Privacy Policy
Last Updated: January 1, 2025 • Effective Date: January 1, 2025
Table of Contents
Introduction
Open Xenodochial Oasis University (“OXOU,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (oxou.edu.kg), apply for admission, enroll as a student, or otherwise interact with our university.
By using our website or providing us with your personal information, you consent to the data practices described in this policy. If you do not agree with this policy, please do not access or use our services.
Contact Information
Open Xenodochial Oasis University
12 University Avenue, Ala Too District
Chuy Region, Kyrgyz Republic 720000
Email: privacy@oxo.edu.kg
General Inquiries: info@oxo.edu.kg
Scope of This Policy
This Privacy Policy applies to:
- All visitors to our website (oxo.edu.kg)
- Prospective students and applicants
- Current and former students
- Faculty, staff, and employees
- Alumni and donors
- Parents and guardians of students
- Any other individuals who provide personal information to OXOU
This policy covers information collected through:
- Our website and online portals
- Application forms and admissions processes
- Student enrollment and academic records
- Email communications and newsletters
- Events, campus visits, and recruitment activities
- Surveys and feedback forms
- Third-party platforms integrated with our services (Google Analytics, WPForms)
Information We Collect
Personal Information You Provide
We collect information that you voluntarily provide to us, including:
Application & Admission Information:
- Full name, date of birth, gender, nationality
- Contact details (email address, phone number, mailing address)
- Passport or national ID information
- Previous educational history and academic transcripts
- Standardized test scores (IELTS, TOEFL, Duolingo, etc.)
- Letters of recommendation and references
- Statement of purpose and essays
- CV/Resume and portfolio materials
- Financial information for scholarship applications
Student Records (for enrolled students):
- Academic performance, grades, and transcripts
- Course enrollment and attendance records
- Disciplinary records
- Health and medical information (for accommodation purposes only)
- Immigration and visa status
- Financial aid and tuition payment records
- Campus housing and meal plan preferences
Communication Preferences:
- Email subscription preferences
- Language and communication preferences
- Communication history with our admissions and support teams
Information We Collect Automatically
When you visit our website, we automatically collect certain information through cookies and similar technologies:
Device & Browser Information:
- IP address and approximate geolocation data
- Browser type, version, and language settings
- Operating system and device type
- Device identifiers and screen resolution
Usage Data:
- Pages visited and time spent on each page
- Clickstream data and navigation paths
- Referral source (how you arrived at our website)
- Date and time of visits
- Forms submitted and files downloaded
Cookies & Tracking Technologies:
- Session cookies and persistent cookies
- Google Analytics cookies for website analytics
- Web beacons and pixel tags
See Section 8 for detailed information about cookies.
Information from Third Parties
We may receive information about you from:
- Educational institutions (for transcript verification)
- Testing agencies (IELTS, TOEFL, ETS, etc.)
- Payment processors (for tuition payments)
- Background check providers (as permitted by law)
- Government agencies (for visa and immigration purposes)
- Scholarship and funding organizations
How We Use Your Information
We use your personal information for the following purposes:
Admissions & Enrollment
- Processing and evaluating applications for admission
- Communicating admission decisions and program information
- Assessing eligibility for scholarships and financial aid
- Facilitating enrollment, registration, and orientation
- Conducting background checks (where permitted by law)
- Managing waitlists and application deferrals
Educational Services
- Managing student records and academic progress
- Providing academic support, advising, and tutoring services
- Facilitating course registration and class scheduling
- Issuing grades, transcripts, diplomas, and certificates
- Coordinating internships, career services, and job placements
- Managing campus housing, dining services, and student activities
Communication & Marketing
- Sending important academic updates and announcements
- Marketing our programs to prospective students
- Sending newsletters, event invitations, and promotional materials (with consent)
- Responding to inquiries and support requests
- Conducting surveys and gathering feedback to improve our services
Legal & Administrative
- Complying with legal and regulatory obligations
- Enforcing our terms of service, policies, and academic regulations
- Preventing fraud, ensuring campus security, and protecting student safety
- Conducting internal audits and quality assurance
- Defending legal claims and protecting our rights and property
Website Improvement & Analytics
- Analyzing website usage and performance using Google Analytics
- Improving user experience and website functionality
- Testing new features and services
- Personalizing content and recommendations
- Troubleshooting technical issues
Research & Statistical Analysis
- Conducting educational research (with anonymized data)
- Generating statistical reports for accreditation and regulatory compliance
- Evaluating program effectiveness and student outcomes
- Publishing institutional data in aggregate form only
Legal Basis for Processing (GDPR Compliance)
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions with similar data protection laws, we process your personal information based on the following legal grounds:
- Contractual Necessity: To fulfill our contract with you (e.g., providing educational services to enrolled students, processing your application)
- Legitimate Interests: To operate and improve our university, conduct research, ensure campus security, and maintain academic standards (where not overridden by your fundamental rights)
- Consent: For marketing communications, optional data collection, and cookies (you may withdraw consent at any time)
- Legal Obligation: To comply with applicable laws, regulations, court orders, and accreditation requirements
- Vital Interests: To protect your health, safety, and well-being in emergency situations
How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information with the following parties:
Service Providers
We engage trusted third-party vendors to perform functions on our behalf:
- WPForms: Form processing and application submissions
- Google Analytics: Website analytics and performance tracking
- Payment processors for tuition and fee payments
- Email and communication platforms
- Cloud storage and hosting services
- Student information system vendors
- Background check providers
These providers are contractually obligated to protect your data and use it only for the specific purposes we authorize.
Academic & Government Institutions
- Educational credential verification services
- Accreditation bodies and regulatory authorities in Kyrgyzstan
- Immigration and visa authorities (for international students)
- Scholarship and funding organizations
- Transfer institutions (with your consent)
- Partner universities and exchange programs
Legal Requirements
We may disclose your information when required by law or when we believe disclosure is necessary to:
- Comply with court orders, subpoenas, or legal processes
- Respond to regulatory investigations
- Protect our rights, property, and safety, as well as that of our students and staff
- Prevent fraud, illegal activities, or violations of our policies
- Cooperate with law enforcement in criminal investigations
Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. You will be notified of any such change in ownership or control of your personal information.
With Your Consent
We may share your information with other parties when you have given explicit consent, such as:
- Publishing your name and photo in university materials (yearbooks, website, social media)
- Sharing your information with potential employers through career services
- Including you in alumni directories
- Nominating you for external awards or recognitions
International Data Transfers
OXOU is located in the Kyrgyz Republic. If you are accessing our services from outside Kyrgyzstan, please be aware that your information may be transferred to, stored, and processed in Kyrgyzstan or other countries where our service providers operate.
These countries may have data protection laws that differ from those in your country of residence. We take appropriate measures to ensure your information receives adequate protection, including:
- Standard contractual clauses approved by the European Commission
- Ensuring third-party processors comply with GDPR and similar standards
- Implementing technical and organizational safeguards
- Conducting data protection impact assessments for high-risk transfers
By using our services and providing your personal information, you consent to the transfer of your information to Kyrgyzstan and other countries as described in this policy.
Cookies and Tracking Technologies
What Are Cookies?
Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit a website. They help websites remember your preferences and improve your browsing experience. We use cookies and similar technologies (web beacons, pixel tags) to enhance functionality, analyze usage, and deliver personalized content.
Types of Cookies We Use
Essential Cookies (Always Active)
These cookies are necessary for the website to function properly and cannot be disabled without affecting site performance:
- Session cookies: Maintain your session as you navigate the website
- Security cookies: Authenticate users and prevent fraudulent use
- Load balancing cookies: Distribute traffic across our servers
Analytics Cookies (Google Analytics)
We use Google Analytics to understand how visitors use our website. These cookies collect information in an anonymized form:
| Cookie Name | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes unique users and tracks sessions | 2 years |
| _gid | Distinguishes unique users | 24 hours |
| _gat | Throttles request rate to limit data collection | 1 minute |
| _ga_<container-id> | Persists session state (Google Analytics 4) | 2 years |
Data collected by Google Analytics includes:
- Pages viewed and time spent on each page
- Traffic sources (search engines, referral sites, direct visits)
- Geographic location (country, city)
- Device type, browser, and operating system
- User behavior patterns (bounce rate, navigation paths)
Google Analytics anonymizes IP addresses before storing data. Learn more: Google Privacy Policy
Functional Cookies
These cookies enable enhanced functionality and personalization:
- Remember your language and region preferences
- Store your application form progress (WPForms partial entries)
- Remember your consent choices for cookies
- Customize website layout based on your preferences
WPForms Cookies
When you use our application forms powered by WPForms:
- wpforms_form_<form_id>_abandoned: Saves partial form entries so you can return and complete your application later (stored locally in your browser for up to 30 days)
- wpforms_submit: Prevents duplicate form submissions
Third-Party Cookies
Our website may contain embedded content from third-party services (such as Google Maps for campus location). These third parties may set their own cookies. We do not control these cookies, and you should review their privacy policies:
- Google Maps: Google Privacy Policy
- Google Analytics: How Google uses data
Managing Cookies
You have several options to control and manage cookies:
Browser Settings:
- Block all cookies (may affect website functionality)
- Accept only first-party cookies (block third-party cookies)
- Delete cookies after each browsing session
- Receive notifications before cookies are stored
Opt-Out Tools:
- Google Analytics Opt-Out: Install the Google Analytics Opt-out Browser Add-on
- Do Not Track (DNT): Enable DNT in your browser settings (note: not all websites honor DNT signals)
⚠️ Important: Disabling cookies may limit your ability to use certain features of our website, including application form auto-save functionality.
For more information about cookies, visit www.allaboutcookies.org.
Data Retention
We retain your personal information only as long as necessary for the purposes outlined in this policy, or as required by law. Retention periods vary depending on the type of information and legal requirements in Kyrgyzstan:
| Data Type | Retention Period | Reason |
|---|---|---|
| Applicant Data (not enrolled) | 7 years after application | Statistical reporting, accreditation requirements, potential re-application |
| Student Academic Records | Permanent (indefinitely) | Issuance of transcripts, degree verification, alumni services |
| Financial Records | 10 years | Tax compliance, audit requirements under Kyrgyz law |
| Disciplinary Records | 10 years after graduation | Reference checks, legal compliance |
| Employment Records | 10 years after termination | Labor law compliance, pension records |
| Website Analytics (Google Analytics) | 26 months (auto-deletion) | Website improvement and analysis |
| Marketing Consents | Until withdrawn or 3 years of inactivity | Compliance with consent requirements |
| Email Communications | 5 years | Record-keeping, dispute resolution |
| Security Logs | 1 year | Security monitoring and incident response |
After the retention period expires:
- We securely delete or anonymize your personal information
- Anonymized data may be retained indefinitely for research and statistical purposes
- Some information may be retained longer if required by legal obligations or ongoing legal proceedings
Early Deletion: You may request early deletion of your information by contacting privacy@oxo.edu.kg, subject to legal and legitimate business requirements.
Your Rights and Choices
Depending on your location and applicable laws, you may have the following rights regarding your personal information:
Right to Access
- Request a copy of the personal information we hold about you
- Receive information about how we process your data
- Obtain copies of your academic records and transcripts
Right to Rectification
- Correct inaccurate or incomplete personal information
- Update your contact details and preferences
- Amend outdated information
Right to Erasure ("Right to Be Forgotten")
- Request deletion of your personal information
- Note: We may need to retain certain records for legal, administrative, or accreditation purposes (e.g., academic transcripts, financial records)
Right to Restriction
- Request that we limit how we process your information
- Restrict processing while we verify accuracy or assess objections
Right to Data Portability
- Receive your data in a structured, machine-readable format
- Transfer your data to another service provider (where technically feasible)
Right to Object
- Object to processing based on legitimate interests
- Opt out of marketing communications at any time
- Object to automated decision-making (we do not currently use fully automated decision-making for admissions)
Right to Withdraw Consent
- Withdraw consent for data processing (where consent is the legal basis)
- Unsubscribe from marketing emails using the link in each message
- Note: Withdrawal does not affect the lawfulness of processing before withdrawal
Right to Lodge a Complaint
- File a complaint with your local data protection authority
- Contact the Kyrgyz Republic’s data protection regulator (if applicable)
- We encourage you to contact us first so we can address your concerns: privacy@oxo.edu.kg
How to Exercise Your Rights
To exercise any of these rights, please email privacy@oxo.edu.kg with:
- Your full name and contact information
- A clear description of your request
- Proof of identity (to prevent unauthorized access)
- Your application or student ID number (if applicable)
Response Time: We will respond to your request within 30 days (or as required by applicable law). In complex cases, we may extend this period by an additional 60 days, and we will notify you of any delay.
No Fee: We do not charge a fee for processing your requests unless they are manifestly unfounded, excessive, or repetitive.
Data Security
We implement appropriate technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction:
Technical Safeguards:
- Encryption: Data in transit is protected using SSL/TLS encryption (HTTPS). Sensitive data at rest is encrypted using industry-standard algorithms.
- Secure Servers: Our website and databases are hosted on secure servers with firewalls and intrusion detection systems.
- Regular Security Audits: We conduct periodic vulnerability assessments and penetration testing.
- Multi-Factor Authentication (MFA): Staff access to sensitive systems requires MFA.
- Secure Backups: Regular encrypted backups with disaster recovery procedures.
- Software Updates: Timely installation of security patches and updates.
Organizational Measures:
- Access Controls: Role-based access permissions ensure staff can only access data necessary for their duties.
- Employee Training: Regular training on data protection, privacy, and security best practices.
- Confidentiality Agreements: All staff and contractors sign confidentiality agreements.
- Incident Response Plan: Procedures for detecting, responding to, and reporting security breaches.
- Vendor Management: Third-party service providers undergo security assessments and must comply with our data protection standards.
Your Responsibility:
- Keep your login credentials confidential
- Use strong, unique passwords
- Log out of your account when using shared computers
- Notify us immediately if you suspect unauthorized access: security@oxo.edu.kg
⚠️ Important: While we strive to protect your information using industry best practices, no system is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any breaches in accordance with applicable laws and notifying affected individuals as required.
Children's Privacy
Our services are primarily directed to individuals aged 16 and older (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children under the age of 16 without parental consent.
For Applicants Under 18:
- We may require parental or guardian consent for certain data processing activities
- Parents/guardians may request access to their child’s information
- We may communicate with parents/guardians regarding admissions and academic matters
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at privacy@oxo.edu.kg. We will promptly investigate and delete such information if we determine it was collected inappropriately.
Third-Party Links and Services
Our website may contain links to external websites and integrations with third-party services that are not operated by OXOU. We are not responsible for the privacy practices of these third parties.
Third-Party Services We Use:
Google Analytics
- Purpose: Website analytics, user behavior tracking, and performance monitoring
- Data Collected: IP address (anonymized), device information, pages visited, session duration
- Privacy Policy: https://policies.google.com/privacy
- Opt-Out: Google Analytics Opt-out Browser Add-on
WPForms
- Purpose: Application form processing, contact forms, and surveys
- Data Collected: Form responses, email addresses, uploaded documents
- Privacy Policy: https://wpforms.com/privacy-policy/
- Note: Form submissions are stored on our secure servers; WPForms acts as a form builder tool
Google Maps
- Purpose: Display campus location and provide directions
- Privacy Policy: https://policies.google.com/privacy
Payment Processors
- Purpose: Processing tuition payments and application fees
- Note: We do not store your full credit card information; payments are processed securely through third-party payment gateways compliant with PCI DSS standards
Your Responsibility:
We encourage you to review the privacy policies of any third-party sites or services you access through our website. Each service has its own privacy policy governing data collection, use, and protection.
External Links: Our website may link to partner universities, scholarship organizations, social media platforms, and other educational resources. These links are provided for your convenience, but we do not endorse or assume responsibility for the content or privacy practices of these external sites.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or technology. When we make material changes, we will notify you through one or more of the following methods:
- Updating the “Last Updated” date at the top of this policy
- Displaying a prominent notice on our website homepage
- Sending an email notification to your registered email address
- For significant changes affecting your rights, we may seek your renewed consent
Your Continued Use: Your continued use of our website and services after the effective date of any changes constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, please discontinue use of our services and contact us to discuss your options.
Version History: We maintain a record of previous versions of this Privacy Policy. To request a copy of a prior version, please contact privacy@oxo.edu.kg.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Jurisdiction-Specific Rights
In addition to the rights described in Section 10, residents of certain jurisdictions may have additional rights under local laws:
For Users in the European Economic Area (EEA) and United Kingdom
Under the General Data Protection Regulation (GDPR) and UK GDPR, you have comprehensive data protection rights, including:
- Right to access, rectification, erasure, and data portability
- Right to restrict processing and object to automated decision-making
- Right to lodge a complaint with your supervisory authority
- Right to withdraw consent at any time
EU Representative: For GDPR-related inquiries, contact privacy@oxo.edu.kg
For Users in California, USA
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have the right to:
- Know what personal information is collected and how it is used
- Request deletion of your personal information
- Opt out of the sale or sharing of personal information (note: we do not sell your data)
- Correct inaccurate personal information
- Limit the use of sensitive personal information
- Non-discrimination for exercising your privacy rights
California residents may submit requests via privacy@oxo.edu.kg or call us during office hours.
For Users in Canada
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have rights regarding access, correction, and complaints about our handling of your personal information.
For Users in Other Jurisdictions
We comply with applicable data protection laws in all jurisdictions where we operate or recruit students. If you have specific questions about your rights under local laws, please contact us at privacy@oxo.edu.kg.