1. Who we are and what this policy covers
Nara Abroad ("Nara", "we") runs nara-abroad.co.uk, the student portal at student.nara-abroad.co.uk, and the portals used by our partner agents and by universities. We help students, mostly from the Middle East and North Africa, find and apply to universities in the United Kingdom and elsewhere.
Nara is the controller of the personal data described here under the UK GDPR and the Data Protection Act 2018. Our ICO registration number will be published on this page as soon as it is issued.
This policy covers the website, the portals, our AI assistant and the emails we send you. It describes what we actually do today — not what a platform like ours might do in general — and the date at the top is the date it last changed. Questions about anything in it: privacy@nara-abroad.co.uk.
2. The information we hold about you
Everything below comes from you, from your use of the platform, or from the universities and partners involved in your applications. We do not buy data and we collect nothing from social media.
- Account: your email address, preferred language and — if you sign in with Google — the Google account identifier plus the name and email Google shares with us.
- Profile: name, phone number, date of birth, gender, nationality, address, native language, passport number and dates, and a profile photo if you add one.
- Academic and professional history: schools and universities attended, grades, work experience, languages, test scores (IELTS, TOEFL and similar) and skills.
- Application details: the courses you apply to, your answers to application questions, your study preferences, and whatever the university asks for. Some universities also ask about study gaps, failed modules and previous visa refusals; we ask those questions only because the application requires them.
- Documents you upload: passport scans, transcripts, certificates, English-test results, references, a CV or personal statement. They are stored as files, separately from the database.
- Contacts you add: an emergency contact or an alternative contact person, when you choose to add one.
- Assistant conversations: the text of your chats with our AI assistant. When voice calls are available, what you say is transcribed and the transcript is kept in the same way; the audio itself is not stored (section 5).
- Payments: the amount, currency, date and status of each Nara fee you pay, and a Stripe reference. Card details go directly to Stripe and never reach our servers.
- Support messages: emails you send to support@ or privacy@, and contact-form messages.
- Technical records: the IP address, browser and time of each sign-in (kept with your session), and standard server logs of requests to our API, used for security and troubleshooting.
- Newsletter: your email address, if you subscribe on our website.
If a partner education agent created your account for you, the information in it was provided by that agent on your behalf — see section 4.
3. Why we use your information, and the legal basis
UK GDPR requires a lawful basis for each use. Ours are:
- To run your account and your applications — building your profile, matching you with courses, preparing and submitting applications, tracking their status and telling you about decisions. Basis: performing our contract with you.
- To answer your questions through the AI assistant and give course recommendations. Basis: performing our contract with you. The assistant suggests; it does not decide. No decision with legal or similarly significant effect on you is taken automatically — admissions decisions are made by universities, and any change the assistant proposes to your profile or application is shown to you for confirmation first.
- To take payment for Nara's fees and keep the financial records the law requires. Basis: contract, and our legal obligation to keep accounting records.
- To send emails about your account and applications — sign-in codes, status updates, document requests. Basis: contract. These are not marketing and cannot be switched off while you have an account.
- To send our newsletter, if you subscribed. Basis: your consent; every issue has an unsubscribe link.
- To keep the platform secure — sign-in records, rate limiting, server logs, error monitoring. Basis: our legitimate interest in protecting the service and your data.
- To meet legal duties and respond to lawful requests from authorities. Basis: legal obligation.
Special category data. We do not ask about your health, religion, ethnic origin or similar. A document a university requires (for example a medical letter supporting a deferral) may contain such information; we process it only because you chose to provide it for that application, on the basis of your explicit consent, and you can delete the document from your portal at any time.
We do not use your data for advertising, and we do not sell it.
4. Who we share your information with
- Universities and colleges you apply to. When you submit an application, the personal details, documents and answers it contains are sent to that institution. From that point the institution is also a controller of that data under its own privacy policy, and it may be outside the UK (section 6).
- Our course-supply partner. Most of the courses in our catalogue come from a partner that can submit applications to universities on our behalf. Today we submit applications to universities ourselves, and nothing about you is passed to that partner. If we ever pass an application to our course-supply partner for submission, we will tell you first, and that partner becomes a controller of it under its own privacy policy.
- Partner education agents. If a partner agent created your account for you, that agent can see and manage your profile, documents and applications, because you asked them to handle your applications. Ask us at privacy@nara-abroad.co.uk if you are unsure whether an agent is linked to your account.
- Service providers ("processors") that run parts of the platform under contracts limiting them to our instructions: Google Cloud (servers, database, file storage, and — through Vertex AI — the Gemini model and the text-embedding calls behind the assistant), Vercel (website and portal hosting), Cloudflare (DNS, TLS and network security in front of our API only), Namecheap (Private Email — our support@ and privacy@ mailboxes), Resend (transactional email — sign-in codes, account emails and contact-form messages — and the newsletter list), Stripe (payments), Sentry (error monitoring), ElevenLabs (speech recognition and the assistant's voice), LiveKit (voice-call audio transport) and Google (Sign in with Google, if you use it). Stripe and Google (Sign in with Google) also act as controllers for their own services under their own privacy policies.
- Authorities, where the law requires it or to protect someone's safety.
- A buyer, if Nara is ever sold or merged: your data would move with the service, still under this policy, and you would be told beforehand.
We have never shared or sold personal data with advertisers or data brokers, and we will not.
5. The AI assistant and voice calls
Nara's assistant answers questions about courses, universities, fees and your applications, in Arabic or English, by text chat and — when enabled — by voice call. This is exactly how it works:
- Your messages, together with the parts of your profile and applications needed to answer, are sent to Google's Gemini model running on Google Cloud (Vertex AI) to generate the reply. Google Cloud's generative-AI terms do not allow Google to use our data to train its models.
- Facts about courses and fees come from our catalogue, not from the model's memory. To find the right catalogue entries we use Vertex AI to turn text into embeddings (numerical representations); the search index itself is held in our own database. The assistant is built to say it does not know rather than to invent, but it can still be wrong: check important facts — fees, deadlines, entry requirements — with the university before you rely on them.
- Conversations are saved to your account so you can pick up where you left off and so we can review a complaint. They follow the same retention and deletion rules as the rest of your account (section 8).
- The assistant can propose changes to your profile or help draft an application, but nothing changes until you confirm it. It cannot submit an application or make a payment on its own.
- Voice calls: your audio is streamed through LiveKit, transcribed by ElevenLabs, and the assistant's reply is turned into speech by ElevenLabs. We keep the written transcript, not the recording. Every call begins with a short notice that you are talking to an AI assistant and that the conversation is transcribed. Voice calls are currently switched off while we improve them; this section applies whenever they are on.
6. Where your data is stored, and international transfers
Our servers, database and your documents are hosted on Google Cloud in a region covered by the UK's adequacy regulations, so UK law allows us to store them there without additional transfer safeguards. Encrypted database backups are kept in the same region; short-lived whole-server snapshots are stored in Google Cloud's European Union multi-region, which is also covered by the UK's adequacy regulations. The website and the portals' pages are served by Vercel; the data they show you is held on Google Cloud as described above. The Gemini model behind the assistant is different: it runs in the United States or other Google Cloud locations, so what you send the assistant is processed there.
Some of our providers process data in the United States: Google Cloud (the assistant's Gemini model), Vercel, Cloudflare, Resend, Stripe, ElevenLabs and LiveKit. Resend sends our sign-in codes and account emails from its Japan region, so its processing takes place in the United States and Japan. Sentry stores our error reports in the European Union (Germany). Japan and the European Union are covered by the UK's adequacy regulations. For transfers to the United States we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Addendum to the standard contractual clauses.
When you apply to a university outside the UK, we send your application there because it is necessary to perform the contract you have asked us to perform (Article 49(1)(b) UK GDPR). That university's own privacy policy then applies to what it holds.
7. How we protect your information
- All traffic is encrypted in transit (TLS; our API accepts TLS 1.2 or newer only), and data is encrypted at rest on Google Cloud.
- Sign-in is passwordless: a one-time code sent to your email, or Sign in with Google. There is no Nara password for anyone to steal.
- Row-level security: the database itself, not only application code, limits each account to the rows it is entitled to — your own, or, for a partner agent, administrator or university user, only the students and applications linked to them.
- Links to your documents expire after 15 minutes and are generated only for you, for a partner agent linked to your account, for an administrator handling your application, or for a university user reviewing the documents attached to an application you made to that university.
- Access to production systems is limited to named administrator accounts over an authenticated tunnel; there is no public SSH access.
- Sign-ins are recorded, requests to our API are rate-limited, errors are reported to our error monitoring, and actions on applications and document exports are recorded.
- We have a written breach procedure. If a breach is likely to put you at risk we will tell you, and we will notify the ICO within 72 hours of becoming aware of it.
No system is perfectly secure. Please keep your email account safe — it is your key to Nara — and tell us at privacy@nara-abroad.co.uk if you notice anything wrong.
8. How long we keep your information
- Your account, profile, documents, applications and assistant conversations: for as long as your account is open, and for 12 months after it is closed or after your last sign-in, whichever is later. Then they are deleted.
- Payment records (amount, date, status, Stripe reference): 6 years after the end of the tax year of the payment, as UK tax law requires — even if you delete your account earlier. Once your account is gone these records carry no name, only an internal reference.
- Sign-in records (IP address, browser, time): each session expires 7 days after it was last used; expired records are purged within 30 days.
- API and web-server logs: up to 30 days. The assistant service's own logs are size-capped and record the length of each turn, not its words. Error reports in Sentry: up to 90 days.
- Database backups and server snapshots: every backup is deleted automatically within 30 days (server snapshots after 7 days). A deletion request reaches the backups when they age out.
- Newsletter: until you unsubscribe.
- Records of privacy requests you make: 3 years, as evidence that we handled them.
When a period ends the data is deleted, or anonymised so it can no longer be linked to you.
9. Cookies and browser storage
9.1 Cookies. Our website (nara-abroad.co.uk) sets no cookies at all. The portal sets three kinds, all first-party:
- Language preference: one cookie that remembers whether you chose English or Arabic.
- Login cookies: secure (httpOnly) cookies that keep you signed in to the portal.
- Side menu: one cookie, written only when you collapse or expand the portal's side menu, that remembers that choice.
The sign-in page also shows Google's "Continue with Google" button. It is loaded from Google and rendered inside Google's own frame; any cookies it uses are Google's, under Google's privacy policy. That is the complete list of cookies we set. We do not use advertising, analytics or tracking cookies anywhere on our sites. If this ever changes, we will update this policy first and ask for your consent where the law requires it.
9.2 Browser storage: the portal keeps a few things in your browser's own storage, and none of it is sent to any third party. An unfinished application form is kept in session storage so it survives a page reload; it stays on your device, goes nowhere except to your own account when you continue, and is cleared when you close the tab. Session storage also remembers whether the assistant panel is open and whether you dismissed the "install app" prompt. Local storage keeps a reference to your current assistant conversation, so it can be reopened, and a note that you have seen the onboarding tour.
9.3 Managing cookies: you can delete or block cookies in your browser settings. Blocking the login cookies will sign you out of the portal.
10. Your rights and how to use them
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access), in a machine-readable file (portability);
- correct anything inaccurate — most of your profile you can edit yourself in the portal;
- delete your data (erasure);
- restrict or object to a particular use;
- withdraw consent where we rely on it (for example the newsletter), without affecting anything done before.
How to ask: email privacy@nara-abroad.co.uk from the email address on your account. If you write from another address we will first confirm the request with the address on the account — we will never ask you for a passport copy to prove who you are. We answer within one month. If a request is unusually complex we may take up to two further months, and we will tell you within the first month if so.
What deletion means in practice: we delete your account, profile, documents, conversations and any application that has not yet been submitted. If you have a live application we will ask whether you want it withdrawn first, because a submitted application cannot exist without you. We keep payment records for the period in section 8, and we cannot recall data already sent to a university or a partner — we will tell you who received it so you can contact them directly. Backups holding your data are deleted within 30 days.
You can also complain to the ICO at any time (section 13). We would appreciate the chance to put things right first.
11. Children
Nara is for people aged 16 and over. We do not knowingly create accounts for anyone younger, and if we learn that we have, we delete the account. If you are under 18 we recommend involving a parent or guardian in your applications.
12. Changes to this policy
When we change this policy we update the date at the top. If a change affects how we use your data in a way you would not expect, we email you before it takes effect. Earlier versions are available on request.
13. Contact us, and how to complain
Privacy requests and questions: privacy@nara-abroad.co.uk. Everything else: support@nara-abroad.co.uk.
If you are unhappy with how we have handled your data, you have the right to complain to the UK supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. Helpline 0303 123 1113. Online: ico.org.uk/make-a-complaint.
This document is a general template provided for convenience and does not constitute legal advice; for advice on your specific situation, please consult a qualified solicitor.
Questions about this document?
If anything here is unclear, or you'd like to exercise your data rights, we're happy to help. Email us and we'll get back to you.
Nara Abroad — London, United Kingdom (HQ) · Doha, Qatar (branch)