How applicant, student and website data is collected and handled.
This prototype policy is a starting structure only. The final legally binding version should reflect the College’s actual data collection, payment processor, admission workflow, refund rules, governing entity and applicable law.
Application details, contact information, academic information, uploaded documents, enquiry data, payment references and basic technical logs where required for secure service delivery.
Admissions processing, applicant communication, payment reconciliation, statutory/academic administration, service improvement and information security.
Data may be shared with authorised College personnel, approved service providers, payment processors, university/regulatory bodies and lawful authorities where legitimately required.
Production systems should apply role-based access, encryption in transit, secure storage, audit logging, backups and documented retention/deletion schedules.
Insert the College’s designated privacy/grievance contact before launch.