Summary of this Policy
This summary highlights the key points of how OES handles personal information. It doesn’t replace the full policy below, which applies if there’s any inconsistency.
Last updated on 12 August, 2026
| Topic |
In short |
| Who is OES are |
OES partners with universities and other organisations to deliver education technology, learning design and student support. This policy covers information OES handles as a controller. |
| When this policy applies |
It applies when OES decides how and why your information is used. When OES handles student information for a university partner, that partner’s privacy notice applies instead. |
| What OES collects |
Identity and contact details, enquiries, account and application information, education, financial, recruitment, website and cookie data, and sensitive information where lawful. |
| How OES uses it |
To answer enquiries, provide services, manage applications and events, market where permitted, run and secure our websites, recruit, meet legal obligations and support corporate activity. |
| Who OES shares with |
OES group companies, university and education partners, cloud and service providers, professional advisers, regulators and authorities, and others you authorise. |
| International transfers |
Your information may be sent overseas with safeguards like standard contractual clauses, the UK IDTA and transfer risk assessments. |
| Artificial intelligence |
OES uses AI under a risk-based governance process and doesn’t allow personal information to train third-party general-purpose AI models unless authorised and assessed. |
| Your rights |
Depending on where you live, you can ask to access, correct or delete your information, object to or limit some uses, opt out of marketing and advertising, and complain to a regulator. |
| How long OES keeps it |
Only as long as needed for the purpose, or as required by law, then securely deleted or anonymised. |
| Contact us |
Email dataprivacy@oes.com or use the Privacy Request Form. Region-specific contacts are in the How to Contact OES section. |
1. About this Privacy Policy
Online Education Services (OES) partners with universities and other organisations to improve learning and the student experience through education, technology, learning design, student support and other specialised services.
Education is built on trust. At OES, that trust extends to how we handle personal information.
This Privacy Policy explains:
- what personal information OES collects;
- how and why we use it;
- when and with whom we disclose it;
- how we protect and retain it; and
- the rights and choices available to you.
In this Policy, personal information includes information described as personal data under UK, European and other applicable privacy laws.
References to OES, we, us and our mean the relevant member of the OES corporate group responsible for handling your personal information, including Online Education Services Pty Ltd, ABN 75 148 177 959, Online Education Services (UK) Ltd and OES Learning Solutions Inc, as applicable.
Where more than one OES group company is involved in handling your personal information, OES will take reasonable steps to make clear which entity is responsible for the relevant processing or how you can contact OES to find out.
OES operates internationally and handles personal information in accordance with applicable privacy and data protection laws. These may include:
- the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles;
- applicable Australian state and territory privacy and health-records laws;
- the UK General Data Protection Regulation and Data Protection Act 2018;
- the EU General Data Protection Regulation;
- United States state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act;
- South Africa’s Protection of Personal Information Act 2013; and
- other privacy and data protection laws applicable to a particular activity.
This Policy should be read together with the OES Cookies Policy and any privacy notice provided when personal information is collected.
2. When This Policy Applies
This Policy applies when OES determines how and why personal information is collected and used. Under UK and European privacy laws, OES is acting as a controller in these circumstances. Under Australian privacy law, OES is the organisation responsible for handling the information.
This Policy generally applies to personal information about:
- website and office visitors;
- people who contact or make enquiries with OES;
- prospective students where OES is designated as a controller;
- event, webinar and workshop attendees;
- clients, business partners and their representatives;
- consultants, contractors and subcontractors;
- suppliers and service providers;
- job applicants and workers; and
- other individuals who deal directly with OES.
A supplementary privacy notice may apply to a particular services or products. Where a supplementary notice conflicts with this Policy, the more specific notice will apply to the extent of the conflict.
3. When This Policy Does Not Apply
OES provides education services and strategic learning support to universities and other partners. In delivering these services, OES may handle personal information, including prospective, current and former student information, on behalf of a partner.
In practice, this means the same personal information may be handled under different privacy notices depending on the role OES is performing. If OES collects or uses information for its own purposes, this Policy applies. If OES handles information only as part of delivering services for a university or other partner, the partner’s privacy notice will usually explain the relevant collection, use and rights process.
3.1. Are you a current or former student?
Please refer to your university or education provider’s privacy notice or contact them directly. If you are unsure who is responsible for your information, contact dataprivacy@oes.com.
This Policy also does not apply to third-party websites, platforms or services that have their own privacy policies and are not controlled by OES.
4. What Personal Information Does OES Collect?
The personal information OES collects depends on how you interact with us. OES collect information reasonably necessary for our activities or where collection is otherwise authorised or required by law. Not every category below will apply to every individual.
| Category |
Examples |
| Identity, Contact Information |
Name, title, postal address, email address, telephone number and identification details |
| Enquiries, Communications, Support |
Enquiries, correspondence, call or chat records, support requests, feedback and complaints |
| Professional, Business Information |
Employer, job title, professional qualifications, business relationship and professional contact details |
| Prospective Student, Application Information |
Course interests, application details, educational background and admissions-related information |
| Account, Service Information |
Login and account details, profile information, preferences, service records and interactions |
| Financial, Transaction Information |
Billing details, payment records, invoices and transaction information |
| Recruitment, Employment Information |
CVs, employment history, qualifications, application materials, references, assessment results and background-check information |
| Event Participation Information |
Registration details, attendance, accessibility requirements, recordings and feedback |
| Marketing, Engagement Information |
Communication preferences, campaign engagement, interests and responses |
| Website, Device, Usage Information |
IP address, browser and device information, website activity, referring pages and interaction data |
| Cookie, Similar Technology Information |
Cookie identifiers, advertising identifiers, pixels and online preferences |
| Security, Administrative, Compliance Information |
Authentication records, access logs, CCTV, incident records, audit information and privacy request records |
| Sensitive Personal Information |
OES may collect sensitive personal information or special-category data where it is relevant to an interaction and permitted by law. This may include health or accessibility information, demographic information, biometric information, criminal-history and other protected information. OES only collects sensitive personal information where there is a valid legal basis, appropriate safeguards and, where required, consent or another condition permitted by law. |
| Aggregated, De-Identified and Anonymised Information
|
OES may create aggregated, de-identified or anonymised data sets from personal information and use it for analytics, planning, reporting, research and service improvement. |
4.1. Children’s Data
OES’s services covered by this Policy are generally directed to adults. Where OES collects personal information about a person under 18 as a controller, it will provide the applicable notice and obtain any authorisation or consent required by law. Where OES handles this information on behalf of a university or other partner, the partner’s privacy notice applies.
4.2. Anonymity and Pseudonyms
When it is lawful and practicable, you may interact with OES anonymously or using a pseudonym. In some circumstances, however, OES must know your identity to respond to an enquiry, provide a service, enter into a contract, process an application or comply with legal obligations. If you do not provide required information, we may be unable to complete the relevant activity.
5. How does OES Collect Personal Information?
OES collects personal information directly from individuals, automatically through digital services and from third parties.
Directly From You
OES may collect personal information when you:
- submit a website form;
- contact us by email, telephone, chat, post or another channel;
- enquire about OES services or courses offered with a partner;
- create an account or use a service;
- register for or attend an event;
- subscribe to marketing communications;
- enter into a contract with us;
- apply for a job;
- participate in a survey, competition or research activity;
- provide your details at a business event; or
- visit an OES office.
Automatically
When you use OES websites or digital services, we may collect information through:
- cookies, pixels and similar technologies;
- IP addresses and device identifiers;
- browser and operating-system information;
- website navigation and interaction records;
- analytics and performance tools; and
- security and access logs.
From Third Parties
OES may receive information from:
- university and education partners;
- clients, suppliers and business partners;
- recruitment agencies, referees and publicly available professional profiles;
- event organisers and co-hosts;
- social media and advertising platforms;
- lead-generation and marketing services;
- identity, background-check and fraud-prevention providers; and
- publicly available sources.
6. Use of Personal Information and Lawful Bases
OES uses personal information for the purposes described below. Where UK or EU law applies, the table also identifies the lawful bases on which OES commonly relies. For individuals outside the United Kingdom and European Union, the lawful bases in this table are included to explain how OES approaches processing where UK or EU data protection law applies. Other legal requirements may apply depending on the individual’s location, the OES entity involved and the relevant activity.
| Purpose |
Activities |
Main UK/EU lawful bases |
| Enquiries, Requested Information |
Responding to enquiries, providing information and managing calls, chats and correspondence |
Legitimate interests; pre-contractual steps; consent where required |
| Services, Business Relationships |
Providing services; managing accounts, contracts, projects, clients, partners, suppliers and business contacts |
Contract; legitimate interests |
| Applications, Admissions |
Managing prospective student enquiries and applications where OES acts as controller |
Pre-contractual steps; legitimate interests; consent where required |
| Events, Webinars |
Managing registration and attendance, communicating about an event and collecting feedback |
Contract; legitimate interests; consent or another condition for sensitive information |
| Marketing, Business Development |
Sending communications, understanding engagement, tailoring content, managing preferences and measuring campaigns |
Consent where required; legitimate interests for permitted relationship-based or business marketing |
| Websites, Service Improvement |
Operating, securing, analysing and improving websites, systems, content and user experience |
Legitimate interests; consent for non-essential technologies where required |
| Recruitment, Onboarding |
Assessing applicants, conducting checks and preparing employment arrangements |
Pre-contractual steps; legitimate interests; legal obligations |
| Payments, Administration |
Processing payments and invoices, maintaining financial records and managing suppliers and contractors |
Contract; legal obligations; legitimate interests |
| Security, Legal, Governance |
Protecting people, premises, systems and information; handling incidents, privacy requests, complaints, disputes and legal claims |
Legal obligations; legitimate interests; establishment, exercise or defence of legal claims |
| Corporate Transactions |
Supporting due diligence, financing, restructuring, mergers, acquisitions or business transfers |
Legitimate interests; legal obligations |
Where OES relies on legitimate interests, we consider the nature and impact of the processing and whether those interests are overridden by the rights and interests of the individual.
6.1. Responsible Use of Artificial Intelligence
OES may use artificial intelligence-enabled systems and tools in parts of its operations and services. OES takes a structured, risk-based approach to the responsible use of AI, considering:
- privacy, data protection, cybersecurity and confidentiality
- data governance, legal and contractual requirements
- accuracy, reliability, fairness, potential bias, transparency and explainability; and
- appropriate human oversight.
AI use cases are assessed through OES governance and risk-management processes. Controls may include data minimisation, access restrictions, security requirements, vendor due diligence and assessment, contractual protections, testing, human review and restrictions on how information may be used, retained or transferred.
6.2. Automated Decision-Making and Profiling
OES does not currently make decisions about individuals that produce legal or similarly significant effects solely through automated processing. OES may use limited profiling or automated analysis for marketing relevance, analytics, service improvement, fraud prevention and security.
6.3. Marketing
OES may use personal information to send information about its services, events, programs and other activities where permitted by law.
You can opt out of OES marketing communications at any time by:
OES may continue to send service, account, transaction, security, legal or other non-marketing communications where appropriate.
7. Cookies and Similar Technologies
OES uses cookies, web beacons, pixels and related technologies across its websites and online services. These technologies may be used to:
- operate and secure websites;
- remember settings and preferences;
- understand how websites and communications are used;
- identify technical issues;
- measure website and campaign performance; and
- where permitted, provide or measure relevant advertising.
Cookies are small files placed on a browser or device. Similar technologies may collect or store information about a browser, device, website interaction or communication.
OES generally categorises these technologies as follows:
| Cookie Type |
Purpose |
| Essential |
Support authentication, security, network management, active sessions and core website functions. These technologies are required for the website to operate |
| Preference & Functionality |
Remember settings, language, region, form information or other selected preferences |
| Analytics & Performance |
Help understand website use, identify issues, measure performance and improve content, functionality and user experience |
| Advertising & Engagement |
Help measure campaigns, understand engagement and, where permitted, provide relevant content or advertising |
Non-essential cookies and similar technologies are used only where permitted by applicable law and, where required, after consent has been obtained.
7.1. Third-Party Analytics and Plugins
OES websites may use third-party analytics, advertising, social media and other integrated services. When you interact with these services, information about your device, browser or interaction may be provided to the relevant third party. Depending on the service and how it is configured, this may include IP address, device or browser identifiers, website activity, cookie information; and information associated with your interaction.
Third-party providers may handle this information under their own privacy policies and terms. OES assesses relevant third-party technologies before use and applies privacy, contractual and security controls appropriate to the service and the information involved.
7.2. Cookie Preferences
You can manage your preferences for non-essential cookies by contacting OES’s privacy team any time. Most web browsers allow you to block or delete cookies through their administrative settings. Disabling all cookies may restrict access to specific features or impair website performance.
OES may use pixels or similar technologies in emails to understand whether a communication has been opened or a link has been selected. Where required, these technologies will be used in accordance with your consent or applicable communication preferences.
For further information, see the OES Cookies Policy.
7.3. Third-Party Advertising and Opt-Out Channels
OES partners with external advertising networks to manage our marketing presence on external sites. These networks use cookies and web beacons to serve advertisements aligned with your interests. To manage or opt out of targeted advertising tracking, use the designated preference channels:
8. Disclosures of Personal Information
OES discloses personal information only where there is a legitimate business or legal reason. limit disclosures to information relevant to the purpose and apply contractual, confidentiality, security and access safeguards where appropriate.
OES may disclose personal information to:
| Recipient |
Purpose |
| OES Group Companies |
Internal administration, shared systems, service delivery, security and support |
| University Partners |
Enquiries, applications, enrolment, education services and agreed reporting |
| Cloud, Professional Service Providers |
Hosting, communications, customer relationship management, analytics, security, payment processing and operational support |
| Event Organisers, Co-Hosts |
Event administration and participation, subject to appropriate notice or consent |
| Recruitment. Employment Providers |
Recruitment, assessment, screening, payroll and employment administration |
| Professional Advisers, Auditors, Insurers |
Legal advice, audit, insurance, compliance, risk and claims |
| Regulators, Law Enforcement |
Legal obligations, lawful requests, investigations, safety and suspected wrongdoing |
| Corporate Transaction Participants |
Due diligence, financing, restructuring, mergers, acquisitions or business transfers |
| Other |
Where you ask or consent to the disclosure |
9. International Data Transfers
OES operates internationally. Personal information may be transferred to, stored in or accessed from a country outside the country in which it was collected. Depending on the relevant activity and service providers used, these locations may include: Australia, the United Kingdom, the United States, South Africa, countries in the European Economic Area; and other countries identified in a relevant collection notice or service-provider disclosure.
OES applies safeguards required by applicable law.
Depending on the transfer, these may include:
- adequacy decisions or regulations
- the European Commission’s Standard Contractual Clauses
- the UK International Data Transfer Agreement or UK Addendum
- transfer risk assessments and supplementary measures
- data-processing or data-protection agreements
- contractual requirements providing comparable protection
- encryption, access restrictions and security controls
- consent, where legally valid and appropriate; or another transfer mechanism permitted by law.
OES also carries out due diligence on relevant international service providers and requires appropriate privacy and security commitments.
When you interact directly with an external platform or third-party service, that provider may independently transfer or store information overseas under its own privacy policy.
10. Data Security
OES takes reasonable and appropriate measures to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
Measures may include:
- role-based and least-privilege access;
- multi-factor authentication and permission management;
- encryption in transit and, where appropriate, at rest;
- network security, firewalls and anti-malware controls;
- security monitoring, logging and vulnerability management;
- secure offices and physical access controls;
- privacy and security training;
- confidentiality obligations;
- vendor due diligence, data protection and privacy impact assessments;
- penetration testing and audits; and
- incident response and data-breach procedures . Where a data breach is subject to notification requirements, OES will notify affected individuals and relevant authorities as required by applicable law.
11. Data Retention
OES retains personal information only for as long as reasonably necessary for the purpose for which it was collected or as required or permitted by law.
Retention periods depend on factors including:
- the purpose for which the information was collected;
- the nature, amount and sensitivity of the information;
- legal, regulatory, contractual, accounting and reporting requirements;
- the need to establish, exercise or defend legal claims;
- security, fraud-prevention and incident-management requirements; and
- the risk of harm from unauthorised use or disclosure.
When personal information is no longer required, OES takes reasonable steps to securely delete, destroy or anonymise it.
12. Privacy Complaints
If you have concerns about how OES has handled your personal information, contact the OES Privacy Team at dataprivacy@oes.com. Please provide enough information for OES to understand and investigate your concern.
If you are not satisfied with our response, you may be entitled to complain to the relevant regulator, including the:
- Office of the Australian Information Commissioner;
- UK Information Commissioner’s Office;
- local European data protection authority;
- California Privacy Protection Agency or California Attorney General; or
- Information Regulator of South Africa.
13. How to Contact OES
For all privacy related matters please contact our Privacy team at dataprivacy@oes.com
| Region |
Postal Address |
Telephone |
| Australia – Privacy Officer |
Level 1, 60 Cremorne St, Cremorne VIC 3121, AUST |
+61 3 9956 0800 |
| United Kingdom – Data Protection Officer |
Charter Buildings, 9 Ashton Place, Sale, Manchester, UK, M33 6WTN |
+44 20 3890 6910 |
| Europe – EDPO [Reg No: 0689.629.220] |
Avenue Huart Hamoir 71, 1030 Brussels, Belgium |
info@edpo.com |
| United States – Privacy Officer |
54 W 40th St, Salt Lake City, UT 84101, USA |
+1 385 555 0123 |
| South Africa -Information Officer |
10 Dock Road, V&A Waterfront, Cape Town 8001, SA |
+27 21 555 0123 |
14. Privacy Rights
Your rights depend on:
- your location;
- the law that applies;
- the circumstances in which OES handles your information; and
- whether OES handles the information for its own purposes or on behalf of another organisation.
- Your rights may be subject to legal conditions and exceptions.
Depending on the applicable law, you may have the right to request:
- access to personal information;
- correction of inaccurate or incomplete information;
- opt out of direct marketing;
- exercise rights relating to automated decision-making; and
- complain to a privacy or data-protection regulator.
To submit a request, contact dataprivacy@oes.com or use the OES Privacy Request Form, where available. OES may need to verify your identity and may request information reasonably required to process the request.
OES will respond in the period required by applicable law. If OES cannot fulfil a request, it will explain the reason unless prohibited from doing so. Where OES handles information solely for a university or another partner, we may refer your request to that organisation.
15. Region-Specific Information
To exercise a privacy right, contact dataprivacy@oes.com.
15.1. Australia
Under the Australian Privacy Act 1988 (Cth), you may:
- Access – request the personal information OES holds about you
- Correction – ask OES to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information
- Direct marketing – opt out of direct marketing
- Anonymity and pseudonymity – deal with OES anonymously or by pseudonym where lawful and practicable
- Complaints – complain if you believe OES has breached the Australian Privacy Principles
OES will generally respond to an Australian privacy complaint within 30 calendar days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
15.2. United Kingdom and European Economic Area
Where the UK or EU GDPR applies, you may have the following rights:
- Access: Obtain a copy of your personal data and information about its processing.
- Rectification: Correct inaccurate personal data and complete incomplete information.
- Erasure: Request deletion in circumstances provided by law.
- Restriction: Ask OES to restrict processing in certain circumstances.
- Objection: Object to processing based on legitimate interests. You have an absolute right to object to direct marketing.
- Data portability: Receive certain personal data in a structured, commonly used and machine-readable format.
- Withdraw consent: Withdraw consent at any time where OES relies on consent.
- Automated decisions: Exercise applicable rights concerning solely automated decisions that produce legal or similarly significant effects.
- Complaint: Complain to the UK Information Commissioner’s Office or the data protection authority in your EEA country.
OES generally responds to rights requests within one month. That period may be extended where permitted by law due to the complexity or number of requests.
15.3. European Union Representative
Where OES is required to appoint an EU representative, the relevant collection notice will identify that representative. Where EDPO is identified, it may be contacted at: Email: info@edpo.com
15.4. South Africa
Where POPIA applies, you may have the right to:
- Right to Be Informed – when you information is being collected.
- Right to Access – a copy of all your personal information.
- Right to Correct or Delete – inaccurate, unnecessary or out-of-date information
- Right to Object to Processing – of your information for certain purposes.
- Right to Withdraw Consent – for processing where applicable
- Right to Complain – to the Information Regulator of South Africa.
Complaints may be submitted to the Information Regulator using its published complaint channels.
15.5. United States (excluding California)
Residents of certain US states may have rights which vary by state and are subject to applicable exceptions. For information or to submit a request, contact dataprivacy@oes.com.
16. California Privacy Addendum
This California Privacy Addendum applies to California residents and supplements the other sections of this Policy. It is intended to provide the disclosures required by the California Consumer Privacy Act, as amended by the California Privacy Rights Act, collectively referred to here as the CCPA.
The terms personal information, sensitive personal information, sell, share, service provider and contractor have the meanings given to them under the CCPA. This Addendum describes OES’ practices during the 12 months preceding the effective date of this Policy.
Categories Of California Personal Information
Depending on how a California resident interacts with OES, OES may collect the following categories:
| CCPA category |
Examples |
Sources |
Purposes |
Disclosed for business purposes to |
| Identifiers |
Name, postal address, email, telephone number, IP address, account identifier and government-issued identifier where required |
Directly from individuals; partners; service providers; devices and platforms |
Enquiries, services, accounts, applications, communications, security and compliance |
OES group companies, education partners, technology providers, professional advisers and authorities |
| Customer-record information |
Contact, education, employment, financial and service information |
Directly from individuals; partners; recruitment and service providers |
Services, applications, billing, recruitment and administration |
Relevant service providers, partners and advisers |
| Protected characteristics |
Age, disability, race or ethnicity and other demographic information where lawfully collected |
Directly from individuals; recruitment or education partners |
Accessibility, equal opportunity, services, reporting and legal compliance |
Relevant partners and service providers |
| Commercial information |
Services considered or obtained, transaction and engagement history |
Directly from individuals; systems; partners |
Service delivery, administration, analytics and marketing |
Technology providers, partners and advisers |
| Biometric information |
Biometric identifiers where specifically required and lawfully collected |
Directly from individuals or approved systems |
Identity, security or accessibility purposes |
Approved security or technology providers |
| Internet or network activity |
Browsing activity, interactions, IP address, device and cookie information |
Devices, browsers, cookies, analytics and advertising partners |
Website operation, security, analytics, service improvement and advertising |
Hosting, security, analytics and advertising providers |
| Geolocation information |
General location derived from an IP address or device settings |
Devices, browsers and technology providers |
Security, website localisation and analytics |
Technology, analytics and security providers |
| Audio, visual or similar information |
Call recordings, webinar recordings, photographs and CCTV |
Directly from individuals; events; premises and communication systems |
Training, events, security, quality assurance and record-keeping |
Event, communications and security providers |
| Professional or employment information |
Employer, role, CV, qualifications, work history, references and assessment results |
Individuals, referees, recruiters and public professional profiles |
Business relationships, recruitment and workforce administration |
Recruitment, screening and professional service providers |
| Education information |
Qualifications, educational history, applications and course interests |
Individuals, institutions and education partners |
Enquiries, applications, admissions and service delivery |
Education partners and relevant service providers |
| Inferences |
Inferred interests, preferences or engagement |
Interactions, analytics and marketing systems |
Analytics, personalisation, marketing relevance and service improvement |
Analytics, marketing and technology providers |
| Sensitive personal information |
Government identifiers, account credentials, financial account information, racial or ethnic origin, health, disability, sexual orientation, religious beliefs, union membership, biometric information and precise geolocation where applicable |
Individuals, partners and approved service providers |
Services, accessibility, security, recruitment, legal compliance and other disclosed purposes |
Service providers and partners requiring the information for the relevant purpose |
OES retains each category for no longer than reasonably necessary for the purpose for which it was collected. The applicable period is determined using the criteria in the Retention section, including the relationship or transaction, legal and contractual requirements, limitation periods, security needs and the sensitivity of the information.
Sale And Sharing Of Personal Information
OES does not sell personal information in exchange for money.
OES’ use of certain advertising, analytics and social media technologies may, however, constitute a sale or sharing under the broad definitions in the CCPA, including sharing for cross-context behavioural advertising. During the preceding 12 months, OES may have sold or shared the following categories through these technologies:
- identifiers, including online and device identifiers;
- internet or other electronic network activity;
- commercial or engagement information;
- general geolocation information; and
- inferences about interests or engagement.
These categories may be sold or shared with advertising networks, analytics providers, social media platforms and similar marketing technology providers for advertising delivery, campaign measurement, analytics and cross-context behavioural advertising.
OES does not sell or share sensitive personal information for cross-context behavioural advertising.
OES does not have actual knowledge that it sells or shares the personal information of consumers under 16 years of age.
Sensitive Personal Information
OES uses sensitive personal information only where reasonably necessary to provide requested services, maintain security, process employment or education-related activities, comply with law or carry out other purposes permitted by the CCPA.
OES does not use or disclose sensitive personal information for the purpose of inferring characteristics about California residents or for other purposes that would require OES to provide a separate right to limit under the CCPA. If these practices change, OES will provide the required notice and method to exercise the right to limit.
California Privacy Rights
Subject to applicable exceptions, California residents have the right to:
- Know: Request the categories and specific pieces of personal information OES has collected and information about its sources, purposes and disclosures.
- Delete: Request deletion of personal information OES collected from you.
- Correct: Request correction of inaccurate personal information.
- Opt out of sale or sharing: Direct OES not to sell or share personal information.
- Limit sensitive personal information: Limit certain uses and disclosures of sensitive personal information where that right applies.
- Data portability: Receive requested information in a readily usable format where technically feasible.
- Automated decision-making rights: Receive applicable notices and exercise access or opt-out rights relating to covered automated decision-making technology, where required.
- Non-discrimination: Exercise CCPA rights without unlawful discrimination or retaliation.
Exercising California rights
California residents may submit requests through the following methods:
For opt-out requests, use the Your Privacy Choices or Do Not Sell or Share My Personal Information link on the relevant OES website or enable a qualifying browser-based opt-out preference signal, such as Global Privacy Control.
OES will process qualifying opt-out preference signals as required by California law. The signal will generally apply to the browser or device from which it is received and, where OES can associate the signal with an account or profile, may also be applied to that account.
OES will acknowledge and respond to verifiable requests within the periods required by the CCPA, generally within 45 days. OES may extend the response period once by an additional 45 days where reasonably necessary and will notify you of the extension.
OES may verify a request by asking for information that can be matched with information already held by OES. The verification required will depend on the nature of the request and the sensitivity of the information involved. OES will use information provided for verification only for that purpose.
Requests to opt out of sale or sharing do not require identity verification, although OES may request information necessary to process the request.
Authorised agents
A California resident may authorise another person or a business registered with the California Secretary of State to submit a request on their behalf. OES may require evidence that the agent has authority to act for the resident; verification of the resident’s identity; or direct confirmation from the resident that the agent is authorised. These requirements do not apply where the agent holds a valid power of attorney under applicable California law.
Financial incentives
OES does not currently offer financial incentives or price or service differences in exchange for collecting, retaining, selling or sharing personal information. If OES introduces such a program, it will provide the notice and obtain any consent required by the CCPA.
17. Changes to this Policy
OES may update this Policy to reflect changes to its operations, services, technology, legal obligations or privacy practices. When OES updates the Policy, we will publish the revised version and update the Last updated date.
Where changes are material, OES will take reasonable steps to provide additional notice, which may include a website notice, direct communication or another method appropriate to the circumstances.