Skip to content
Draft — pending legal reviewVersion 1.0 · Last updated 29 September 2026

Privacy notice

How we handle personal data on our website and in the Oxonia Govern platform, and the rights you have.

Legal documents are published in English. Text in [brackets] is a placeholder to be completed before launch.

Questions? Contact us

Who we are and what this notice covers#

Oxonia Govern is provided by [Oxonia legal entity name], [Registered office address] ("Oxonia", "we", "us"). This notice explains how we process personal data in two different roles.

  • As a controller, for our own website (govern.oxonia.app), demo and pilot requests, sales and support correspondence, and the operation of our business.
  • As a processor, for the personal data a university puts into the Oxonia Govern platform (for example Senate minutes, attendance, AI-use declarations and training records). There, the university is the controller and decides why and how the data is used. We act only on its documented instructions, under our Data Processing Agreement.

If you are a member of staff, a student, or a member of a governing body at a university that uses Oxonia Govern, your university is responsible for how your data is used in the platform. Please contact your university’s data protection officer first; we will help them respond.

Personal data we collect as a controller#

SourceDataPurposeLawful basis
Demo and pilot formsName, work email, institution, role, country, messageRespond to your request and arrange a demo or pilotLegitimate interests; steps prior to a contract
Correspondence and supportContact details and the content of your messagesAnswer questions and provide supportLegitimate interests; performance of a contract
Website operationIP address, browser type, pages requested, timestamps (server logs)Security, fraud and abuse prevention, troubleshootingLegitimate interests
Account administrationName, email and role of university administrators we deal withAccount management, billing and service noticesPerformance of a contract
EventsName, organisation and contact details you give us at eventsFollow up on your interestLegitimate interests; consent where required

We do not use advertising cookies or third-party trackers on our website, and we do not sell personal data.

Personal data processed in the platform (as a processor)#

Depending on the modules a university uses, the platform may process:

  • Identity and account data: name, work email, phone number, title, faculty, roles, sign-in and security events.
  • Governance records: agendas, papers, board packs, attendance, declarations of interest, votes (secret ballots are stored without any link between a member and their choice), minutes, resolutions and actions.
  • Meeting recordings and transcripts, where the university enables recording and the required consent is recorded.
  • AI-policy and compliance data: policies, the AI-use register, tool requests, risk assessments, incidents and evidence.
  • Teaching and assessment data: AI-use declarations, optional process evidence from the composition space (typing and pasting counts and timings, and periodic snapshots of the student’s own text — never keystrokes), integrity case records, training progress and certificates.
  • Messages sent on the university’s behalf by email, SMS or WhatsApp, and replies to them.
  • Audit logs of access, approvals, exports and AI agent runs.

The university determines which of these it collects, the lawful basis, and how long it keeps them. We process them only to provide the service.

How AI features use personal data#

Oxonia Govern includes AI agents that draft documents (for example minutes and policy clauses) and answer questions. Every AI output is labelled as an AI draft until a person adopts it, and anything that becomes an official record requires human approval.

  • AI providers are engaged as our sub-processors and are configured for zero data retention and no training on customer data wherever the provider offers it.
  • Prompts and outputs are stored in the university’s own tenant, not shared with other customers.
  • Retrieval for answers is filtered by the user’s permissions before any ranking, so confidential items are never used to answer someone who cannot see them.
  • Where configured, personal data can be redacted before a request is sent to an external model.
  • We do not use customer platform data to train our own or third-party models.
  • The platform does not make decisions with legal or similarly significant effects about individuals by automated means alone. For example, an AI-detection score can never on its own open an academic integrity case.

Who we share personal data with#

  • Sub-processors that host and operate the service (listed on our Sub-processors page), bound by written terms at least as protective as ours.
  • Professional advisers (lawyers, accountants, auditors) under confidentiality obligations.
  • Authorities, where the law requires it. We will tell the affected university unless the law prohibits it.
  • A buyer or successor in a merger or acquisition, subject to this notice.

Regulators and university federations that use the Federation view receive aggregated, anonymised statistics only, and a university’s documents only if that university chooses to share them.

International transfers and data residency#

Each university chooses where its platform data is stored (for example the EU or UK; a Nigeria-hosted option is in preparation). Some sub-processors, including AI providers, may process data outside that region.

Where personal data is transferred across borders, we rely on appropriate safeguards required by the applicable law — such as adequacy decisions, standard contractual clauses, or other mechanisms recognised under the Nigeria Data Protection Act 2023, the UK GDPR or the EU GDPR — and we assess the transfer. Details are available on request.

How long we keep data#

  • Demo and pilot requests: up to 24 months after our last contact, unless you become a customer.
  • Website server logs: up to 90 days, unless needed to investigate a security incident.
  • Platform data: for as long as the university instructs, and deleted or returned at the end of the contract as set out in the Data Processing Agreement.
  • Meeting audio: according to each governing body’s retention setting; bodies can choose to delete audio automatically once minutes are approved.
  • Audit logs: for the period the university configures, and at least as long as needed to demonstrate the integrity of official records.

Security#

We protect personal data with encryption in transit and at rest, strict tenant isolation enforced both in the application and by database row-level security, role-based access control, mandatory two-factor authentication for privileged roles, and append-only audit logs. See our Security page for more detail.

Your rights#

Depending on the law that applies to you (including the Nigeria Data Protection Act 2023, the UK GDPR and the EU GDPR), you may have the right to:

  • be informed about and access your personal data;
  • have inaccurate data corrected;
  • have data erased or its processing restricted;
  • object to processing based on legitimate interests;
  • data portability;
  • withdraw consent at any time, where processing is based on consent;
  • not be subject to decisions based solely on automated processing that significantly affect you.

For our website and sales data, contact privacy@oxonia.app. For platform data, contact your university’s data protection officer. We respond within the time limits set by law, and do not charge for reasonable requests.

You also have the right to complain to a supervisory authority, such as the Nigeria Data Protection Commission, the UK Information Commissioner’s Office, or the authority in your EU member state. We would appreciate the chance to address your concern first.

Students under 18#

Some universities admit students under 18. Where a university uses the platform with such students, it is responsible for the lawful basis and any required consent, and for configuring features appropriately. Our website is not directed at children.

Changes and contact#

We will post any changes on this page and update the date above; for material changes affecting customers we will give notice as set out in our agreements. Questions: privacy@oxonia.app. Data protection officer: [DPO name and contact].