The European Union General Data Protection Regulation (GDPR) is Regulation (EU) 2016/679 of the European Parliament and of the Council of the 27th of April, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, coming into force on the 25th of May, 2018. GDPR sets new standards and compliance requirements for every company that holds or processes personal data. It replaces the 1995 EU Data Protection Directive (European Directive 95/46/EC), strengthening the rights that EU individuals have over their data.
The English Language Centre Oxford, hereinafter referred to as Elcox, is a private company limited by shares, registered in England and Wales. The address of the registered office is 41 Cornmarket Street, OXFORD, OX1 3HA.
Elcox is committed to the highest standards of information security, data privacy, and transparency, and to managing data in accordance with legislation and regulation, including but not limited to GDPR, and attests that it will comply with applicable GDPR regulations as a provider of academic e-learning services to private fee-paying clients around the world.
Elcox will maintain and reinforce existing security and management policies, procedures, and controls, to ensure compliance with GDPR prior to the 25th of May, 2018.
Elcox secures its in-house handling of client data, whether on-site, in transit, or in the cloud, with end-to-end fully military-grade AES-256 encryption.
Elcox collects client data via its fully-certified https website displaying the green padlock icon at all times. Once in-house, client data is protected with military-grade AES-256 encryption, and from Internet attack by a VPN connection and Norton real-time protection against existing and emerging malware including ransomware and viruses.
Where and when Elcox relies on third-party services with respect to its website, email, data storage, and data collection, it attests that such services are and will continue to be industry-leading and security-certified providers and data centres with a high level of security, data confidentiality, integrity, and availability.
Elcox attests that its clients who consist in current private students, alumni, and prospective students remain the sole owners of the data they agree or have agreed to provide, thereby retaining the rights, title, and interest in that stored data and may at any time invoke their rights to request deletion, amendment, transfer, access, or processing of their personal data.
Elcox further attests that Data is collected for a specific purpose, namely the provision of private online distance learning courses and online one-to-one tuition to fee-paying students, and that the data necessary to this purpose is stored securely and not kept for longer than necessary.
Contact the Elcox Data Protection Officer at firstname.lastname@example.org