BUSINESS ENGLISH LANGUAGE SCHOOL LTD (hereinafter BELS, we, us, our, the School), having company registration number C.19451 and its registered office at No.4, Triq ix-Xnien, San Gwann SGN 1661, Malta, will act as the data controller in processing your personal data and/or personal data relating to your parent or legal guardian in accordance with the Data Protection Act (Chapter 568), as enacted in Malta and which implements and further specifies the relevant provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, better known as the General Data Protection Regulation (GDPR).
BELS is committed to protecting and respecting your privacy. We take the privacy of all of our students, their parents or legal guardians, where applicable, host families and individuals working with us in a commercial capacity as an Agent, service provider and/or subcontractor, seriously and take great care to protect their personal information.
Please read the following policy carefully to understand what information we may collect from you, how we may use it, and your rights in respect of our use.
We will be guided by the following principles when processing your data:
We will only collect data for specific and specified purposes. We will make it clear at the point when we request your information, what we are collecting it for and how we are going to use it.
We will not collect data beyond what is necessary to accomplish those purposes. We will minimise the amount of information we collect from you to what we need to deliver the services required.
We will collect and use your personal information only if we have sensible business reasons for doing so, such as managing a quotation request or booking or gathering necessary information about a host family or an individual connected to our Agents or service providers.
We will not use data for purposes other than that for which the data was collected, except as stated herein, or with prior consent.
We will seek to verify and/or update data periodically, and we will accept requests for amendments of personal data.
We will apply high technical standards to make our processing of data secure.
Except when stated herein, we will not store data in identifiable form longer than is necessary to accomplish its purpose, or as is required by law.
The information collected by BELS includes information that you provide to us when you:
contact us for a quotation or information, via our website, by email, by phone, through social media or in person.
submit an enrolment or registration form to join a course or programme at the School.
sign up for lessons or a newsletter or subscribe to other services.
give us feedback about your experience at BELS.
use our website.
post on our social media channels or on our website or blog.
request live support/chat.
work with us in a commercial capacity (for example as an Agent, service provider and/or subcontractor).
apply to be a host family.
We require our students to provide us with their personal details, including name, gender, date and place of birth; contact details such as address, email address, landline and mobile numbers; and information concerning their identity such as photo ID or passport information and nationality.
When you affect a payment for our services, we process your account details including full beneficiary name, bank account number and sort code. When you affect a card payment, we do not store your card details. Your card details are processed and stored by our card processor, Flywire Corporation which is PCI DSS Compliant.
In case of minors, we also collect the abovementioned personal details for the parent or legal guardian.
In fulfilling its responsibilities and ensure the safety and wellbeing of our students, BELS processes special categories of personal data (such as any medical conditions).
When you work with us in a commercial capacity, we require you to provide us with your personal details, including name; contact details such as address, email address, landline and mobile numbers. Additionally, as part of our vetting exercise we may request copies of permits and authorisations of all our sub-contractors/agents or other persons providing any non-academic services to the students on behalf of the School.
PURPOSES AND LEGAL BASES FOR PROCESSING YOUR DATA
We use different legal bases for processing your data depending on the purpose for collecting your data.
Personal data collected as part of the process of enquiring about, obtaining quotations, applying for and booking a course, is processed when necessary for the performance of a contract to which the student is party or in order to take steps at the request of the student prior to entering into a contract.
Personal data collected as part of the process of booking any other related service such as accommodation, airport transfer, insurance to cover you during your stay and visa applications, is processed when necessary for the performance of a contract to which the student is party (or in order to take steps at the request of the student prior to entering into a contract) and for the purpose of the legitimate interest pursued by BELS or by a third party. This may include sending of your data to our partners such as Operators, Host Families and Hotels.
BELS will take a photo of the student for administrative and record purposes and to comply with its legal obligation to provide an identification document for each student registered to follow a course at the School. During your stay, we may also take photographs or videos of you for promotional, marketing or communication purposes, with your prior Consent.
Any processing of personal data not directly related to the fulfilment of a booking or related services, such as for direct marketing or the signing up for newsletters on our website, will be processed with your Consent.
For all data collected as part of managing our relationship with commercial partners, such as sub-contractors/Agents or other persons providing any non-academic services to the students including, without prejudice to generality of the foregoing, accommodation or lodging, transportation, cultural, leisure, entertainment and sports activities in Malta and Gozo, we process such data when necessary for the performance of a contract and under a legal obligation to vet the necessary permits and authorisations of all sub-contractors/Agents or other persons providing any non-academic services to the students on behalf of the School and in the case of lodging facilities, to ensure that such facilities at all times comply with all licensing conditions and applicable regulations. As newsletters to commercial partners are an important part of how we communicate with them, these are managed under Legitimate Interest.
We may also process any of your personal data identified in this policy where necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is Legitimate Interest or in the case of special categories of personal data for such establishment, exercise or defence of the legal claim.
SPECIAL CATEGORIES OF PERSONAL DATA
BELS will processes special categories of personal data (health data) to protect the vital interest (wellbeing) of the student or of another natural person where the student is physically or legally incapable of giving consent.
CHILDREN UNDER 18
We collect or store personal data about children under the age of 18 in the context of managing bookings and directly related services, and for safeguarding the wellbeing of the children.
Through our Legal Guardian Consent Form, we obtain permission directly from the Parent or a legal guardian to process visual images for communication purposes and to process electronic address for direct marketing purposes. As part of this process, we also request special categories of personal data relating to the health of the child, which is necessary to protect the vital Interest of the student or of another natural person.
DISCOLURE OF YOUR PERSONAL DATA
BELS will share your information with others where it is lawful to do so including where BELS or any third party:
needs it in order to provide you with the product or service;
has a public or legal obligation to do so;
in connection with any regulatory reporting obligations,
in litigation or asserting or defending its legal rights and interests; or
has obtained your consent to share it.
Specifically, BELS may share your information for the above purposes with others including:
any Agents who introduced you to BELS or deal with BELS for you;
host families, providers for your accommodation, insurance brokers or non-scholastic activity providers who work for BELS or provide services to BELS (including their employees, directors and officers);
processors and their respective sub-processors who work for BELS or provide services to BELS (including their employees, directors and officers) such as the software provider of our CLASS School Management Software, our hosting provider, our IT managed service provider, and other service providers. If you would like to receive more details on our processors and sub-processors please send us an email to [email protected] and we would provide you with the requested information.
the English Language Teaching Council (ELTC) or any other educational authority and any party appointed or requested by the educational authorities to carry out investigations or audits of our activities;
law enforcement, government, tax authorities, courts, dispute resolution bodies, and our auditors.
TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES
BELS shall not cause or permit any personal data to be transferred outside of the EEA unless such transfer takes place under one of the following conditions:
Transfers are based on adequacy decisions, that is, processing of the personal data carried out in a country that the European Commission has considered as offering an adequate level of protection;
Transfers are subject to adequate safeguards on the basis of an agreement between BELS and a data processor, designed to protect your information, in the appropriate form approved for this purpose by the European Commission;
You have consented to such transfer and acknowledge and accept that certain data processors engaged by BELS in the provision of the products and services are located in a country that the European Commission has not formally declared to have an adequate level of protection and are not able to demonstrate appropriate safeguards;
the transfer is necessary for the performance of a contract between BELS and the student;
the transfer is necessary for the conclusion or performance of a contract concluded in your interest between BELS and the data processor;
the transfer is necessary for important reasons of public interest; or
the transfer is necessary for the establishment, exercise or defence of legal claims.
RETENTION OF YOUR INFORMATION
Your personal data is managed to ensure that it is either erased from our system when it is no longer required for the purpose for which it was collected and/or once any retention period required by law elapses.
Your personal data which is stored on our CLASS School Management Software and/or which forms part of our fiscal records will be retained for a period of ten years in accordance with our legal obligation.
Where you have consented us to process your personal data or visual images for direct marketing purposes, we will retain your data until you would have withdrawn your consent or objected to such processes.
When you are introduced to BELS by one of our Agents, which is incorporated or established within the European Union (“EU”), BELS and the Agent shall be both responsible for compliance with their respective obligations under the GDPR as joint controllers, in particular as regards the exercising of your below rights as data subject. You may exercise your rights in respect of and against each of the controllers by contacting either your Agent or BELS directly. BELS and the Agent endeavour to assist each other in fulfilling your requests.
If you are student residing outside of the EU and are introduced by an Agent which is incorporated or established in your home country, the Agent shall be responsible for compliance with its obligations under Data Protection Legislation applicable in your home country whereas BELS shall be responsible for compliance with its obligations under the GDPR, in particular as regards the exercising of your below rights as data subject. You can exercise your rights at any time by contacting directly BELS Data Protection Officer by email to [email protected].
You have a number of rights in relation to the personal data that BELS holds about you. These rights include:
the right to access information which BELS holds about you and to obtain information about how BELS process it;
the right to withdraw at any time any consent you have provided to BELS, without affecting the lawfulness of processing based on such consent before its withdrawal;
the right to request BELS to rectify your information if it is inaccurate or incomplete;
the right to request, in certain circumstances, BELS to erase your personal data unless the data is necessary for compliance with a legal obligation to which BELS is subject to or for the establishment, exercise or defence of a legal claim;
in certain circumstances the right to obtain from BELS restriction to your personal data;
in certain circumstances, you may also have a “data portability” right to require us to transfer your personal data to you or to a new service provider; and
the right to object at any time to processing of your personal data for direct marketing purposes and to any profiling and automated decision making.
You can exercise your rights at any time by contacting directly BELS Data Protection Officer by email to [email protected].
In the event that you have applied or enrolled through an Agent, BELS and the Agent would be considered as Joint Controllers. If you are a resident of and/or your Agent is established within the European Union, BELS and the Agent are both responsible for compliance with the obligations under GDPR. In this regards, you can exercise your rights under GDPR at any time by contacting either BELS as indicated above or by contacting your Agent.
You have also the right to raise complaints or concerns about BELS use or processing of your personal information with the body regulating data protection in your country, if you are residing in another EU member State or the Office of Information and Data Protection Commissioner in Malta (details are available at https://idpc.gov.mt/en/Pages/Home.aspx).
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server. Cookies may collect information (including Personal Information), such as user preferences, general usage information and unique identifiers.
We use a single cookie, “sessionid”, to identify you when you visit our website, keep you logged in as you navigate our website, and store temporary information. This functional cookie does not identify any individual, and is required for the correct operation of our website.
Livechat – provides a chat service to our website visitors.
Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:
Blocking all cookies will have a negative impact upon the usability of many websites. If you block cookies, you will not be able to use all the features on our website.
LINKS FROM OUR WEBSITE
HOW WE KEEP YOU PERSONAL DATA SECURE
We store your personal information on secure servers that are managed and maintained by our service providers which are committed to a global certification strategy so that their infrastructures and services comply with Information Security international standards and best practices. Personal information that we store or transmit is protected by security and access controls, including username and password authentication, and data encryption where appropriate.