Students World

Privacy Policy

Version 1.0. In force from 22 August 2026.

This Privacy Policy is given pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the GDPR) and to Legislative Decree no. 196 of 30 June 2003 as amended by Legislative Decree no. 101 of 10 August 2018 (the Italian Privacy Code).

It sets out the particulars of the processing of personal data carried out by the Controller in connection with the Service. The terms of service governing use of the Service are published separately at Terms of Service.

1.Data controller

1.1

The controller of the processing described in this Policy is legal entity name, with registered office at registered office, VAT number P.IVA (the Controller).

1.2

The Controller may be contacted in respect of any matter arising under this Policy at privacy email address.

2.Scope

2.1

This Policy applies to the Students World Platform, comprising the website operated by the Controller, the ambassador pages forming part of it, and the Telegram group opened following a request for an introduction (together, the Service).

2.2

This Policy does not apply to the consulting business carried on by the Controller with universities and institutions, which is a separate activity and is not conducted through the Service.

2.3

Were a disclosure under clause 5.2 to be made, this Policy would not apply to the processing carried out by the University following it. In respect of that processing the University would determine the purposes and means on its own account and act as an independent controller, and its own privacy policy would apply.

2.4

This Policy does not apply to Telegram, which processes messages exchanged in the group under its own terms and privacy policy.

3.Definitions

3.1

In this Policy the following expressions bear the following meanings.

Ambassador
A student enrolled at a University who is engaged by the Controller and who corresponds with prospective students through the Service under the authority and instruction of the Controller.
Data subject
The natural person to whom the personal data described in this Policy relate, being the person requesting an introduction.
University
The higher education institution nominated on the ambassador page from which the request for an introduction is made.
Processor
A person appointed under Art. 28 GDPR to process personal data on behalf of and on the documented instructions of the Controller.

4.Categories of personal data processed

4.1

Data provided by the data subject: name, surname, electronic mail address, and country of origin. Country of origin is collected because it determines which admission, entry and residence requirements apply to the data subject, and is not transmitted to the university.

4.2

Data relating to consent: the consents given or withheld, the version of the wording displayed at the time, and the date and time of the act.

4.3

Data arising from the Telegram group: the Telegram username and numeric identifier of the data subject, and the messages exchanged in the group.

4.4

Data collected automatically upon access: IP address, user agent, referring page, and the date and time of access.

4.5

No special categories of personal data within Art. 9 GDPR are requested by the Controller. The data subject is asked not to communicate such data through the Service.

4.6

The Controller does not acquire personal data concerning the data subject from third-party sources.

4.7

Data collected upon a visit to an ambassador page or a university page, for the purpose described at clause 14.1: a salted, one-way hash of the IP address and user agent, computed afresh for each calendar day. The IP address and user agent themselves are not retained.

5.Purposes of the processing and legal bases

The purposes of the processing, the categories of data processed for each, and the legal basis on which each is carried out are as follows.

5.1

Effecting the introduction requested by the data subject

The processing is necessary in order to perform the service requested by the data subject and to take steps at the data subject’s request prior to the provision of that service. The declaration recorded at the same moment is an acknowledgement of this Policy and of the support relationship, and is not the basis upon which the processing is carried out.

Categories of data
Name, surname, electronic mail address, and the country of origin stated by the data subject.
Legal basis
Art. 6(1)(b) GDPR, performance of a contract
5.2

Disclosure of the data subject’s particulars to the nominated university

Not currently carried out.

This disclosure is not presently carried out and no consent to it is presently sought. Should it be carried out, consent will be obtained by affirmative act before any particulars are disclosed, will be sought separately from any other consent, and may be withdrawn at any time under Art. 7(3) GDPR. Upon disclosure the university determines the purposes and means of its own processing and acts as an independent controller in respect of it.

Categories of data
Name, surname, and electronic mail address.
Legal basis
Art. 6(1)(a) GDPR, consent
5.3

Retention of a record of the conversation with the ambassador

The legitimate interests pursued are the supervision and quality assurance of the service, the ability to intervene where a conversation does not progress, and the ability to evidence which ambassador effected the introduction. The data subject is informed of the record before the group is opened, and the assistant maintaining it is present in the group as a disclosed third participant.

Categories of data
The messages exchanged in the Telegram group and the Telegram username of the data subject.
Legal basis
Art. 6(1)(f) GDPR, legitimate interests
5.4

Service communications concerning an introduction already commenced

The legitimate interest pursued is the completion of a process the data subject has initiated. Communications under this purpose are limited to that process and each carries a facility to object, the exercise of which terminates them.

Categories of data
Name and electronic mail address.
Legal basis
Art. 6(1)(f) GDPR, legitimate interests
5.5

Direct marketing communications

Consent is sought separately and is not a condition of any other part of the service. It may be withdrawn at any time under Art. 7(3) GDPR, including by the facility contained in each communication. Upon withdrawal the electronic mail address is entered on a suppression list for the sole purpose of ensuring that no further communication is sent.

Categories of data
Name and electronic mail address.
Legal basis
Art. 6(1)(a) GDPR, consent
5.6

Evidence of the introduction and of the consent given

The legitimate interests pursued are the establishment of which ambassador effected an introduction, the performance of the Controller’s arrangements with the universities with which it works, and the discharge of the Controller’s obligation under Art. 7(1) GDPR to demonstrate that consent was given. Records forming part of the Controller’s accounts are retained for the period prescribed by Italian law.

Categories of data
Name, the nominated university, the ambassador, the date and time, the version of the wording assented to, and the IP address and user agent recorded at the moment of assent.
Legal basis
Art. 6(1)(f) GDPR, legitimate interests
5.7

Security, prevention of misuse, and diagnosis of faults

The legitimate interests pursued are the prevention of fraudulent or automated submissions, the prevention of attempts to misattribute an introduction, and the maintenance and security of the service.

Categories of data
IP address, user agent, referring page, and the date and time of access.
Legal basis
Art. 6(1)(f) GDPR, legitimate interests
5.8

Measuring which content brings students to the Service

The legitimate interest pursued is understanding which ambassador pages and university pages lead a visitor to request an introduction, so that the Controller can direct its own efforts toward what demonstrably works. The daily rotation of the salt prevents the record from being used to follow a visitor from one day to the next, and no cookie or other tracking technology is used to collect it.

Categories of data
A salted, one-way hash of the IP address and user agent recorded on each visit to an ambassador page or a university page, computed afresh for each calendar day. The IP address and user agent themselves are not retained.
Legal basis
Art. 6(1)(f) GDPR, legitimate interests

6.Nature of the provision of data

6.1

The provision of the data listed at clause 4.1, and the declaration made at the same moment, are necessary in order for an introduction to be effected. Where they are not provided, the Service cannot be provided. No further consequence follows.

6.2

The consent referred to at clause 5.5 is optional. Its refusal has no effect upon any other part of the Service and is not a condition of it.

6.3

There is no statutory or contractual obligation upon the data subject to provide any of the data described in this Policy.

7.Recipients

7.1

An Ambassador processes personal data as a person acting under the authority of the Controller within the meaning of Art. 29 GDPR and as a person authorised to process within the meaning of Art. 2-quaterdecies of the Italian Privacy Code. An Ambassador is not a recipient within the meaning of Art. 4(9) GDPR, and the making available of personal data to an Ambassador does not constitute a disclosure to a third party.

7.2

Each Ambassador is designated in writing, is authorised to process personal data only upon the instructions of the Controller, is bound by an obligation of confidentiality, and receives no more than the name of the data subject and such information as the data subject communicates within the Group. An Ambassador does not receive the electronic mail address of the data subject.

7.3

Personal data may be disclosed to the following recipients and categories of recipients.

The nominated university
Where and only where consent under clause 5.2 has been given. The university thereafter acts as an independent controller and its own privacy policy governs its processing.
Telegram
The conversation is conducted on Telegram, which processes it under its own terms and privacy policy. The group is private to the data subject, the ambassador and the assistant. No content is published.
Processors engaged by the Controller
Providers of hosting, database and electronic mail delivery services, each appointed under a contract satisfying Art. 28 GDPR and acting only on the documented instructions of the Controller.
Professional advisers and public authorities
Legal and accounting advisers where necessary, and public authorities where disclosure is required by law.
7.4

Personal data are not sold, leased, or disclosed to advertisers or to data brokers, and are not disclosed to any recipient outside the categories set out above.

8.Transfers to third countries

8.1

Certain of the recipients identified at clause 7.3, including Telegram, are established outside the European Economic Area.

8.2

Where personal data are transferred to a third country that is not the subject of an adequacy decision under Art. 45 GDPR, the transfer is carried out on the basis of the standard contractual clauses adopted by the European Commission under Art. 46(2)(c) GDPR.

8.3

A copy of the safeguards relied upon may be obtained on request at privacy email address.

9.Retention periods

9.1

Personal data are retained for the periods set out below, determined by reference to the purpose for which they were collected.

Record of the introduction and of the consent given
For the duration of the Controller’s engagement with the nominated university in respect of the application, and for five years thereafter, a question as to which ambassador effected an introduction being capable of arising long after enrolment.
5 years after the engagement ends
Record of the conversation with the ambassador
Twenty-four months from the last message, upon which it is erased.
24 months
Data processed for direct marketing
Until consent is withdrawn or an objection is made, and in any event not more than twenty-four months from the last interaction of the data subject with a communication sent under that consent.
24 months from last interaction
Suppression list
Indefinitely. The list contains no more than is required to identify the address and refrain from contacting it, an objection being of no effect if the record of it is erased.
Indefinite
Accounting records
Ten years, being the period prescribed by Art. 2220 of the Italian Civil Code.
10 years
9.2

Upon expiry of the applicable period the personal data are erased, or irreversibly rendered incapable of being attributed to a data subject.

10.Security of processing

10.1

The Controller implements technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, including encryption of personal data in transit and at rest and the restriction of access to those persons who require it for the performance of their functions.

10.2

Personal data by which a data subject is directly identified are held separately from the remaining records of the Service.

10.3

In the event of a personal data breach the Controller shall notify the supervisory authority in accordance with Art. 33 GDPR and, where the breach is likely to result in a high risk to the rights and freedoms of the data subject, shall communicate it to the data subject in accordance with Art. 34 GDPR.

11.Rights of the data subject

11.1

The data subject is entitled to exercise the following rights.

Access
To obtain confirmation as to whether personal data concerning the data subject are processed, a copy of those data, and the particulars set out in that Article.
Art. 15 GDPR
Rectification
To obtain the rectification of inaccurate personal data and the completion of incomplete personal data.
Art. 16 GDPR
Erasure
To obtain the erasure of personal data where one of the grounds in that Article applies. Where an exemption is relied upon, the Controller shall identify it.
Art. 17 GDPR
Restriction of processing
To obtain the restriction of processing in the circumstances set out in that Article, whereupon the data are stored but not otherwise processed.
Art. 18 GDPR
Portability
To receive personal data provided by the data subject in a structured, commonly used and machine-readable format, and to have those data transmitted to another controller where technically feasible.
Art. 20 GDPR
Objection
To object to processing carried out on the basis of legitimate interests. Where the objection concerns direct marketing, the processing shall cease and no balancing of interests arises.
Art. 21 GDPR
Withdrawal of consent
To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal or processing carried out on another basis.
Art. 7(3) GDPR

12.Exercise of rights

12.1

The rights set out at clause 11.1 are exercised by written request to privacy email address.

12.2

The Controller shall respond without undue delay and in any event within one month of receipt, in accordance with Art. 12(3) GDPR. That period may be extended by two further months where necessary, in which case the Controller shall inform the data subject of the extension and of the reasons for it within the first month.

12.3

No fee is charged, save in the circumstances contemplated by Art. 12(5) GDPR.

12.4

The Controller may request such further information as is necessary to confirm the identity of the person making the request, in accordance with Art. 12(6) GDPR.

12.5

Consent to direct marketing may in addition be withdrawn by means of the facility contained in each communication sent under it, without any request under clause 12.1 being necessary.

13.Cookies

13.1

The Controller does not use profiling cookies, advertising cookies, or third-party analytics on the pages accessible to a data subject. Accordingly no consent is sought under Art. 122 of the Italian Privacy Code.

13.2

Technical cookies strictly necessary for the availability and security of the Service are set by the providers of hosting services. No consent is required for cookies of that description.

14.Measurement of page views

14.1

The Controller counts visits to ambassador pages and to university pages forming part of the Service, so as to measure which content brings students to the Service.

14.2

No cookie is set for this purpose, and no tracking technology requiring consent under Art. 122 of the Italian Privacy Code is used.

14.3

The visitor is identified by a salted, one-way hash of the IP address and user agent recorded at the moment of the visit. The salt changes with the calendar day, so the hash computed for a given visitor on one day differs from the hash computed for the same visitor on the next, and the same person cannot be followed across days.

14.4

The IP address and user agent themselves are not retained. What is stored is the hash described at clause 14.3.

14.5

This hash is produced by pseudonymisation within the meaning of Art. 4(5) GDPR and remains personal data within the meaning of Art. 4(1) GDPR notwithstanding the salting and the daily rotation. It is not anonymous data.

15.Minors

15.1

The Service is not directed to persons under the age of 16, who may not use it.

15.2

Where the Controller becomes aware that personal data relating to a person under that age have been provided, those data shall be erased. Any person having knowledge of such a circumstance is invited to notify the Controller at privacy email address.

16.Automated decision-making

16.1

No automated decision-making within the meaning of Art. 22(1) GDPR, including profiling, is carried out in respect of the data subject. The Ambassador with whom the data subject is placed in contact is selected by the data subject.

17.Amendments

17.1

The Controller may amend this Policy. The version in force is published at this address and bears the version number and date of effect stated at its head.

17.2

Where an amendment materially affects the data subject and the Controller holds an electronic mail address for that data subject, notice of the amendment shall be given by electronic mail.

18.Complaints

18.1

The data subject has the right to lodge a complaint with a supervisory authority under Art. 77 GDPR. In Italy that authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy.

18.2

A data subject resident or working in another Member State of the European Economic Area, or in which the alleged infringement occurred, may lodge the complaint with the supervisory authority of that State.

18.3

The right at clause 18.1 is exercisable without prior recourse to the Controller. The Controller nevertheless invites any complaint to be addressed to it in the first instance, at the address given at clause 1.2.

18.4

For matters other than the processing of personal data, the Controller may be contacted at support email address.