Gradix Pte. Ltd. — 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
Gradix Pte. Ltd. ("Gradix.io", "we", "us", "our") operates a B2B platform connecting recruitment agencies, local institutions, and international universities through a technology-driven ecosystem for international student admissions. We are committed to protecting the privacy and security of all personal data processed through our platform.
This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard personal data. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, Singapore's Personal Data Protection Act 2012 (PDPA), Canada's PIPEDA, the California Consumer Privacy Act (CCPA/CPRA), Australia's Privacy Act 1988, and other applicable data protection laws.
By accessing gradix.io, creating a partner account, or submitting information to our platform, you acknowledge that you have read and understood this Policy.
This Policy applies to:
This Policy does not apply to third-party websites, university portals, or partner systems linked from our platform.
Gradix.io acts in different capacities depending on the data:
| Data Category | Our Role |
|---|---|
| Partner account data, website analytics, marketing contacts, employment applications | Data Controller |
| Student application data uploaded by recruitment agency and institution partners | Data Processor Acting on documented instructions of the partner, who is the Controller |
| Data transmitted onward to international universities | Universities act as independent Controllers |
Where we act as a Processor, our processing is governed by a Data Processing Agreement executed with the relevant partner.
Certain data we process may constitute special category data under Article 9 GDPR or sensitive personal data under the PDPA and other regimes. This may include:
We process such data only where the data subject has given explicit consent; where processing is necessary for the establishment, exercise, or defence of legal claims; or where processing is required to comply with immigration and education regulatory obligations.
We do not process special category data for marketing, profiling, or automated decision-making without explicit consent.
| Purpose | Lawful Basis |
|---|---|
| Providing platform access and account management to partners | Performance of a contract |
| Processing student applications and transmitting to universities | Performance of a contract; legitimate interests; consent obtained by partner |
| Commission calculation and payment | Performance of a contract; legal obligation |
| Fraud prevention, document verification, and compliance screening | Legal obligation; legitimate interests |
| Platform security, audit logging, and incident response | Legitimate interests |
| Direct marketing to business contacts | Legitimate interests; consent where required |
| Regulatory reporting to education and immigration authorities | Legal obligation |
| AI-assisted document verification and completeness checking | Legitimate interests |
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment balancing our interests against your rights and freedoms. You may request a summary of this assessment.
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We use personal data to:
Gradix.io uses artificial intelligence and automated systems to support admissions processing, including:
Automated verification of document completeness, internal consistency, formatting compliance, and expiry validation.
Routing applications to appropriate stages and generating notifications.
Highlighting applications that may require additional human review.
These systems assist human decision-makers; they do not make final admissions decisions. No solely automated decision-making producing legal or similarly significant effects is carried out on students within the meaning of GDPR Article 22. All flagged applications are subject to human review by qualified staff before any adverse action is taken.
Data subjects have the right to obtain human intervention, express their point of view, and contest any output of these systems.
We do not use personal data submitted through the platform to train third-party general-purpose AI models without a lawful basis and appropriate contractual safeguards.
We disclose personal data only to the categories of recipients below.
Student application data is transmitted to the specific universities to which a student has applied. Each university acts as an independent Controller and applies its own privacy policy.
Partners access data relating to students they have introduced, and to sub-agents within their network.
These include cloud hosting and infrastructure providers, email and notification platforms, payment processors and banking institutions, identity verification and fraud detection services, customer support systems, and analytics providers. All such providers are bound by written agreements containing confidentiality undertakings and appropriate technical and organisational measures.
We may disclose personal data where required by law, court order, or a competent regulatory or immigration authority, or where necessary to establish, exercise, or defend legal claims.
In the event of a merger, acquisition, restructuring, or asset sale, personal data may be transferred to the acquiring entity, subject to this Policy and applicable law.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising.
Gradix.io operates a global network spanning multiple jurisdictions, including the United Kingdom, Canada, Australia, the United States, Germany, the United Arab Emirates, Singapore, Malaysia, Turkey, Hungary, South Korea, and Pakistan. Personal data will therefore be transferred across borders.
Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we implement one or more of the following safeguards:
Transfers under Singapore's PDPA comply with the Transfer Limitation Obligation.
You may request details of the safeguards applied to a specific transfer by contacting us at operations@gradix.io.
We retain personal data only for as long as necessary for the purposes described in this Policy, and in accordance with our contractual obligations to university partners and the statutory requirements of relevant education regulators, immigration authorities, and accounting law.
Retention periods vary by data category and by the jurisdiction and institution to which an application relates. Where we act as a Processor, retention is determined by the partner Controller's documented instructions, subject to our statutory minimums.
Upon expiry of the applicable period, data is securely deleted or irreversibly anonymised.
You may request information about the retention period applicable to a specific category of data by contacting operations@gradix.io.
Subject to applicable law and verification of identity, you have the right to:
Access
Obtain confirmation of processing and a copy of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion where processing is no longer necessary or consent is withdrawn
Restriction
Limit processing in defined circumstances
Data portability
Receive your data in a structured, commonly used, machine-readable format
Object
Object to processing based on legitimate interests, and to direct marketing at any time
Withdraw consent
At any time, without affecting prior lawful processing
Not be subject to solely automated decision-making
Producing legal or similarly significant effects
Lodge a complaint
With a supervisory authority
Additional rights apply in certain jurisdictions. California residents have the right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination for exercising these rights. Singapore residents may withdraw consent and request access and correction under the PDPA. Canadian residents may challenge our compliance and access personal information held. Australian residents have rights under Australian Privacy Principles 12 and 13.
To exercise your rights, contact operations@gradix.io. We respond within 30 days, extendable to 60 days for complex requests with notice to you. No fee applies unless a request is manifestly unfounded or excessive.
If you are a student whose data was submitted by a recruitment agency, please direct your request to that agency in the first instance. We will assist them in fulfilling it, and will also respond to you directly where we act as Controller.
We implement appropriate technical and organisational measures to protect personal data, including:
Encryption of data in transit and at rest
Role-based access control and the principle of least privilege
Multi-factor authentication for administrative accounts
Network security controls, including firewalls and intrusion detection
Logical separation of partner data environments
Comprehensive audit logging of data access and modification
Due diligence and contractual controls on all service providers
Confidentiality obligations and mandatory data protection training for personnel
Encrypted backups and tested disaster recovery procedures
Periodic vulnerability assessment and security testing
No system is entirely secure. While we apply industry-standard safeguards, we cannot guarantee absolute security of data transmitted over the internet.
In the event of a personal data breach:
We maintain an internal breach register documenting all incidents, their effects, and remedial action taken.
Our platform is a B2B service not directed at children. However, applicants for international education may occasionally be under 18.
Where personal data of a minor is submitted, the submitting partner is responsible for obtaining verifiable parental or guardian consent as required by applicable law. We apply enhanced safeguards, including restricted access and exclusion from marketing communications. We do not knowingly collect data directly from children under 16 without appropriate authorisation.
If you believe a minor's data has been submitted without proper authorisation, contact operations@gradix.io for immediate review and deletion where appropriate.
Our website and platform contain links to university websites, partner portals, and external resources. We are not responsible for the privacy practices or content of these third parties. We encourage you to review their privacy policies before submitting personal data.
If you believe your data protection rights have been infringed, please contact us first at operations@gradix.io so we may resolve the matter.
You also have the right to lodge a complaint with a supervisory authority, including:
Singapore
Personal Data Protection Commission (PDPC)
European Union
Your national Data Protection Authority
United Kingdom
Information Commissioner's Office (ICO)
Canada
Office of the Privacy Commissioner of Canada
Australia
Office of the Australian Information Commissioner (OAIC)
California
California Privacy Protection Agency (CPPA)
We may update this Policy to reflect changes in law, technology, or our services. Material changes will be communicated by posting the revised Policy at gradix.io with an updated "Last Updated" date, and by notifying registered partners by email at least 30 days before the changes take effect. Where required, we will obtain fresh consent.
Continued use of the platform after the effective date of changes constitutes acceptance, except where consent is legally required.
Gradix Pte. Ltd.
160 Robinson Road, #14-04
Singapore Business Federation Center
Singapore 068914
For all enquiries — including general questions, privacy matters, data subject rights requests, and security disclosures — please contact operations@gradix.io.
© 2026 Gradix Pte. Ltd. All rights reserved.