Privacy & Data Protection

Gradix Privacy Policy

Gradix Pte. Ltd. — 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914

Effective Date: 9 July 2026 Last Updated: 9 July 2026
1

Introduction

Gradix Pte. Ltd. ("Gradix.io", "we", "us", "our") operates a B2B platform connecting recruitment agencies, local institutions, and international universities through a technology-driven ecosystem for international student admissions. We are committed to protecting the privacy and security of all personal data processed through our platform.

This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard personal data. It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, Singapore's Personal Data Protection Act 2012 (PDPA), Canada's PIPEDA, the California Consumer Privacy Act (CCPA/CPRA), Australia's Privacy Act 1988, and other applicable data protection laws.

By accessing gradix.io, creating a partner account, or submitting information to our platform, you acknowledge that you have read and understood this Policy.

2

Scope

This Policy applies to:

  • Visitors to gradix.io and related subdomains
  • Recruitment agency partners, sub-agents, and counsellors using the Gradix Portal
  • Local institutions and international university partners
  • Prospective and current students whose application data is submitted to the platform by our partners
  • Applicants for employment with Gradix

This Policy does not apply to third-party websites, university portals, or partner systems linked from our platform.

3

Our Role: Controller and Processor

Gradix.io acts in different capacities depending on the data:

Data Category Our Role
Partner account data, website analytics, marketing contacts, employment applications Data Controller
Student application data uploaded by recruitment agency and institution partners Data Processor Acting on documented instructions of the partner, who is the Controller
Data transmitted onward to international universities Universities act as independent Controllers

Where we act as a Processor, our processing is governed by a Data Processing Agreement executed with the relevant partner.

4

Personal Data We Collect

4.1 Partner and Business Contact Data

  • Full name, job title, business email address, telephone number
  • Company/agency name, registration number, business address, country of operation
  • Bank and remittance details for commission payments
  • Login credentials, authentication tokens, and account security information
  • Contractual documents, including recruiter agreements and compliance declarations

4.2 Student Application Data (processed on behalf of partners)

  • Identity data: full name, date of birth, gender, nationality, passport number, national ID
  • Contact data: home address, email address, telephone number
  • Academic data: transcripts, degree certificates, grade records, English language test results
  • Immigration and visa data: visa history, previous refusals, immigration status
  • Financial data: bank statements, sponsorship letters, funding evidence, scholarship documentation
  • Supporting documents: personal statements, references, CVs, employment records, and medical or disability disclosures where voluntarily submitted
  • Application status, offer letters, enrolment confirmations, and related admissions records

4.3 Technical and Usage Data

  • IP address, browser type and version, operating system, device identifiers
  • Login timestamps, session duration, pages accessed, features used
  • Cookie identifiers and similar tracking technologies
  • Audit logs of actions taken within the Gradix Portal

4.4 Communications Data

  • Correspondence with our support, compliance, and regional management teams
  • Records of calls, emails, in-platform messages, and automated notifications
  • Feedback, survey responses, and training programme participation
5

Special Category and Sensitive Data

Certain data we process may constitute special category data under Article 9 GDPR or sensitive personal data under the PDPA and other regimes. This may include:

  • Racial or ethnic origin (inferred from nationality or passport data)
  • Health data or disability disclosures submitted for reasonable adjustment purposes
  • Religious affiliation, where disclosed in scholarship or accommodation applications
  • Criminal conviction data, where required for visa compliance declarations

We process such data only where the data subject has given explicit consent; where processing is necessary for the establishment, exercise, or defence of legal claims; or where processing is required to comply with immigration and education regulatory obligations.

We do not process special category data for marketing, profiling, or automated decision-making without explicit consent.

6

Lawful Bases for Processing

Purpose Lawful Basis
Providing platform access and account management to partners Performance of a contract
Processing student applications and transmitting to universities Performance of a contract; legitimate interests; consent obtained by partner
Commission calculation and payment Performance of a contract; legal obligation
Fraud prevention, document verification, and compliance screening Legal obligation; legitimate interests
Platform security, audit logging, and incident response Legitimate interests
Direct marketing to business contacts Legitimate interests; consent where required
Regulatory reporting to education and immigration authorities Legal obligation
AI-assisted document verification and completeness checking Legitimate interests

Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment balancing our interests against your rights and freedoms. You may request a summary of this assessment.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

7

How We Use Personal Data

We use personal data to:

  1. 1 Create, authenticate, and administer partner accounts and sub-agent networks
  2. 2 Receive, validate, and process student applications through structured admissions workflows
  3. 3 Perform AI-assisted document intelligence, including completeness checks, cross-document consistency verification, and compliance flagging
  4. 4 Transmit application packages to international university partners
  5. 5 Track application progress across counsellors, branches, intakes, countries, and stages
  6. 6 Calculate, verify, and remit partner commissions
  7. 7 Provide visa counselling support, training resources, and counsellor enablement
  8. 8 Send transactional notifications, status updates, and service communications
  9. 9 Detect and prevent fraudulent applications, document forgery, and misuse of the platform
  10. 10 Comply with legal, regulatory, and contractual obligations, including those imposed by education regulators and immigration authorities
  11. 11 Generate aggregated, anonymised analytics to improve platform performance and reporting
  12. 12 Respond to enquiries, disputes, and legal claims
8

Automated Processing and AI Systems

Gradix.io uses artificial intelligence and automated systems to support admissions processing, including:

Document compliance checks

Automated verification of document completeness, internal consistency, formatting compliance, and expiry validation.

Workflow automation

Routing applications to appropriate stages and generating notifications.

Risk flagging

Highlighting applications that may require additional human review.

These systems assist human decision-makers; they do not make final admissions decisions. No solely automated decision-making producing legal or similarly significant effects is carried out on students within the meaning of GDPR Article 22. All flagged applications are subject to human review by qualified staff before any adverse action is taken.

Data subjects have the right to obtain human intervention, express their point of view, and contest any output of these systems.

We do not use personal data submitted through the platform to train third-party general-purpose AI models without a lawful basis and appropriate contractual safeguards.

9

Disclosure of Personal Data

We disclose personal data only to the categories of recipients below.

International university partners

Student application data is transmitted to the specific universities to which a student has applied. Each university acts as an independent Controller and applies its own privacy policy.

Recruitment agency and institution partners

Partners access data relating to students they have introduced, and to sub-agents within their network.

Service providers

These include cloud hosting and infrastructure providers, email and notification platforms, payment processors and banking institutions, identity verification and fraud detection services, customer support systems, and analytics providers. All such providers are bound by written agreements containing confidentiality undertakings and appropriate technical and organisational measures.

Legal and regulatory disclosures

We may disclose personal data where required by law, court order, or a competent regulatory or immigration authority, or where necessary to establish, exercise, or defend legal claims.

Corporate transactions

In the event of a merger, acquisition, restructuring, or asset sale, personal data may be transferred to the acquiring entity, subject to this Policy and applicable law.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

10

International Data Transfers

Gradix.io operates a global network spanning multiple jurisdictions, including the United Kingdom, Canada, Australia, the United States, Germany, the United Arab Emirates, Singapore, Malaysia, Turkey, Hungary, South Korea, and Pakistan. Personal data will therefore be transferred across borders.

United Kingdom Canada Australia United States Germany UAE Singapore Malaysia Turkey Hungary South Korea Pakistan

Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we implement one or more of the following safeguards:

  • Standard Contractual Clauses adopted by the European Commission
  • The UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses
  • Transfer Impact Assessments evaluating the legal environment of the destination country
  • Supplementary technical measures, including encryption in transit and at rest, pseudonymisation, and access controls
  • Binding contractual commitments and, where available, certification mechanisms

Transfers under Singapore's PDPA comply with the Transfer Limitation Obligation.

You may request details of the safeguards applied to a specific transfer by contacting us at operations@gradix.io.

11

Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, and in accordance with our contractual obligations to university partners and the statutory requirements of relevant education regulators, immigration authorities, and accounting law.

Retention periods vary by data category and by the jurisdiction and institution to which an application relates. Where we act as a Processor, retention is determined by the partner Controller's documented instructions, subject to our statutory minimums.

Upon expiry of the applicable period, data is securely deleted or irreversibly anonymised.

You may request information about the retention period applicable to a specific category of data by contacting operations@gradix.io.

12

Data Subject Rights

Subject to applicable law and verification of identity, you have the right to:

Access

Obtain confirmation of processing and a copy of your personal data

Rectification

Correct inaccurate or incomplete data

Erasure

Request deletion where processing is no longer necessary or consent is withdrawn

Restriction

Limit processing in defined circumstances

Data portability

Receive your data in a structured, commonly used, machine-readable format

Object

Object to processing based on legitimate interests, and to direct marketing at any time

Withdraw consent

At any time, without affecting prior lawful processing

Not be subject to solely automated decision-making

Producing legal or similarly significant effects

Lodge a complaint

With a supervisory authority

Additional rights apply in certain jurisdictions. California residents have the right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination for exercising these rights. Singapore residents may withdraw consent and request access and correction under the PDPA. Canadian residents may challenge our compliance and access personal information held. Australian residents have rights under Australian Privacy Principles 12 and 13.

To exercise your rights, contact operations@gradix.io. We respond within 30 days, extendable to 60 days for complex requests with notice to you. No fee applies unless a request is manifestly unfounded or excessive.

If you are a student whose data was submitted by a recruitment agency, please direct your request to that agency in the first instance. We will assist them in fulfilling it, and will also respond to you directly where we act as Controller.

13

Cookies and Tracking Technologies

We use the following categories of cookies:

Category Purpose Consent Required
Strictly necessary Authentication, session management, security, load balancing No
Functional Language preference, dashboard configuration Yes
Analytics and performance Usage measurement, feature adoption, error monitoring Yes
Marketing Campaign attribution, remarketing Yes

Non-essential cookies are set only after affirmative consent, in accordance with the ePrivacy Directive and GDPR. You may modify or withdraw consent at any time through your cookie preferences or by configuring your browser settings.

We honour Global Privacy Control signals as a valid opt-out of sale or sharing where applicable.

14

Security Measures

We implement appropriate technical and organisational measures to protect personal data, including:

Encryption of data in transit and at rest

Role-based access control and the principle of least privilege

Multi-factor authentication for administrative accounts

Network security controls, including firewalls and intrusion detection

Logical separation of partner data environments

Comprehensive audit logging of data access and modification

Due diligence and contractual controls on all service providers

Confidentiality obligations and mandatory data protection training for personnel

Encrypted backups and tested disaster recovery procedures

Periodic vulnerability assessment and security testing

No system is entirely secure. While we apply industry-standard safeguards, we cannot guarantee absolute security of data transmitted over the internet.

15

Data Breach Notification

In the event of a personal data breach:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware, where the breach is likely to result in a risk to individuals' rights and freedoms
  • We will notify the Personal Data Protection Commission of Singapore where the notification thresholds under the PDPA are met
  • We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Where we act as a Processor, we will notify the relevant partner Controller without undue delay

We maintain an internal breach register documenting all incidents, their effects, and remedial action taken.

16

Children's Privacy

Our platform is a B2B service not directed at children. However, applicants for international education may occasionally be under 18.

Where personal data of a minor is submitted, the submitting partner is responsible for obtaining verifiable parental or guardian consent as required by applicable law. We apply enhanced safeguards, including restricted access and exclusion from marketing communications. We do not knowingly collect data directly from children under 16 without appropriate authorisation.

If you believe a minor's data has been submitted without proper authorisation, contact operations@gradix.io for immediate review and deletion where appropriate.

18

Complaints and Supervisory Authorities

If you believe your data protection rights have been infringed, please contact us first at operations@gradix.io so we may resolve the matter.

You also have the right to lodge a complaint with a supervisory authority, including:

Singapore

Personal Data Protection Commission (PDPC)

European Union

Your national Data Protection Authority

United Kingdom

Information Commissioner's Office (ICO)

Canada

Office of the Privacy Commissioner of Canada

Australia

Office of the Australian Information Commissioner (OAIC)

California

California Privacy Protection Agency (CPPA)

19

Changes to This Policy

We may update this Policy to reflect changes in law, technology, or our services. Material changes will be communicated by posting the revised Policy at gradix.io with an updated "Last Updated" date, and by notifying registered partners by email at least 30 days before the changes take effect. Where required, we will obtain fresh consent.

Continued use of the platform after the effective date of changes constitutes acceptance, except where consent is legally required.

20

Contact Us

Gradix Pte. Ltd.

160 Robinson Road, #14-04
Singapore Business Federation Center
Singapore 068914

operations@gradix.io

For all enquiries — including general questions, privacy matters, data subject rights requests, and security disclosures — please contact operations@gradix.io.

© 2026 Gradix Pte. Ltd. All rights reserved.