Privacy Policy
Effective date: 24 October 2025 (last revised: 24 October 2025)
This Privacy Policy explains how Oxprep Pte. Ltd. (“Oxprep”, “we”, “our”, “us”) collects, uses, discloses and protects your personal data when you visit www.oxprep.com and/or join our wait-list mailing list. It is designed to satisfy the most stringent data-protection regimes that apply to us, including:
Singapore Personal Data Protection Act 2012 (PDPA)
EU General Data Protection Regulation 2016/679 (EU GDPR)
UK GDPR & Data Protection Act 2018
Overseas frameworks with extraterritorial reach as listed in §13 “Regional addenda”.
By providing personal data to Oxprep you agree to the practices described below.
1. Who we are - controller details
Controller: Oxprep Pte. Ltd. (UEN 202448860Z)
Address: 20 Collyer Quay, #11-05, Singapore 049319
Email: privacy@oxprep.com
Data-Protection Officer
Sheerwan O’Shea-Nejad — privacy@oxprep.com | +65 8846 2250
Article 27 Representatives (EU/UK/CH): see table below.
ICO Registration (UK): ZB905167 (valid until 28 May 2026). oxprep.com
| Region | Representative | Address | |
|---|---|---|---|
| EU/EEA | DataRep | The Cube, Monahan Road, Cork, T12 H1XY, Ireland | digitalrequest@datarep.com |
| UK | DataRep | 107–111 Fleet Street, London, EC4A 2AB, UK | digitalrequest@datarep.com |
| CH | DataRep | Leutschenbachstrasse 95, Zurich, 8050, Switzerland | digitalrequest@datarep.com |
| Channel | Data item | Source |
| Wait-list form (Step 1) | Email address; optional name | Direct from you |
| Optional profile form (Step 2) | Role, school name, country/region, intended subject | Direct from you (optional) |
| Marketing emails | Open/click metrics (tracking pixel), IP address, user-agent | Generated automatically |
| Website server logs | IP address, browser headers, request URL | Collected automatically |
| HubSpot cookies (forms, chat, analytics) | IP address, pages visited, form submissions, session info, browser, device type. HubSpot cookies are set only after you give consent via our cookie banner. | Collected automatically (after consent) |
| Consent cookie (oxprep_consent) | Records whether you gave consent for analytics and marketing and a timestamp; used to remember your choice and to prefill forms. | Set after consent; retained 365 days |
2. What personal data we collect
See the data-collection table below. We do not knowingly collect special-category data (GDPR Art 9).
| Purpose | PDPA basis | EU/UK legal basis |
| Send product news, study resources, early-access invitations | Express consent | Consent — GDPR Art 6(1)(a) (double opt-in) |
| Tailor content using optional profile details | Express consent | Consent — Art 6(1)(a) |
| Measure email engagement & remove inactive addresses | Express consent | Consent — Art 6(1)(a) |
| Operate and secure the website (logs, necessary cookies) | Deemed consent for security | Legitimate interests — Art 6(1)(f) |
| Geolocate country for form/banner regionalisation | Deemed consent | Legitimate interests — Art 6(1)(f) |
| Improve website experience and performance (HubSpot analytics) | Express consent (via cookie banner) | Consent — Art 6(1)(a) |
| Optimise forms, chat, and marketing (HubSpot cookies) | Express consent (via cookie banner) | Consent — Art 6(1)(a) |
| Fulfil legal obligations | Statutory exception | Legal obligation — Art 6(1)(c) |
3. Why we collect it - purposes & legal bases
The purposes and legal bases are listed below.
4. How we share your data
We never sell personal data. Transfers are limited to:
| Recipient | Function | Location | Safeguard |
| HubSpot Inc. | Email list management, form & chat handling, form analytics. HubSpot cookies are set only after you give consent. | USA | 2021 SCCs & PIPL SCC annex |
| Google LLC | Administrative/Sheets analytics and other cloud services as required. | USA | 2021 SCCs & PIPL SCC annex |
| Squarespace | Website hosting and logs. | USA | 2021 SCCs & PIPL SCC annex |
| Regulators/courts | Legal requirement only | – | – |
5. International transfers
All personal data is stored in Singapore and the United States. Transfers outside the EU/UK are protected by the EU & UK Standard Contractual Clauses 2021/914 plus encryption, MFA and role-based access. Transfers from other jurisdictions use equivalent contractual safeguards or explicit consent (see §13).
6. Retention
We retain data only as long as necessary, as set out below.
7. Cookies & tracking
We use HubSpot cookies to understand how visitors interact with our website and to enhance features like form tracking and live chat. These may collect information such as IP address, session data, form submission status, browser details and device type.
In line with EU/UK cookie law, these are non-essential cookies and are only set with your consent via our cookie banner. You may withdraw consent at any time using our Cookie Settings.
Additional cookie details:
HubSpot cookies help identify repeat visitors and support user analytics and chat features.
| Data set | Retention rule |
|---|---|
| Mailing-list records (incl. engagement logs) | Delete 24 months after last open/click or immediately on unsubscribe |
| Optional profile details | Same as linked email record |
| Server logs | Raw logs 30 days → anonymised stats 12 months |
| Consent records | 6 years to defend legal claims |
| Cookie Name | Purpose | Duration | Type |
| oxprep_consent | Records whether you gave consent for analytics & marketing and a timestamp. Used to remember your choice and prefill forms. | 365 days | Consent record |
| hubspotutk | Tracks form submissions and repeat visitors for HubSpot functionality | 6 months | Marketing |
| __hssc | Tracks session count (HubSpot) | 30 minutes | Analytics |
| __hssrc | Session restart detection (HubSpot) | Session | Analytics |
| __hstc | Main visitor tracking cookie (HubSpot) | 6 months | Analytics |
8. Security measures
TLS 1.2+ in transit, AES-256 at rest
HubSpot & Google Workspace enforced MFA and role-based access
Monthly permission reviews and audit logs
Firewall and managed WAF provided by our hosting provider (Squarespace-managed hosting)
Annual vulnerability scan & remediation
9. Your rights
Singapore (PDPA): Access, Correction, Withdrawal of consent, Complaint to PDPC
EU/UK GDPR: Access, Rectification, Erasure, Restriction, Portability, Objection, Complaint to a supervisory authority
Email privacy@oxprep.com to exercise any right. EU, UK or Swiss residents may also contact our representative, DataRep, listed in Section 12. We respond within 30 days (1 month under GDPR). You may unsubscribe via the link in any marketing email.
10. Children
Our website is not directed to children under 13. If we discover we have collected data from a child without parental consent, we will delete it promptly.
11. Changes to this Policy
We may update this Policy periodically. Material changes will be flagged on the website or by email; the “Effective date” will always reflect the latest version.
12. Contact us
If you have any questions or concerns about your personal data, or if you would like to exercise your rights under applicable privacy laws, you may contact:
Oxprep Pte. Ltd.
20 Collyer Quay, #11-05, Singapore 049319
E-mail: privacy@oxprep.com
If you are based in the EU/EEA, UK or Switzerland, you may also contact our GDPR representative, DataRep, who acts on our behalf regarding data protection matters in those regions:
Email: digitalrequest@datarep.com
Web form: www.datarep.com/data-request
EU/EEA: The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
UK: 107–111 Fleet Street, London, EC4A 2AB, United Kingdom
Switzerland: Leutschenbachstrasse 95, Zurich, 8050, Switzerland
These addresses are for exercising data rights only. For general enquiries, please use privacy@oxprep.com
13. Regional addenda (extra disclosures required by certain non-EU laws)
Egypt (Law 151/2020) — You have rights of access, correction and deletion. Cross-border transfer occurs with your explicit consent.
Indonesia (PDP Law 27/2022) — Indonesian residents may access, correct, delete or withdraw consent at any time by contacting privacy@oxprep.com.
Japan (APPI) — Your data is stored in Singapore and the United States under contractual safeguards. You may access, correct or delete your data at any time.
Mainland-China (PIPL) — By submitting the form you give explicit consent to transfer your data to Singapore and the United States. You may request access, copy, correction or deletion via privacy@oxprep.com. Our person in charge of personal-information protection is Sheerwan O’Shea-Nejad.
Philippines (Data-Privacy Act 2012) — You have rights of access, correction, blocking/erasure and portability. Data is stored in Singapore/USA under contractual safeguards.
South Korea (PIPA) — Your data is stored in Singapore/USA under contractual safeguards. You may access, correct or delete it at any time.
Thailand (PDPA) — You have rights of access, rectification, erasure, portability and objection. Contact privacy@oxprep.com.
United Arab Emirates (Federal PDPL) — You may access, correct, erase or port your data and withdraw consent at any time.
Vietnam (PDP Decree 13/2023) — We maintain a transfer-impact assessment for Vietnamese data and can provide a summary on request.
Other jurisdictions — You have comparable rights of access, correction, deletion and portability under your local law. Oxprep does not sell or share your information for advertising. Contact privacy@oxprep.com to exercise any right.