1. Introduction
IEC Global ("IEC", "we", "us", or "our") is an international education consultancy headquartered in Nairobi, Kenya. We help students β primarily from African nations including Kenya, Nigeria, Ghana, Uganda, and Tanzania β navigate the process of applying to universities in the United Kingdom, United States, Canada, Australia, Germany, the Netherlands, Ireland, and other destinations worldwide.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our website, Student Atlas portal, Counselor portal, Admin portal, or any related services and tools (collectively, the "Platform"). It applies to all users β students, parents or guardians, counselors, administrators, and general visitors.
By accessing or using our Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices described herein, please do not use our services.
2. Legal Framework and Data Controller
Imperial Education Consultants Ltd ("IEC") is a company registered in the Republic of Kenya and is the data controller responsible for your personal data as described in this Privacy Policy.
This Privacy Policy is governed by and compliant with the Kenya Data Protection Act, 2019 (No. 24 of 2019) ("the DPA"), which is the primary data protection legislation in Kenya. The DPA establishes rights for data subjects, obligations for data controllers and processors, and is enforced by the Office of the Data Protection Commissioner (ODPC).
Where our services are used by individuals in other jurisdictions, we also take into account the requirements of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other applicable local data protection laws. In the event of any conflict between this policy and the Kenya DPA, the provisions of the Kenya DPA shall prevail.
2.1 Data Controller Details
- Data Controller: Imperial Education Consultants Ltd
- Registered Address: Nairobi, Kenya
- Data Protection Officer (DPO): dpo@ieduconsultants.com
- Supervisory Authority: Office of the Data Protection Commissioner (ODPC), datacommissioner.or.ke
3. Information We Collect
We collect various categories of information to provide, improve, and secure our services. The types of information we collect include:
3.1 Personal Identification Information
- Full legal name, date of birth, gender, and nationality
- Email address, phone number (including messaging service number), and physical/mailing address
- Country of residence and country of citizenship
- Profile photograph
- Preferred language (English, French, Portuguese, or Swahili)
3.2 Identity and Travel Documents
- Passport copies, national identification cards, and birth certificates
- Passport numbers, issue/expiry dates, and issuing authority
- Visa documentation and immigration records
3.3 Education and Academic Records
- Academic transcripts, certificates, and diplomas
- Standardised test scores (IELTS, TOEFL, SAT, GRE, GMAT, PTE, Duolingo, etc.)
- Personal statements, statements of purpose, and motivation letters
- CVs/resumes and letters of recommendation
- Research proposals, writing samples, and portfolios
- Current and previous educational institution details
- Intended programme of study and preferred destinations
3.4 Financial Information
- Bank statements and financial support documents submitted for university or visa applications
- Scholarship and financial aid documentation
- Payment records for IEC consultancy services
- Sponsor/guarantor details where applicable
3.5 Communication Data
- Messages exchanged with counselors through our in-app chat system
- Translated messages (our chat supports real-time translation between languages)
- Email correspondence and messaging service communications
- Notes and records created by counselors during consultations
- Feedback, reviews, and survey responses
3.6 AI Interaction Data
- Queries and conversations with our Compass chatbot (public FAQ assistant)
- Documents submitted for AI-powered review and analysis
- AI-generated assessments, suggestions, and feedback on your documents
- Interaction logs with AI-assisted features
3.7 Technical and Usage Data
- IP address, browser type and version, device type, and operating system
- Pages visited, features used, time spent on pages, and click patterns
- Referring URLs and search terms used to reach our Platform
- Login timestamps, session duration, and activity logs
- Error logs and performance data
4. How We Collect Information
4.1 Information You Provide Directly
Most information we collect is provided directly by you when you create an account, fill out forms, upload documents, communicate with counselors, interact with our chatbot, or otherwise use our services.
4.2 Automated Collection
When you access our Platform, we automatically collect certain technical data through cookies, server logs, and similar technologies. This includes your IP address, browser type, device information, and usage patterns. We also store your language and currency preferences locally on your device.
4.3 Third-Party Authentication
We use Clerk as our authentication provider. When you sign up or log in, Clerk may collect and provide us with your email address, name, and profile information from your chosen sign-in method (email, Google, or other social providers). Clerk processes this data under its own privacy policy, which we encourage you to review.
4.4 AI and Automated Processing
When you upload documents or interact with our AI-powered features, your data is processed by artificial intelligence systems to provide document analysis, feedback, and suggestions. This processing generates additional data (such as AI assessments and recommendations) that we store and associate with your account.
4.5 Counselors and Administrators
Your assigned counselor or IEC administrators may add information to your profile, such as consultation notes, task assignments, application status updates, and internal assessments. This information is created in the course of providing our services to you.
5. Lawful Basis for Processing
In accordance with Section 30 of the Kenya Data Protection Act, 2019, we process your personal data only where we have a lawful basis to do so. The legal grounds on which we rely include:
5.1 Consent
Where you have given us clear, informed consent to process your personal data for specific purposes β for example, when you submit an application, upload documents, or agree to receive marketing communications. You may withdraw your consent at any time by contacting our Data Protection Officer at dpo@ieduconsultants.com, though withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.2 Contractual Necessity
Processing that is necessary for the performance of a contract to which you are a party β such as providing education consultancy services, processing your university applications, and facilitating communication with counselors.
5.3 Legitimate Interest
Processing that is necessary for our legitimate interests or those of a third party, provided that your fundamental rights and freedoms are not overridden. This includes platform security, fraud prevention, service improvement through analytics (including PostHog product analytics), and internal research.
5.4 Legal Obligation
Processing necessary for compliance with a legal obligation β such as tax record retention, responding to lawful government requests, and complying with the Kenya DPA and other applicable regulations.
6. How We Use Your Information
We use the information we collect for the following purposes:
6.1 Application Processing and Management
- Preparing, reviewing, and submitting applications to universities and educational institutions on your behalf
- Tracking application status and managing deadlines
- Coordinating with institutions regarding your application
6.2 Counselor Matching and Support
- Matching you with a qualified counselor based on your academic profile, destination preferences, and programme interests (including AI-assisted matching)
- Enabling counselors to review your documents and provide personalised guidance
- Facilitating real-time communication between you and your counselor, including translated messaging
6.3 Document Verification and AI Review
- Using AI-powered tools to analyse and provide preliminary assessments of uploaded documents (e.g., transcripts, personal statements, test scores)
- Verifying document completeness and identifying potential issues before submission
- Generating AI-assisted feedback and improvement suggestions for application materials
6.4 Communication
- Sending application updates, deadline reminders, and task notifications via email and in-app notifications
- Delivering event invitations, webinar reminders, and educational content
- Sending marketing communications about our services (with your consent, and you may opt out at any time)
- Facilitating messaging service communications where applicable
6.5 Platform Operations and Improvement
- Maintaining, securing, and improving the Platform and our services
- Analysing aggregated and anonymised usage data to enhance features and user experience
- Conducting analytics and generating reports on service performance
- Training and improving our AI models using anonymised and aggregated data
6.6 Legal and Compliance
- Fulfilling legal obligations and responding to lawful requests from authorities
- Enforcing our Terms of Service and other agreements
- Detecting, preventing, and addressing fraud, security issues, or technical problems
- Protecting the rights, property, and safety of IEC, our users, and the public
7. AI and Automated Decision-Making
Our Platform incorporates several AI-powered features to enhance our services. We believe in transparency about how these tools work:
7.1 Document Review AI
When you upload documents (such as personal statements, transcripts, or test score reports), our AI system may automatically analyse them to provide preliminary feedback, assess completeness, identify areas for improvement, and flag potential issues. These AI assessments are designed to assist β not replace β your counselor's professional review.
7.2 Compass Chatbot
Our public-facing Compass chatbot uses AI to answer frequently asked questions about our services, university applications, destinations, and general educational guidance. The chatbot provides informational responses only and does not make decisions about your application or account.
7.3 Counselor Assistance AI
AI tools assist counselors in managing student applications, drafting communications, reviewing documents, and generating content such as blog posts. These tools support counselor productivity but do not independently make decisions about student applications.
7.4 AI-Powered Matching
We may use AI to suggest counselorβstudent pairings based on specialisations, language preferences, destination expertise, and student profiles. Final matching decisions are reviewed and confirmed by administrators.
7.5 Your Rights Regarding AI
Important:
- AI does not make final decisions about your applications, eligibility, or account status. All significant decisions are made or reviewed by human counselors and administrators.
- You have the right to request human review of any AI-generated assessment or recommendation.
- You may object to automated processing of your data by contacting our Data Protection team.
- You may request an explanation of how AI tools have been used in relation to your data.
8. PostHog Analytics and Product Tracking
We use PostHog, a product analytics platform, to understand how users interact with our Platform and to continuously improve the user experience. PostHog operates as a data processor on our behalf under a data processing agreement.
8.1 Data Collected by PostHog
- Page views, navigation paths, and time spent on pages
- Click events, button interactions, and feature usage patterns
- Session recordings (anonymised β no keystrokes on sensitive fields are captured)
- Device type, operating system, browser type, and screen resolution
- Approximate geographic location derived from anonymised IP addresses
- User journey flows and conversion funnels (e.g., application completion rates)
- Error events and performance metrics
8.2 PostHog Cookies
PostHog sets cookies prefixed with ph_ to maintain session state and distinguish unique users. These cookies are first-party cookies set on our domain and are used solely for analytics purposes. They do not track you across other websites.
8.3 Data Processing and Storage
PostHog Cloud processes data on servers in the European Union and the United States. We have appropriate data transfer safeguards in place in accordance with Section 48 of the Kenya DPA. PostHog retains analytics data for a maximum of 12 months, after which it is automatically deleted.
8.4 Opting Out
You may opt out of PostHog analytics tracking by declining cookies when prompted by our cookie consent banner, or by adjusting your browser settings to block cookies prefixed with ph_. Opting out will not affect the core functionality of the Platform. You may also contact us at dpo@ieduconsultants.com to request deletion of your analytics data.
9. Data Sharing and Third Parties
We share your personal information only where necessary to provide our services, as described below. We never sell your personal data to advertisers or unrelated third parties.
9.1 Universities and Educational Institutions
When submitting applications on your behalf, we share relevant academic records, personal information, and supporting documents with your chosen universities and institutions. This sharing is essential to the application process and is done with your knowledge and at your direction.
9.2 Visa and Immigration Authorities
Where required, we provide supporting documentation to embassies, consulates, and immigration bodies to facilitate your visa application process.
9.3 Technology Service Providers
We use trusted third-party service providers to operate our Platform. Each provider is bound by data-processing agreements and processes your data only as instructed by us:
- Clerk β Authentication and user identity management. Processes your login credentials, email, and profile data.
- Convex β Backend database and real-time data infrastructure. Stores and processes your application data, messages, and profile information.
- Amazon Web Services (AWS) Bedrock β AI and machine learning services (Claude models). Processes documents and queries submitted to our AI features.
- AWS Translate β Real-time translation of chat messages between supported languages.
- Cloudflare R2 β Secure cloud storage for uploaded files and documents (passports, transcripts, financial statements, etc.).
- Resend β Transactional and marketing email delivery service.
9.4 Legal Requirements
We may disclose your information when required by law, court order, subpoena, or government request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a government request.
9.5 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred to the successor entity. We will notify you of any such change and ensure the successor entity honours this Privacy Policy.
10. International Data Transfers
IEC Global operates from Kenya and serves students across Africa and beyond. Given the international nature of our services and technology infrastructure, your personal data may be transferred to and processed in countries other than your country of residence, including:
- Kenya β Our headquarters and primary operations
- United States β Cloud infrastructure (AWS, Cloudflare, Convex, Clerk) and AI processing
- European Union β Where applicable for service providers and university communications
- Destination countries β UK, Canada, Australia, Germany, Netherlands, Ireland, and others where your chosen universities are located
We take appropriate safeguards to ensure your data remains protected during international transfers, including:
- Entering into data-processing agreements with all third-party providers that include standard contractual clauses where applicable
- Ensuring our service providers maintain appropriate security certifications and compliance standards
- Applying the same level of data protection regardless of where data is processed
- Complying with the Kenya Data Protection Act (2019) and, where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR
11. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
11.1 Active Accounts
Your data is retained for the duration of your active engagement with our services. We maintain all application materials, communications, and profile data while your account remains active.
11.2 Inactive Accounts
Our system monitors account activity and flags accounts that have been inactive for 90 days. Inactive accounts may be subject to follow-up communication to confirm continued interest. Extended inactivity may result in account archival, with data retained in a secure archive for the period described below.
11.3 Post-Engagement Retention
After your engagement with IEC ends (whether by completion of services, account closure, or termination), we retain your personal data for up to 5 years for legitimate business purposes including:
- Providing references or verification of past applications at your request
- Complying with legal, tax, and regulatory obligations
- Resolving disputes and enforcing our agreements
- Maintaining anonymised analytics data
11.4 Deletion
You may request deletion of your data at any time by contacting our Data Protection team. Upon receiving a valid request, we will delete or anonymise your personal data within 30 business days, except where retention is required by law or for the exercise or defence of legal claims. We will also instruct our third-party processors to delete your data from their systems.
12. Your Rights Under Kenya DPA
Depending on your location and applicable data protection laws (including the Kenya Data Protection Act, EU/UK GDPR, and other regional regulations), you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you, along with information about how we process it.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restrict Processing: Request that we temporarily limit how we process your data under certain circumstances (e.g., while we verify its accuracy).
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to Object: Object to processing of your data based on legitimate interests, including profiling and direct marketing.
- Right to Object to Automated Decisions: Object to decisions made solely through automated processing (including AI) that significantly affect you, and request human intervention.
- Right to Withdraw Consent: Where we process your data based on consent, withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint: File a complaint with the Office of the Data Protection Commissioner (Kenya), a supervisory authority in the EEA/UK, or your local data protection authority.
To exercise any of these rights, please contact our Data Protection team using the details in the Contact section below. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
13. Children's Privacy
Our services may be used by students aged 16 and older. We do not knowingly collect personal information from children under the age of 16 without verifiable parental or guardian consent.
For students aged 16 to 17, we require that a parent or legal guardian provides consent for the collection and processing of their data. Parents and guardians who have provided consent retain the right to:
- Review the personal data we have collected about their child
- Request correction or deletion of their child's data
- Withdraw consent for further data collection and processing
- Receive a copy of their child's data in a portable format
If we discover that we have collected personal information from a child under 16 without appropriate consent, we will take steps to delete that information promptly.
14. Security Measures
We take the security of your personal data seriously and implement a range of technical and organisational measures to protect it:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Secure File Storage: Uploaded documents are stored in Cloudflare R2 with access controls, ensuring only authorised personnel and systems can retrieve them.
- Role-Based Access Control (RBAC): Access to your data is restricted based on user roles (Student, Counselor, Admin), ensuring individuals can only access information relevant to their role and responsibilities.
- Authentication Security: We use Clerk for robust authentication, supporting secure sign-in methods, session management, and protection against unauthorised access.
- Rate Limiting: Our APIs implement rate limiting to prevent abuse and protect against automated attacks.
- Regular Security Reviews: We conduct periodic security assessments of our Platform and third-party integrations.
- Access Logging: We maintain logs of access to sensitive data for audit and security monitoring purposes.
While we strive to protect your data using industry best practices, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
16. Data Breach Notification
In accordance with Section 43 of the Kenya Data Protection Act, 2019, in the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will:
- Notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, including the nature of the breach, categories of data affected, approximate number of individuals affected, and the measures taken to address it.
- Notify affected data subjects without undue delay where the breach is likely to result in high risk to their rights, providing clear information about the breach and recommended protective measures.
- Document the breach internally, including facts, effects, and remedial actions taken, to demonstrate compliance.
We maintain incident response procedures and conduct regular security assessments to minimise the risk of data breaches. If you believe your data has been compromised, contact our DPO immediately at dpo@ieduconsultants.com.
17. Data Protection Impact Assessments
In accordance with Section 31 of the Kenya DPA and best practices under the GDPR, we conduct Data Protection Impact Assessments (DPIAs)before undertaking any processing that is likely to result in high risk to the rights and freedoms of data subjects. This includes:
- AI Document Review: Automated analysis of identity documents, transcripts, and financial statements using AWS Bedrock (Claude models).
- Automated Counselor-Student Matching: AI-powered profiling to recommend counselors based on specialisation, language, and regional expertise.
- Large-Scale Processing of Student Data: Processing application data of students across multiple African countries and international destinations.
- PostHog Session Recordings: Anonymised session replay data used for UX improvement.
DPIAs are reviewed annually or whenever a significant change is made to the processing activity. Summaries of DPIAs are available upon request to the ODPC.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- We will update the "Last updated" date at the top of this page.
- For significant changes, we will notify registered users via email and/or in-app notification at least 14 days before the changes take effect.
- We will provide a summary of key changes for your convenience.
- Continued use of our Platform after the effective date of an updated policy constitutes your acceptance of the changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
19. Complaints and Regulatory Contact
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the relevant data protection authority:
Office of the Data Protection Commissioner (ODPC) β Kenya
Website: datacommissioner.or.ke
Email: complaints@odpc.go.ke
The ODPC is the supervisory authority under the Kenya Data Protection Act, 2019.
You may also seek judicial remedies through the Kenyan courts under Section 56 of the DPA if you believe your data protection rights have been infringed. We encourage you to contact our DPO first so that we can attempt to resolve your concern directly.
20. Contact Information and DPO
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below:
General Enquiries
Email: info@ieduconsultants.com
Phone: +254 748 669 938
Address: Westlands, Nairobi, Kenya
Data Protection Officer (DPO)
Email: dpo@ieduconsultants.com
Our DPO is responsible for overseeing compliance with the Kenya Data Protection Act, 2019 and related data protection laws. Contact the DPO for data subject access requests, consent withdrawal, complaints, or any privacy-related concerns.
We aim to respond to all data protection enquiries within 30 days as required by the Kenya DPA. We may need to verify your identity before processing data subject requests. Complex requests may take up to an additional 30 days, in which case we will inform you of the extension and reasons.
