Legal information

Privacy Notice

This notice explains how Unirovia handles personal data for prospects, students, parents/guardians, website users, representatives and contacts.

01

Controller and scope

UNIROVIA INTERNATIONAL EDUCATION AND TRAVEL SERVICES LIMITED, trading as Unirovia, is responsible for personal data it determines how and why to process. This notice covers prospects, students, parents/guardians, website users, representatives and contacts.

02

Data collected

Unirovia may collect identity and contact details; account credentials and session records; education history, transcripts, certificates, programme preferences and eligibility information; passport, photograph, visa and travel documentation when required for an active service; payment, invoice and transaction records; communications, complaints and consent records; technical and security data such as IP address, device/browser information, logs and cookie choices; and special-category or sensitive information only where necessary and lawful, such as limited health information required by an official process.

03

Purposes and lawful grounds

Unirovia processes data to assess eligibility, provide requested and contracted services, communicate, submit authorised applications, meet legal/accounting duties, prevent fraud, secure systems, improve services, and conduct consent-based marketing. The lawful ground must be recorded for each processing activity; consent is used where required and may be withdrawn without affecting prior lawful processing.

04

Sharing and international transfers

Data may be shared, only as needed, with selected universities, authorised translators/notaries, visa or consular service providers, insurers, airlines/travel partners, payment providers, professional advisers and vetted technology processors. Because applications and cloud systems may involve Türkiye or other countries, Unirovia must document a lawful transfer mechanism, necessity, safeguards and recipient before transfer.

05

Technology providers and staff access

MongoDB supports application data storage; Cloudinary stores protected profile images and student documents using authenticated delivery; the configured email provider sends transactional email; and Google Analytics may measure website use only after the required cookie consent. Essential sessions support login and security. Access by authorised Staff is limited by role and service need. Marketing consent is separate, optional and withdrawable.

06

Rights

Subject to law and applicable exceptions, individuals may request access, correction, deletion, restriction or objection; withdraw consent; and complain to Unirovia or the Somalia Data Protection Authority. Identity may be verified before disclosure. Requests should be sent to Admin@unirovia.com and logged.

07

Retention and security

Data is retained only as long as necessary for the stated purpose, legal claims, accounting and regulatory duties, then securely deleted or anonymised under Policy 11. Unirovia uses role-based access, encryption where appropriate, MFA for privileged users, secure providers, audit logs, backups and incident procedures.

08

Children

A parent or lawful guardian must participate where the applicant is under 18, unless Somali law permits otherwise. Unnecessary children's data must not be collected, used for profiling or marketing, or shared without documented authority.

09

Complaints and updates

Privacy complaints may be sent to Admin@unirovia.com. Individuals may also complain to the Somalia Data Protection Authority. Material changes will be dated and communicated where required.