International Student Desk
Product Privacy Notice
This Product Privacy Notice explains how International Student Desk uses personal data to provide the service.
Controller and contact
The controller is International Student Desk, a registered trade name of a Dutch sole proprietorship (eenmanszaak), Kortenaerkade 9N, 2518 AX Den Haag, Netherlands, registered with the Dutch Chamber of Commerce under KvK 93791380. VAT ID: NL005043544B06.
Privacy and rights requests: privacy@internationalstudentdesk.com. General service questions: hello@internationalstudentdesk.com. Complaints: complaints@internationalstudentdesk.com. Telephone: +31 6 82589322.
Who may use the product and what we collect
One Desk account represents one named student aged 16 or older. Depending on how you use the Desk, we may collect the student's name, email address, login records, account settings, registration confirmations, and technical security data.
A named student may optionally ask a parent or guardian to pay. We use that recipient's name and email address to deliver and administer a secure, 48-hour payment link. For a student aged 16 or 17, the same link also records the required guardian decision. Uncompleted requests are deleted after 30 days. Payment and any guardian-approval evidence for a completed purchase is kept with the contract record. The payer does not receive a separate Desk account, and the named student remains the customer and licence holder.
The student may enter planning information such as school system, curriculum, application year, study interests, selected institutions, deadlines, checklist progress, and notes.
What we do not want you to enter
Do not upload or enter passport details, visa or residence permit details, medical information, financial information, official diploma files, official transcripts, confidential school documents, passwords, or government identification numbers unless the Desk clearly asks for it in a reviewed future feature.
Do not enter unnecessary sensitive personal information, confidential material, or official documents into Fen. Fen does not need document uploads at launch.
Purposes and lawful bases
Contract, or steps requested before a contract, is the basis for account creation, entitlement checks, requested planning features, guardian approval evidence and service delivery where that processing is necessary. Consent is used for optional marketing and optional analytics, advertising, profiling or cross-site linkage. Marketing is not required to use the Desk.
Legitimate interests is the basis for proportionate security, abuse prevention, service reliability and narrow support administration. Legal obligation applies to records that applicable law requires us to keep, including accounting records.
We do not switch a consent-based purpose to another basis merely to avoid a withdrawal of consent.
How Fen questions are processed
Fen is an AI assistant powered through OpenAI. The interface tells students that they are interacting with AI. Fen is planning support and does not determine admission, eligibility, grading, subject access or access to education.
When the student asks Fen to respond, the question, limited recent conversation, relevant Desk context and selected source text are sent to OpenAI. OpenAI states that API inputs and outputs are not used to train its models by default. Under OpenAI's standard API configuration, content may be retained in abuse-monitoring logs for up to 30 days and content flagged for safety reasons may be reviewed by authorised provider personnel.
The Desk keeps minimised usage, delivery, token, cost and safety records needed to provide and protect the service, but does not keep a routine server-side transcript of Fen chats. Browser-local conversation history remains until the student clears it or the browser's site data.
There is no routine human reading of student prompts. Any narrowly necessary incident or safety review must be role-restricted, logged, disclosed, time-limited and covered by the retention policy.
Cookies, browser storage and optional tracking
The product uses necessary cookies and browser storage for requested functions such as account security, sign-in, registration continuation, saved planning work, Fen continuity and remembering privacy choices.
Audience analytics, personalisation, profiling and cross-site marketing stay off unless you actively opt in. Refusing optional tracking does not limit access to the Desk. The separate Product Cookie and Storage Notice lists current storage, retention and withdrawal controls.
Recipients, processors and international transfers
Recipients may include providers that support hosting, accounts, essential emails, payments, security and Fen. Supabase supports accounts and hosted records; Resend sends essential account, guardian-approval, purchase and withdrawal emails; Stripe processes payment and billing information; and OpenAI processes the limited question and context sent to Fen. We may also share information with professional advisers, courts, regulators or public authorities where necessary or required by law.
Some recipients may process information outside the European Economic Area. We make such transfers only where an applicable European Commission adequacy decision or another lawful safeguard applies, such as the European Commission's Standard Contractual Clauses. You may request information about the safeguard that applies.
We do not sell personal information. We do not share it with educational institutions or public bodies unless the student asks us to, a requested feature clearly requires it, or the law requires it. Third-party product analytics and advertising are not used in the paid product at launch.
Passwords are handled by the login provider and are not visible to the Desk in readable form.
Retention
Account and planning information is kept while the account is active and afterwards only for the time reasonably needed to close or delete it, subject to legal records and protected backup cycles.
Fen, security, service, support and essential-email records are kept for short periods needed to provide and protect the service, resolve a request or incident, or establish or defend legal claims. Routine durable server-side prompt and response transcripts are not kept. Browser-local conversation history remains until the student clears it or the browser's site data.
Payment, invoice, accounting, tax and contract records are kept for the applicable legal retention period. This is normally seven years for Dutch financial records and may be up to ten years where EU VAT rules require it. Other contract evidence is kept only as long as reasonably needed for the contract, a legal duty, dispute or claim.
Optional marketing information is kept until consent is withdrawn or the purpose ends. A limited suppression record may be retained to honour an unsubscribe request. Deletion from active systems may not immediately remove protected encrypted backups, which are overwritten through the providers' normal backup cycles.
Automated decisions
The Desk does not make decisions that have legal or similarly significant effects on a student. Fen and matching tools provide planning support only; they do not decide admission, eligibility, visa status, finance or access to education. Important requirements must be verified with the official institution or authority.
Your rights
Under GDPR, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing is based on consent.
Signed-in account holders can use Privacy & account to download product-account data, open the profile to correct editable data, withdraw optional product marketing, or permanently delete the product account after a fresh password sign-in and explicit confirmation. This does not automatically remove a separate public prelaunch registration, contact question, or product-interest entry.
Rights requests and help with account-email corrections or separately collected records can be sent to privacy@internationalstudentdesk.com. Identity is verified proportionately, and the operating target is to respond without undue delay and within one month, subject to lawful verification, extension and exception rules.
You may lodge a complaint with the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. We would appreciate the chance to address the concern first, but contacting us is not a condition of complaining to the authority.
Customer Terms and Conditions · Student Data and Fen Privacy Q&A · International Student Desk