Security Policy

Effective 16 September 2026. PASSION CONNECT CONSULTING - FZCO(“Passion Education”, “we”, “us”), IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates. This is a public summary of the technical and organisational measures referred to in ourPrivacy Policy. It deliberately describes what we commit to rather than how our systems are built: publishing the latter would itself weaken it.

1. Scope

This policy covers the personal data we process about prospective students, their parents or guardians, and the staff of the educational institutions we work with — whether it reaches us through our website, through an advertising platform, or through correspondence. It applies to all of our personnel and to any contractor acting on our behalf.

2. Governance

3. Protecting the data

4. Access control

5. Data minimisation

We ask only for the information an educational institution needs in order to advise a candidate. We do not request identity document scans, financial account details or health data, and we ask that they not be sent to us. We do not use data obtained from a platform for any purpose other than those set out in our Privacy Policy, and we do not sell it.

6. Retention and deletion

Personal data is kept only for the periods stated in ourPrivacy Policy and is then deleted or anonymised. Anyone may request deletion at any time; the procedure and the deadline we hold ourselves to are set out on theData Deletion page. Backup copies are cycled out in the ordinary course and are never used to reinstate a record that has been deleted on request.

7. Resilience and change control

8. Incident response

We maintain a documented procedure for security incidents: contain, assess the scope, remediate, and record. Where a personal data breach is likely to result in a risk to the people concerned, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform those affected without undue delay where the risk to them is high. Where platform data is involved we notify the platform concerned as its terms require.

Report a suspected vulnerability or incident toceo@passion-education.com. We acknowledge within two business days. We will not pursue anyone who reports a vulnerability in good faith and who does not access, alter or retain other people’s data.

9. Personnel and devices

Personal data is worked on only within our authorised systems, on devices with disk encryption, a screen lock and current security updates. It is not copied to personal accounts, personal devices or unauthorised applications.

10. Review

This policy is reviewed at least annually and whenever our processing changes materially. Questions go toceo@passion-education.com.

← passion-education.com · Privacy Policy · Terms of Service · Data Deletion · Legal Information