaints

You have the right to complain to us about how we have used your personal data. Complain to us first, under section 164A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act 2025.

Email [email protected] with the details of your complaint. We will acknowledge your complaint within 30 days, as section 164A requires, take the steps needed to deal with it, and tell you the outcome.

If you are not satisfied with our response, or we do not respond, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, under Article 77 of the UK GDPR and section 165 of the Data Protection Act 2018. The law now expects you to raise a complaint with us before the ICO acts on it, and the ICO may ask whether you have done so.

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

If you live or work outside the United Kingdom, you may also be able to complain to the data protection authority for the country you are in, or where you believe the problem happened. You may also have a right to an effective judicial remedy. UK data protection law still applies to what we do with your personal data.

Security

We take appropriate technical and organisational measures to protect personal data, as Article 32 of the UK GDPR requires. Across both the website and the Workspace these include access controls, encryption in transit, audit logging, and regular review of our processors.

In the Workspace we also apply:

  • separation between schools, so that one school's users cannot see another school's data;
  • role-based access control enforced on every request, and a permission check on every document download, which is streamed by our API rather than served from a public link;
  • malware scanning of uploaded files;
  • encryption at rest for data and documents;
  • sign-in without passwords, using a one-time code sent to your email address or Google sign-in;
  • an authentication cookie that your browser will not expose to scripts, which lasts 60 minutes and is re-issued while you are active;
  • automatic sign-out after 60 minutes without activity, unless you choose Stay signed in;
  • audit logging of sign-ins and other significant actions; and
  • database backups held in the same UK region for 35 days.

Keep your one-time codes to yourself and never forward them to anyone.

No system is perfectly secure. If a personal data breach affects data your school controls, we tell your school without undue delay, and within 48 hours of becoming aware of it under our agreement with the school; the school then decides what it must report and to whom. If a breach affects data Studee controls, we report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, as Article 33 of the UK GDPR requires. Where the breach is likely to result in a high risk to you, we tell you as well, as Article 34 requires.

Changes to this notice

We review this notice at least once a year, and we update it whenever our practices change or our sub-processors change.

When we change it, we publish a new version. Each version carries its own version number and a note of what changed, and it is the version that applies from the moment we publish it. A new version replaces the one before it; there is no future-dated version and no notice period. The version number and the publication date of the version you are reading are published in this page's metadata.

There is nothing here for you to accept. This notice tells you what we do with personal data; it is not an agreement between us, and we never ask you to accept it.

If you hold a Workspace account, two things happen when this notice changes. The Workspace shows you a short message telling you that the notice has been updated, which you can dismiss. Separately, when we ask you to accept a new version of the Terms and conditions, we record which version of this notice was shown to you at that moment. That record is evidence of what you were shown. It is not consent, and it is not acceptance of this notice.

Read the current version of this notice before you continue using the website or the Workspace.

How to contact us

Email our Data Protection Officer at [email protected] with any privacy question, request or concern.

For corporate and contractual questions, including our company-disclosure information, see our Terms and conditions.