Privacy Policy for Website Visitors

1.0 Introduction & Scope

This Privacy Notice is related to Epicode Group which fall in scope of the General Data Protection Regulation (GDPR), namely, Epicode Institute of Technology Ltd (‘Group’, ‘Company’, ‘we’, ‘us’, ‘our’). We are committed to safeguarding the privacy of our clients using our services (‘user’, or ‘you’, ‘your’). The Group has a separate Privacy Policy for the usage of its websites.

This Privacy Notice explains how we collect, use, disclose, and safeguard and treat your personal information when you are seeking to become a client, student, employee or contractor of the Group (collectively, ‘Services’).

By utilising, or receiving, our services, you agree with the terms of this Privacy Notice. By providing us with your personal information, you acknowledge to the Group that it is processing your personal data/personal information in accordance with this Notice and the applicable EU laws and regulations.

This Privacy Notice is applicable to the processing of personal data of customers who are Citizens or Residents within the European Union or being serviced by an entity of the Group located in the European Union.

2.0 What type of personal information will we hold on you and why?

We may collect, store and use the following kinds of personal information:

Personal details as per our forms such as collaboration agreements, employment agreements, certificate of enrolment, enrolment application form and similar forms . We shall process the following data on you at enrolment stage (students):

  • Name
  • Surname
  • Date of Birth
  • Place of Birth
  • Address
  • ID document number
  • Tax number
  • Nationality
  • Email address
  • Phone number
  • Residency address
  • School or University Qualifications
  • CV
  • Qualifications / Certificates as applicable
  • University transcript of records, if applicable

Furthermore, if you are a student, during your studies, we will also process the following personal data:

  • Enrolment data including the name of the program and its start date
  • Institutional email address which is formed of the student’s matriculation number and also serves to register on the Learning Management System and to access the live sessions we provide
  • Students’ Progress for every on demand subject
  • Students’ attendance during live sessions
  • Students’ name, surname and institutional email address, as well as image and voice during both, written and oral exams
  • Students’ projects and assignments
  • Courses taken and grades, including the transcript of records
  • Final dissertation and project work
  • Final diploma and diploma supplement

We shall also keep the following financial records for students:

  • Tuition Fee payment history
  • Bank account information

We also keep login and usage data throughout Learning Management System (LMS):

  • Activity logs
  • Exam and assessment submission data
  • Access to university platforms logs, including Discord, Webex, and exam.net
  • IP addresses used for proctored exams, whether written or oral, platform access or live sessions access.
  • Email addresses, name and surname, image and voice are also kept
  • Attendance of the student is also kept on record
  • We will keep a copy of your identification document(s) such as ID card, driving license, residency card, passport or any other identification document available.
  • We will keep a copy of information or documentation to proof residency of your address such as bank statement, bank reference, utility bill, fix telephone line bill, lease agreement or similar documentation.
  • We will keep a copy of your communication with us, such as emails and letters.
  • We may hold and process any other information or documentation we provide to you to complete, whether in physical or digital format, in line with our legal obligations and legitimate interest reasons.

We also keep the following data of contractors and employees:

  • Name
  • Surname
  • Date of Birth
  • Place of Birth
  • Address
  • Document number
  • Tax number
  • Nationality
  • Email Address
  • Phone number
  • Employment contract details
  • Salary or payment records
  • ID Document or Passport
  • Curriculum Vitae
  • Any relevant certificates and professional qualifications
  • Teaching schedule and assigned courses
  • Image and voice during the delivery of the lessons and during exams
  • Login and activity data on LMS or email
  • Course evaluation by students

3.0 When do we need your consent?

We shall need your consent in the following circumstances:

  1. When sending you direct marketing material or promotions regarding our services, unless there is a clear and tested legitimate interest for you to receive such material;
  2. When sharing your personal information outside the Group, unless we are required to do so by law such as providing information to police, court of law or a competent authority, or when we are sending your data to date processors in order to be able to provide you with a service. Please see section 5 for more details. We may also share your data outside the group without your consent if we are sharing it with our processors to help us provide you with a service; and
  3. When processing your personal information without having one of the other legal basis found in section 4 below.

Please note that you can withdraw your consent at any time, unless there is another legal basis that allows us to process your data as per the below section.

3.1 Sending of non-marketing information

From time to time we may send you non-marketing material such as general information about matters that may concern you. Such material is usually sent by email. This is performed after ensuring that our legitimate interest to send you such non-marketing material would not affect in a negative manner your privacy. We shall always provide you with an option to unsubscribe from such informative material. Should you unsubscribe, we shall not send you further non-marketing material. The same would apply if you have requested or shall request that no material whatsoever is sent to you.

Examples of such non-marketing material are found below:

  • Information about new regulations or rules related to your course;
  • Information related to the course you are attending;
  • Information about any other topic which may be of personal interest for you.

The above list is non-exhaustive.

4.0 When can we process your personal data?

Apart from the ‘consent’ noted in section 3 above, we may also process your data if we have the following legal basis:

  1. Contractual obligation or necessity;
  2. Legal obligation;
  3. Member-state law;
  4. Vital interest of the data subject;
  5. When processing the data is in the best interest of the public; and
  6. Legitimate interest.

It is the nature of our business to process your data mostly due to a contractual necessity, legal obligation or due to a legitimate interest. When neither of these apply, it is likely that we will process your data based upon your consent. That said, the Group may process data according to regulations listed within the General Data Protection Regulation (“GDPR”) when dealing with EU residents, EU Citizens or when operating within the European Union (EU) or the European Economic Area (EEA).

4.1 Processing of Personal Data outside the EU/EEA

The Group shall take enhanced measures to protect personal data of EU citizens and/or Residents when such data is being processed through its Head Office, since this is located outside of the EU/EEA. Any transfer of data to countries outside of the EU/EEA is made in line with the principles listed under Article 44 and appropriate safeguards as noted in Article 46, of the GDPR.

In certain instances, where applicable, the Group may apply derogations to transfer data outside of the EU, as specified in Article 49 of the GDPR. Derogations apply only when data is transferred not on ongoing basis but as occasional / one-off.  This may include:

  • Your specific consent
  • Transfer is necessary for the performance of a contract which is in your interest
  • Transfer is necessary for the performance of a contract which is in your interest
  • Transfer is necessary due to public interest
  • Transfer is necessary for the establishment, exercise or defence of legal claims; and/or
  • Transfer is necessary due to vital interests.

5.0 How and when do we disclose your personal information to third parties?

We may disclose your personal information:

  1. To the extent that we are required to do so by law;
  2. In connection with any ongoing or prospective legal proceedings;
  3. In order to establish, exercise or defend our legal rights
  4. To any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information;
  5. To any of our employees, officers, insurers, professional advisers, bankers, agents, suppliers, IT service providers or subcontractors insofar as reasonably necessary for the purposes set out in this notice (also known as Processors and sub-processors);
  6. To any member of our group of companies (this means our subsidiaries, our ultimate holding company and all its subsidiaries) insofar as reasonably necessary for the purposes set out in this notice. If the Company is merged, acquired, or sold, or in the event of a transfer of some, or all, of our assets or equity, we may disclose or transfer Personal Information and usage data in connection with such transaction;
  7. In all other circumstances where you would have given your consent.

We will not, without your express consent, supply your personal information to any third party for the purpose of their, or any other third party’s direct marketing.

Personal information that you publish on our website or submit for publication on our website may be available, via the internet, around the world. We cannot prevent the use or misuse of such information by others.

6.0 Where is your data stored and how is it protected?

Your data may be stored in one or more of the following locations:

  1. Physical files which may be held under lock and key in our offices;
  2. On server using Google Drive within the EU

6.1 How is your personal data protected?

We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. We maintain physical, electronic, and procedural safeguards to protect the confidentiality and security of Personal Information and other information transmitted to us.

You acknowledge that the transmission of information over the internet is inherently insecure and while we strive to protect information transmitted on or through the Site or Services, we cannot, and do not, guarantee the security of any information you transmit on, or through, the Site or Services, and you do so at your own risk.

That said, when information reaches our Group, we shall take the necessary steps to protect such information. This is done by one or more of the below:

  1. Ensuring the data is safeguarded by the use of any of the following: firewalls, encryptions, access restrictions and/or passwords;
  2. In case of physical copies of your personal information or data, precaution shall be taken to ensure such data is accessible only to individuals within the Group that require to access your data to perform their duties and/or to provide you with a service;
  3. The Group shall ensure that proper backups are taken to prevent the data from being lost; and
  4. Without prejudice to section 6 above, your data saved in digital format on our servers, cloud or on our Learning systems shall be accessible by individuals that are required to access your data to perform their duties and/or to provide you with a service. Relevant authorities may request to access your data at any time. This includes, but not limited, to the following Authorities or Entities:
  • The Police;
  • Court of Law, Magistrates and Court experts;
  • The Financial Intelligence Analysis Unit (FIAU);
  • The Commissioner for Data Protection;
  • MFHEA or any other controlling supervising legal entity in relation to accreditation audits and supervision; and/or
  • Other competent Authorities located in Countries we provide our services in or being established in.

7.0 For how long shall we keep your data?

Personal data will be retained by the Group for as long as it is necessary for the purposes of processing such data. Thus, the Group will keep data for as long as it is obliged to by law, or need to keep a record of, a relationship with a client.  As a minimum, we shall keep your data for 5 years following the completion of service or termination of our business relationship with you. This is to ensure we are in line with our legal obligations. If you are a student with us, certain information about your studies is retained permanently since we have a legal obligation to do so. This includes information related to your academic records, examinations and results and similar information.

7.1 How shall we destroy your data after the retention period is over?

We shall destroy your data in a safe and reliable manner. Physical files shall be destroyed by means of shredding. Shredding services may be outsourced to third parties. The Group shall ensure that if shredding is outsourced to third parties, the Group shall review their data privacy procedures and safeguard the interest of the data subjects through ways and means such as through a contractual agreement between the Group as data controller and the shredding company as data processors in line with Article 28 of the General Data Protection Regulation. For the removal of any doubt, this would only apply if the group provides non-shredded data to the shredding service provider. If shredding is done in-house, then the shredding service provider will not be considered as a data processor.

In the case of data stored in digital format, such data shall be permanently deleted. This would include any backups held on servers and/or cloud.

Communication between the client and the Group shall be deleted or destroyed.

Should the Group be required to change one or more of its hard drives where data is, or was previously stored, the Group shall ensure that such hard disk is disposed of in a professional manner and in a way that data cannot be retrieved from it in the future.

8.0 What are your Rights?

  1. You can obtain information regarding the processing of your personal information and access to the personal information which we hold about you by contacting us.
  2. You may request that any personal information be rectified by sending an e-mail notification on privacy@epicode.edu.mt – such information will be provided to you within 30 days. If due to complexities beyond our control we cannot provide you with your information within 30 days, we will inform you accordingly on the expected delay and will provide you with the information as soon as possible.
  3. You have the right to request that we erase your personal information if it is inaccurate or incomplete. There may be circumstances where you ask us to erase your personal information, but we are legally obliged to retain it. In such circumstances, we will inform you that your data cannot be deleted or erased and the reason for rejecting your request.
  4. You may object to, and request the processing of, your personal information in certain circumstances. There might be circumstances where you object to, or ask us to restrict, our processing of your personal information but we are legally entitled to refuse that request. In such cases, we will inform you on the reasons why your request is being rejected.
  5. You may instruct us at any time not to process your personal information for marketing purposes. We will always entertain such requests.
  6. You may withdraw your consent given to us to process your personal data (when consent is required) at any time by sending an e-mail notification on privacy@epicode.edu.mt
  7. Your personal information may only be stored unless further processing is brought about by individual consent and the necessity for the establishment of legal claims for the protection of the rights of another natural/legal person or for the public interest. We will always process your personal data when we have a legal basis for such processing in line with Article 6 and/or Article 9 of the GDPR – namely, if we are allowed by the regulation to process such data.
  8. You have a right to lodge a complaint to the supervisory authority of the jurisdiction in which the personal information is being provided. As an example, the contact details of the Data Protection Commissioner’s Office of Malta, the jurisdiction where one of our license is held, is being provided in section 9.2 below.
  9. You may request one printed copy of this Privacy Notice free of charge.

9.0 Where can you complain if you have an issue related to Data Privacy?

We value our customers’ comments and we are committed to ensure that all our clients’ data is safeguarded and in line with regulation and our internal policies. Should you feel the need to complain about, or raise your objections, to how we are handling your personal data, then you may contact us using the following contact details:

9.1 Contacting the Data Protection Officer

The company does not have a DPO. Instead you may contact us on privacy@epicode.edu.mt

The Group will do its utmost to ensure that complaints are handled and settled internally in an efficient and professional manner.

9.2 Contacting the Maltese Data Commissioner

You may also contact the Office of the Data Commissioner as follows:

  • You may file a complaint with the Maltese Data Protection Commissioner through the following link:

https://idpc.org.mt/raise-a-concern/

  • Alternatively, you may contact the office of the Maltese Data Commissioner by phone on +356 23287100 or by post using the below address:

The Commissioner: Mr Ian Deguara. Level 2, Airways House, High Street, Sliema, SLM 1549, Malta

  • If you are the Resident of another EU country rather than Malta, you may wish to contact your local Data Protection Commissioner as an alternative to the above.

 10.0 Can we modify this Privacy Notice?

From time to time, we may change this Privacy notice. If we change this Privacy notice, we will upload the updated privacy notice on our website, or by posting a notice on our homepage stating that a change has occurred. We shall write to you should there be a ‘material change’ in the Privacy notice which affects your rights.

This Privacy Policy is in conformity with applicable EU laws and regulations. The Company is liable only to the extent of the provisions set out under the applicable EU laws and regulations. Last updated in May 2025

11.0 Access to the full GDPR Regulations

You may wish to download, free-of-charge the GDPR regulations by clicking on the below link:

https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN