Data Protection Notice

Who we are

Aberystwyth University ‘The University’, ‘we’ or ‘us’) are a ‘Data Controller’ and are responsible for and control the processing of your Personal Data. 

You can contact our Data Protection Officer at infogovernance@aber.ac.uk, Aberystwyth University.

This privacy notice is for Aberystwyth University 100%Online Programmes.  We have partnered with an external organisation, Higher Education Partners (HEP) to carry out the management of the online programme delivery. The notice explains how we collect and process your personal data, whether it be for general enquiries or personal data for applications or enrolment.

How We Use Your Data

We will collect and process your personal data for several related reasons. Please see all our purposes listed below:

Purpose

Lawful Basis (Reason)

To respond to your enquiries and fulfil your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, or complaints.

Legitimate interest

To send you marketing related emails, with information about our services and other news about us.

Consent

Assessing your eligibility to be offered a place on one of our online academic courses and programmes

Necessary for a contract or entering into a contract

 

To complete your transactions, and provide you with related assistance in relation to your application.

Necessary for a contract or entering into a contract

Provision of your course of study during your period of enrolment.

 

Necessary for a contract or entering into a contract

Making reasonable adjustments for disabilities and providing relevant support to students or applicants with ill health

 

Substantial public interest – specifically support for individuals with a particular disability or medical condition

 

Assessment of academic progress and performance (including attendance)

Necessary for a contract or entering into a contract

To provide you with support and pastoral services throughout your course of study.

Necessary for a contract or entering into a contract

Administration of complaints, grievances and appeals

Necessary for a contract or entering into a contract

Obtaining payment of fees

Necessary for a contract or entering into a contract

To Communicate directly with students for the purposes of student experience and to communicate updates to documents such as terms and conditions and policies

Legitimate Interests

For audit purposes and to verify that our internal processes are compliant with legal, regulatory or contractual requirements.

Legal obligation

Fraud and security monitoring purposes, including to prevent cyber-attacks.

Legitimate Interest

Developing, enhancing, improving, or modifying our current services, identifying usage trends and determining the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users.

Legitimate Interest

Automated decision making and profiling for business reporting and providing personalised services to you tailored to your interests.

Legitimate Interest

Market research and surveys

Necessary for the legitimate interests of planning and developing the University’s operations.

External Reporting Including to HEFCW and its agencies

Legal Obligation

We will always highlight areas where we need to ask for your consent as the lawful basis and will give you the choice to opt-in. If you do consent or opt in, we will let you know how you can opt out in the future. We will not process your personal data for any other purpose other than those stated above without informing you first.

We may use your data for reporting purposes to improve targeting, personalisation and overall effectiveness of marketing activity. If we do this we will either aggregate your data or anonymise it to ensure you cannot be identified.

Information We Collect

The majority of information that we process about you will be provided by you, typically by one of the following methods including: when you submit your details on the request information form on our website or paid traffic landing pages, by applying for admission via our online application form; and when you contact us by phone and provide information to one of our enrolment advisors. All our phone conversations are recorded for training and quality purposes.

We may get additional information from your referee or employer where one is required.

Information provided by you will include details such as:

  • First Name

  • Last Name

  • Other names used

  • Postal address

  • Email address

  • Telephone number

  • Mobile number

  • Nationality

  • Country of residence

  • Second Nationality

  • Gender

  • Date of birth

  • IP Address

  • Financial data

  • Disability

  • Educational records and qualifications, including higher and further education institutions attended, dates of attendance, degree programme titles, subjects and grades

  • Higher and further education transcripts and certificates

  • Work history – including employer, job title, responsibilities, location and dates in role

  • School type of data subject

  • Confirmation of whether English is first language

  • Membership of professional or industry associations

We are required to collect your personal data in order to provide the requested services to you and facilitate your application process. If you do not provide the information requested, we may not be able to provide our services or consider you for admission. If you disclose any personal data relating to other people to us or to our service providers in connection with our services, you represent that you have the authority to do so and to permit us to use the information in accordance with this privacy notice.

 

Who We Share Your Personal Data With

Information is shared with relevant departments within the University for the purposes outlined above. In addition, specific data may be obtained from and shared with the following parties for the purposes specified:

Recipient or Source

Purpose and type of data

Lawful Basis

Third parties such as auditors or legal entities

Other third parties may include auditors to facilitate auditing purposes, or parties which may assist us to enforce our terms and conditions.

Legal obligation

External Statutory Reporting

Transparency Return including identifiable personal data and special category data.

Statutory requirement

Educational Institutions

Verification of qualifications – Grades and transcripts of grades achieved

Necessary for a contract or entering into a contract

Student Loans Company/Other funders

To facilitate the payment of funds – Contact and payment details

Necessary for a contract or entering into a contract

Organisations with enforcement powers.

To comply or assist with requests in accordance with their enforcement powers

Legal obligation

We will ensure that we have a robust data processing agreement in place with any third-party data processor we use. We will only share the minimum amount of personal data with any of the above and will always do so in accordance with the law.

Higher Ed Partners uses third parties for services such as website hosting, contact centres, information technology and data analysis. These are:

Name of Sub-Processor

Sub-Processor’s details (company number, address)

Location of Sub-Processor and jurisdiction in which data is Processed

Personal Data to be Processed by Sub-Processor

Salesforce.com Inc

This company provides CRM Software

[Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA.

UK

Application data

Contact details including name, telephone number and email address

Country of domicile, Title, Education level, English test, first degree institution, Qualification Title, Degree Class, Awarded Status,

Gender, Nationality, disability information (for the purposes of accessibility) and more

Microsoft Corporation, Inc,

One Microsoft Way Redmond, WA 98052-6399, USA

EU

N/A

MailGun, LLC

This company provides email relays.

701 Brazos St. Austin, TX 78701 United States

USA

Name, email address, Personal information and emails

GearSet Limited.

This company provides CRM Release Deployment and Data Anonymisation Service.

The Bradfield Centre, Cambridge Science Park Rd, Cambridge, CB4 0GA

UK

This tool allows us to deploy our CRM changes from dev platform to production and don’t normally handle any student data.

Google LLC

This company provides analytics and ad services

1600 AMPHITHEATRE PARKWAY MOUNTAIN VIEW CA 94043. We have data centres in the US and EU.

EU

N/A

Darktrace Holdings Limited

. This company provides cybersecurity services

Maurice Wilkes Building, St John's Innovation Park, Cowley Road, Cambridge, United Kingdom, CB4 0DS

UK

Darktrace's systems monitor network activity, learn normal behaviour, and identify anomalies indicative of potential cyberattacks, helping our organization protect the digital assets from evolving threats. We do not share the student data specifically, but it does check the network traffic for vulnerabilities

Them Digital Assistance Limited,

This company provides desktop support and infrastructure management services

Them Digital Assistance Limited, a limited company incorporated in the United Kingdom under the Companies Acts under number 04680604 and having its place of business at 4th Floor 1-5 Clerkenwell Road, London, EC1M 5PA.

UK

Name, email address

Them Digital offers desktop support and IT asset management services. They do not have access to student data or our CRM.

Atlassian, LLC.

This company provides service desk and software project management platform.

Atlassian, LLC. An Australian-based company registered office at Level 6, 341 George Street, Sydney, NSW, 2000,

EU

Student personal information study status, emails and applications are shared on this platform when we need to investigate issues regarding those specific students.

Radicle Inc

This company provides some Salesforce and integration development

Radicle Inc, a US incorporated company having its place of business at 300 W Adams Street, Suite 421, Chicago, IL 60606, USA, with offices in the US and India.

USA

Radicle provide services for the development and integrations of our platforms and therefore they have access to our CRM and most of the data we hold.

Anything is Possible MediaLimited, (AIP)

ANYTHING IS POSSIBLE MEDIA LIMITED, a UK-based company, providing marketing services, having their place of business at the 3rd Floor Pelham House, 25 Pelham Square, Brighton, East Sussex, United Kingdom, BN1 4EA.

UK

Name, email address, telephone, RFI data, including courses students are interested in, applications started etc.

Files.com

This company provides secure file storage for Integration Platform.

Files.com (formally BrickFTP, owned by ActionVerb) is a service owned by Action Verb LLC, a US based company registered office at PO Box 29502, #20898, Las Vegas, NV 89126, USA.

EU

We will be using files.com for integrations and will hold information including personal data.

New Voice Media (Vonage)

This company provides telecommunications services for contact centre in the UK

(now owned by Vonage), a UK-based company with a registered office at of NewVoice Media House, Jays Cl, Basingstoke RG22 4BS. Our data centre for this service is in the EU. 

UK

Personal information including phone numbers and demographics data.

Adobe, Inc (Magento)

This company provides eCommerce Platform

Adobe, Inc. a US-based company with a registered office at Adobe 345 Park Avenue San Jose, CA 95110-2704. Our data centre for this service is in the EU..

EU

Personal information, application data, registration data, module connections, payment information and login details for student hub (Magento)

Amazon Web Services, Inc.

This company provides some data integration and networking services

Amazon Web Services, Inc. a US-based company with a registered office at 410 Terry Avenue North, Seattle, WA 98109-5210, USA. Our data centres for these services are in the US, UK and EU. This company provides some data integration and networking services.

UK

Personal information, application data, registration data, module connections, payment information and login details for student hub (Magento)

Instructure, Inc.

This company provides learning management system

Instructure, Inc. a US-based company registered office at 6330 South 3000 East, Suite 700, Salt Lake City, UT 84121, United States with our data centre being in the EU.

EU

Name, institution email address (Note we are using City’s and not the Supplier’s Canvas instance)

OwnBackup,

This company provides CRM data backup and archiving services.

OwnBackup, A US-based company having its place of business at 940 Sylvan Ave, Englewood Cliffs 07632.

UK

 Personal information, application data, registration data, module connections, payment information and login details for student hub (Magento) 

Name, transaction details

Personal information, address, modules and transaction detail

Dell Boomi

This company provides primary Integration Platform.

Dell Boomi US East Coast Office, 1400 Liberty Ridge Drive, Chesterbrook US PA19087.

UK

Personal information, application data, registration data, module connections and payment information.

Slack

This company provides a communications platform.

San Francisco, Salesforce Tower, 415 Mission St, San Francisco, United States, and has 5 office locations.

U. S

Name, e-mail and phone number

 

HEP GROUP COMPANIES: 

Name of Sub-Processor

 

Sub-Processor’s              details

(company number, address)

Location of Sub-Processor and jurisdiction in which data is Processed

HIGHER ED INTERNATIONAL, LLC

US based company having its place of business at 2200 Ross Avenue, Suite 3800, Dallas,

Texas 75201

US

Please be advised that the third parties used may change from time to time and in which case we will update this notice. We will ensure that Higher Ed Partners have robust data processing agreements in place with any third parties within the EEA, as well as Standard Contractual Clauses or Binding Corporate Rules with any third parties based outside the EEA.

Retention 

  • Successful application data will be retained for six years from the end of the current academic year.

  • Unsuccessful application data will be retained for one year.

  • Enquiry data will be retained for three years.

  • Telephone recordings will be retained for one year.

  • Enrolment data will be retained for ten years following the end of your course. 

Your Individual Rights

As an individual, you have a number of rights available to you. To find out more about how you may exercise those rights, for example, The Right of Subject Access: obtaining a copy of your information which we may hold; The Right to Rectification: correcting any mistakes or completing the information we hold about you; or The Right to Object to Automated Individual Decision-Making please see our Data Protection web pages  or the ICO website for more information.

If you no longer want to receive marketing-related emails , you may opt-out by following the instructions contained in each such email or by contacting us at dataprotection@higheredpartners.co.uk.

How to Complain

If you have any queries, concerns or believe that your Personal Data is being handled in a manner which is contrary to statutory requirements, you may wish to contact the University’s Data Protection Officer via infogovernance@aber.ac.uk

You also may lodge a complaint with a data protection authority for your country or region or where an alleged infringement of applicable data protection law occurs.

Changes to Privacy Notice

We regularly review our privacy notice and will review it at least annually. This privacy notice was last updated on 26th March 2025.