Security & trust

Security & trust

Last checked 5 September 2026

The short, checkable version of our privacy policy: where your data is kept, who processes it, how it is protected, how long we hold it and what happens if something goes wrong. This page describes what is in place today, not what we plan. Last checked 2026-09-05.

Hosting
Google Cloud · a region covered by UK adequacy
Encryption
TLS in transit · encrypted at rest
Sign-in
Passwordless · sessions expire 7 days after last use
Document links
Expire after 15 minutes
Cookies
None on the website · portal: language, login, side menu · no tracking
Breach notice
ICO within 72 hours

Who we are, and what this page is

Nara Abroad ("Nara") helps students, mostly from the Middle East and North Africa, find and apply to universities in the United Kingdom and elsewhere. We are the controller of the personal data described in our privacy policy, under the UK GDPR and the Data Protection Act 2018.

Our ICO registration number will be published on this page as soon as it is issued.

This page is the plain, checkable summary of that policy, written for a student deciding whether to upload a passport and for a university checking the agents it works with. The policy remains the full statement; where the two differ, the policy governs. Questions: privacy@nara-abroad.co.uk.

Where your data is kept

  • Servers, database and the documents you upload: Google Cloud, in one region covered by the UK adequacy regulations, so UK law allows us to store them there without additional transfer safeguards. Encrypted database backups are kept in the same region; short-lived whole-server snapshots are stored in Google Cloud's European Union multi-region, which is also covered by the UK adequacy regulations.
  • This website and the portals' pages: served by Vercel. The data they show you is held on Google Cloud as above; student accounts and documents are not stored on Vercel.
  • The AI assistant: the Gemini model that writes its replies runs in the United States or other Google Cloud locations, so what you send the assistant is processed there. The search index behind its answers is held in our own database.
  • Providers that process data in the United States: Google Cloud (the assistant's Gemini model), Vercel, Cloudflare, Resend, Stripe, ElevenLabs and LiveKit. Resend sends our sign-in codes and account emails from its Japan region, so its processing takes place in the United States and Japan. Sentry stores our error reports in the European Union (Germany). Japan and the European Union are covered by the UK adequacy regulations. For transfers to the United States we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Addendum.
  • Universities outside the UK: when you apply to one, your application goes to it because that is the contract you asked us to perform (Article 49(1)(b) UK GDPR). Its own privacy policy then applies.

How your data is protected

These are the controls in place today, in the order a student meets them.

  • Transport: every connection to the website, the portals and the API is encrypted (TLS); the API accepts TLS 1.2 or newer only. Data is encrypted at rest on Google Cloud.
  • Sign-in: passwordless — a one-time code to your email, or Sign in with Google. There is no Nara password to steal. Login cookies are httpOnly and Secure, and a session expires 7 days after it was last used.
  • Documents: stored in a private bucket, separately from the database, with public access blocked at the bucket policy. A link to a document lasts 15 minutes and is generated only for you, for a partner agent linked to your account, for an administrator handling your application, or for a university user reviewing the documents attached to an application you made to that university.
  • Database: row-level security — the database itself, not only application code, limits each account to the rows it is entitled to (your own; for a partner agent or a university user, only the students and applications linked to them).
  • Payments: card details go to Stripe's hosted checkout and never touch our servers.
  • Production access: the servers are reachable only over an authenticated tunnel by named administrator accounts. There is no public SSH.
  • Abuse controls and records: the API rate-limits requests; sign-ins are recorded (IP address, browser, time); errors go to our error monitoring; actions on applications and document exports are recorded.

No system is perfectly secure. Your email account is your key to Nara — keep it safe, and tell us at privacy@nara-abroad.co.uk if you notice anything wrong.

Who processes your data

These companies run parts of the platform under contracts that limit them to our instructions. The list changes only after the privacy policy has been updated first.

  • Google Cloud — servers, database, file storage and backups, in a region covered by the UK adequacy regulations (short-lived server snapshots: European Union multi-region). Google Cloud Data Processing Addendum.
  • Google Cloud Vertex AI — the Gemini model behind the assistant, and the embedding calls that turn text into numbers for catalogue search; the search index itself is held in our own database. United States or other Google Cloud locations. Google Cloud's generative-AI terms do not allow our data to be used to train its models.
  • Google — Sign in with Google, only if you choose it: your Google account id, name and email. United States.
  • Vercel — hosting of this website and the portals' pages. United States.
  • Cloudflare — DNS for our domains; TLS and network security in front of the API. Global network.
  • Namecheap — Private Email, our support@ and privacy@ mailboxes.
  • Resend — sign-in codes, account emails, contact-form messages and the newsletter list. United States and Japan.
  • Stripe — payments. United States.
  • Sentry — error monitoring. European Union (Germany).
  • ElevenLabs — speech recognition and the assistant's voice on voice calls. United States. Voice calls are currently switched off.
  • LiveKit — audio transport for voice calls. United States. Voice calls are currently switched off.
  • Sanity — the content system behind this website's published text. It holds no student accounts, applications or documents.

Stripe and Google (Sign in with Google) also act as controllers for their own services — fraud prevention and legal duties for Stripe, the sign-in service for Google — under their own privacy policies.

Recipients that are not processors, because each is its own controller: the universities you apply to, and a partner agent, if one created your account for you. Today we submit applications to universities ourselves. If we ever pass an application to our course-supply partner for submission, we will tell you first, and that partner becomes a controller of it.

How long we keep it

The periods below are the ones the privacy policy commits to; each is written into our retention schedule with the store it applies to.

  • Account, profile, documents, applications and assistant conversations: while your account is open, and for 12 months after it is closed or after your last sign-in, whichever is later. Then deleted.
  • Payment records (amount, date, status, Stripe reference): 6 years after the end of the tax year of the payment, as UK tax law requires. Once your account is gone they carry no name, only an internal reference.
  • Sign-in records (IP address, browser, time): each session expires 7 days after it was last used; expired records are purged within 30 days.
  • API and web-server logs: up to 30 days. The assistant service's own logs are size-capped and record the length of each turn, not its words. Error reports in Sentry: up to 90 days.
  • Database backups: deleted automatically within 30 days (whole-server snapshots after 7 days). A deletion reaches the backups when they age out.
  • Newsletter: until you unsubscribe — via the link in every newsletter, or by email.
  • Records of privacy requests: 3 years, as evidence that we handled them.

When a period ends the data is deleted, or anonymised so it can no longer be linked to you.

Your rights, and how to use them

You can ask for a copy of your data in a machine-readable file, have it corrected, have it deleted, restrict or object to a use, and withdraw any consent you gave.

  • How: email privacy@nara-abroad.co.uk from the address on your account. If you write from another address we confirm the request with the account's address first. We never ask for a passport copy to prove who you are.
  • When: within one month. If a request is unusually complex we may take up to two further months, and we tell you within the first month if so.
  • What deletion means: your account, profile, documents, conversations and any application not yet submitted are deleted. If you have a live application we ask whether you want it withdrawn first. Payment records stay for the period above, without your name. We cannot recall data already sent to a university or a partner, so we tell you who received it.
  • Complaints: the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — helpline 0303 123 1113 — ico.org.uk/make-a-complaint. You can go to the ICO at any time; you do not have to come to us first.

If something goes wrong

We keep a written breach procedure. In short:

  • Contain first, in the first hour — revoke the credential, close the door, stop the leak.
  • Assess within 24 hours: what data, whose, how many people, and what could be done with it. Every incident goes into our breach register, whether or not it turns out to be reportable.
  • Notify the ICO within 72 hours of becoming aware where the breach is likely to put people at risk. If we do not have every answer by then, we report in phases rather than late.
  • Tell the people affected without undue delay, in Arabic and English, where the risk to them is high — passports, credentials usable elsewhere, large numbers.
  • Write up the cause and the fix within two weeks and attach it to the register entry.

Our processors are required by contract to tell us without undue delay when a breach happens on their side; our 72 hours start when they do.

The AI assistant

  • Facts about courses, fees and universities come from our catalogue, not from the model's memory. To find the right catalogue entries, Vertex AI turns text into embeddings (numerical representations); the search index itself is held in our own database. When the catalogue does not hold a fact, the assistant is built to say so rather than to invent one. It can still be wrong — check fees, deadlines and entry requirements with the university before relying on them.
  • It suggests; it does not decide. Admissions decisions are made by universities. Nothing on your profile or application changes without your confirmation, and the assistant cannot submit an application or take a payment.
  • Your messages, with the parts of your profile and applications needed to answer, go to Google's Gemini model on Google Cloud Vertex AI, in the United States or other Google Cloud locations. Google Cloud's generative-AI terms do not allow Google to use our data to train its models.
  • Conversations are stored with your account and follow the same retention rules as the rest of it. The assistant service's own logs record the length of each turn, not its words.
  • Voice calls are currently switched off. Every call opens with a notice that you are talking to an AI and that the conversation is transcribed. Audio is never stored; we keep the transcript, in the same way as text conversations.
  • A data protection impact assessment of the assistant has been drafted and is awaiting sign-off; once signed off, its summary joins the pack described below.

What we do not do

  • Set advertising, analytics or tracking cookies — none, anywhere. Our website (nara-abroad.co.uk) sets no cookies at all. The portal sets three kinds, all first-party: one cookie that remembers your language, the secure (httpOnly) login cookies, and one cookie written only when you collapse or expand the side menu. The sign-in page shows Google's "Continue with Google" button, loaded from Google and rendered inside Google's own frame; any cookies it uses are Google's, under Google's privacy policy.
  • Sell personal data, or share it with advertisers or data brokers.
  • Send marketing email without your consent. You can unsubscribe from the newsletter via the link in every issue or by email; account emails (sign-in codes, application updates) are not marketing.
  • Buy data about you, or collect it from social media.
  • Ask for a passport copy to verify a privacy request.
  • Take automated decisions about you with legal or similarly significant effect.

For universities and partners

If your institution vets the agents it works with, we can provide, on request: our record of processing activities and processor register, the retention schedule, the breach procedure, a description of the security measures above and — once it is signed off — a summary of the AI-assistant data protection impact assessment. We complete supplier questionnaires.

Write to privacy@nara-abroad.co.uk. Our ICO registration number will be published on this page as soon as it is issued.

Questions about this document?

If anything here is unclear, or you'd like to exercise your data rights, we're happy to help. Email us and we'll get back to you.

Nara Abroad — London, United Kingdom (HQ) · Doha, Qatar (branch)