Privacy Policy
How UK TEFL Institute collects, uses, and protects your personal information.
UK TEFL Institute ("we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, enrol in our courses, or otherwise interact with our services.
This policy is issued in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. By using our website and services, you acknowledge that you have read and understood this policy.
Last updated: 1 March 2026
1. Information We Collect
We may collect and process the following categories of personal data:
1.1 Information You Provide Directly
- Identity data: your full name, date of birth, and nationality.
- Contact data: your email address, telephone number, and postal address.
- Account data: your username, password, and account preferences.
- Enrolment data: course selections, qualifications, and educational background.
- Payment data: billing address and payment card details (processed securely through our third-party payment provider).
- Communication data: records of correspondence when you contact us via email, telephone, or our contact form.
1.2 Information Collected Automatically
- Technical data: your IP address, browser type and version, operating system, device type, and screen resolution.
- Usage data: pages visited, time spent on pages, click patterns, referring URLs, and navigation paths through our website.
- Cookie data: information collected through cookies and similar tracking technologies (see our Cookie Policy for full details).
1.3 Information from Third Parties
- Analytics providers: aggregated and anonymised usage data from services such as Google Analytics.
- Payment providers: transaction confirmation and fraud prevention data from our payment processing partners.
- Social media platforms: publicly available profile information if you interact with us through social media channels.
2. How We Use Your Information
We process your personal data only where we have a lawful basis to do so under the UK GDPR. The lawful bases we rely upon include:
2.1 Performance of a Contract
- To process your course enrolment and manage your student account.
- To deliver course materials, assessments, and certificates.
- To process payments and issue invoices or receipts.
- To provide tutor support and respond to course-related queries.
2.2 Legitimate Interests
- To improve our website, courses, and services based on usage patterns and feedback.
- To administer and protect our business and website, including troubleshooting, data analysis, and system testing.
- To send you relevant information about course updates, new programmes, or career resources where you have an existing relationship with us.
2.3 Consent
- To send you marketing communications about our courses and services (you may withdraw consent at any time).
- To place non-essential cookies on your device.
2.4 Legal Obligation
- To comply with applicable laws, regulations, and legal processes.
- To maintain records required for tax, accounting, or regulatory purposes.
3. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse site traffic, and understand how visitors interact with our content. We use both essential cookies (necessary for the website to function) and non-essential cookies (used for analytics and marketing purposes).
You can manage your cookie preferences at any time through your browser settings or our cookie consent tool. For comprehensive information about the cookies we use, please refer to our Cookie Policy.
4. Sharing Your Information with Third Parties
We do not sell, rent, or trade your personal data to third parties. We may share your information with the following categories of recipients only as necessary to deliver our services:
- Payment processors: to securely process your course payments (e.g., Stripe, PayPal). These providers are PCI DSS compliant.
- Email service providers: to send transactional emails such as enrolment confirmations, course updates, and certificate delivery.
- Analytics providers: to help us understand website usage and improve our services (data is anonymised or aggregated where possible).
- Accreditation bodies: to verify course completions and issue accredited certifications where required.
- Legal and regulatory authorities: where we are required to do so by law, court order, or regulatory obligation.
- Professional advisers: including lawyers, auditors, and insurers where necessary for the administration of our business.
All third-party service providers are required to process your data in accordance with our instructions and applicable data protection legislation. We do not permit them to use your personal data for their own purposes.
5. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Specific retention periods are as follows:
- Student records and certificates: retained indefinitely to allow graduates to request verification of their qualifications at any time.
- Payment and transaction records: retained for 7 years in accordance with HMRC requirements.
- Marketing consent records: retained for as long as the consent remains valid, plus 12 months after withdrawal.
- Website analytics data: retained in anonymised form for up to 26 months.
- Contact form enquiries: retained for 2 years from the date of the enquiry unless a student relationship is established.
When your data is no longer required, it will be securely deleted or anonymised so that it can no longer be associated with you.
6. Your Rights Under Data Protection Law
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you (commonly known as a "subject access request").
- Right to rectification: You may request that we correct any inaccurate or incomplete personal data.
- Right to erasure: You may request that we delete your personal data where there is no compelling reason for its continued processing.
- Right to restrict processing: You may request that we suspend processing of your personal data in certain circumstances.
- Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to object: You may object to the processing of your personal data where we are relying on a legitimate interest as the legal basis.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us using the details provided below. We will respond to your request within one calendar month. There is no fee for making a request, although we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues. You can contact the ICO at ico.org.uk.
7. International Data Transfers
Some of our third-party service providers may be based outside the United Kingdom. Where we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place to protect your data, including:
- Transfers to countries that the UK Government has determined provide an adequate level of data protection.
- Use of standard contractual clauses approved by the Information Commissioner's Office.
- Binding corporate rules or other legally recognised transfer mechanisms.
You may contact us for further details about the specific safeguards applied to international transfers of your data.
8. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using SSL/TLS technology.
- Secure storage of personal data on protected servers with restricted access.
- Regular security assessments and vulnerability testing.
- Staff training on data protection obligations and best practices.
- Incident response procedures for the prompt detection and management of data breaches.
While we take all reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your personal information.
9. Children's Privacy
Our courses and services are intended for individuals aged 18 and over. We do not knowingly collect or process personal data from children under the age of 18. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information as promptly as possible.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any material changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically to stay informed about how we protect your personal data.
11. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal information, please contact us:
UK TEFL Institute
Data Protection Enquiries
71-75 Shelton Street, London, WC2H 9JQ
Email: [email protected]
Telephone: +44 20 7946 0958