admitAI is a software platform operated by 24 IT Solutions Ltd, a company registered in England and Wales, with its registered office in London, United Kingdom. In this policy "we", "us" and "our" mean 24 IT Solutions Ltd.
We provide software to student recruitment agencies. Those agencies use our platform to manage their students' applications to universities. This distinction matters a great deal for how data protection law applies to us, so we set it out in full in the next section.
We act in two different capacities depending on whose data is involved.
For that data, we decide why and how it is processed, and this policy governs it directly.
If you are a student whose data an agency holds in admitAI, the agency — not us — is responsible for how your data is used, and you should direct your requests to them in the first instance. We will assist them in responding to you. Our obligations to agencies in this role are set out in our Data Processing Addendum.
The categories below are typical of what agencies upload. The precise scope is determined by each agency, not by us.
Some of this is special category data or criminal offence data under UK GDPR — for example, health information disclosed in a visa context, or details of a prior immigration refusal. Agencies are responsible for ensuring they have an appropriate condition for processing it, and we handle it under the additional safeguards described in section 10.
| Processing | Lawful basis |
|---|---|
| Providing the platform to an agency | Performance of a contract |
| Billing and financial records | Contract, and legal obligation for retention |
| Security monitoring and audit logging | Legitimate interests — protecting the service and our customers' data |
| Product analytics and improvement | Legitimate interests — improving a service you use |
| Service and security notices | Contract, and legitimate interests |
| Marketing email to prospective customers | Consent, or legitimate interests in a business context under PECR |
| Non-essential cookies | Consent |
| Student data processed for an agency | Determined by the agency as controller; we act on their instructions |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can ask us for that assessment.
Parts of the platform use large language models and optical character recognition to generate assessment reports, read uploaded documents, draft messages and score leads. Three commitments apply, and we consider all three to be non-negotiable.
Our current AI sub-processor is listed on our sub-processors page, which we keep up to date.
We do not sell personal data. We share it only in these circumstances:
We host customer data in the United Kingdom and the European Economic Area. Some of our sub-processors operate outside the UK. Where personal data is transferred beyond the UK, we rely on UK adequacy regulations where they exist, and otherwise on the International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Our sub-processors page records the location and transfer mechanism for each.
| Data | Retention |
|---|---|
| Agency account data | Duration of the contract, then 12 months |
| Student data held for an agency | As instructed by the agency; deleted within 30 days of contract termination unless they ask for it sooner |
| Uploaded documents | As instructed by the agency; erasure requests actioned within 24 hours |
| Billing and financial records | 7 years, as required by UK tax law |
| Security and audit logs | 12 months |
| Support correspondence | 3 years from last contact |
| Marketing contact data | Until you unsubscribe, then a suppression record only |
| Website analytics | 14 months |
Backups are encrypted and cycle out on a rolling 35-day schedule, so deleted data may persist in backup for up to 35 days before it is overwritten. It is not restored into live systems during that period.
No system is perfectly secure, and we will not tell you otherwise. What we commit to is proportionate measures, honest disclosure when something goes wrong, and no quiet handling of incidents.
Under UK GDPR you have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis we rely on. You also have the right not to be subject to solely automated decisions with legal or similarly significant effects — and as set out in section 6, we do not make them.
If you are an agency user, contact us directly at privacy@admitai.io and we will respond within one month.
If you are a student, contact the agency handling your application — they control your data. If they cannot help, or you cannot reach them, write to us and we will do what we can within our role as processor.
We do not charge for responding, and we will not make you justify the request.
This website uses only what is necessary to make it work. We do not run advertising trackers, and we do not share visitor data with ad networks.
| Type | Purpose | Consent needed |
|---|---|---|
| Essential | Session management, security, load balancing, and remembering your cookie choice | No |
| Analytics | Aggregate page views and navigation paths, so we can see which pages are useful | Yes |
| Advertising | Not used | — |
Within the platform itself, we use only essential cookies. You can clear or block cookies through your browser, though blocking essential ones will stop the platform working.
The platform is sold to businesses and is not intended for direct use by children. Agencies do sometimes handle applicants under 18. Where they do, the platform requires a guardian consent record to be on file before any application can be submitted, as part of our compliance monitoring. Responsibility for obtaining that consent rests with the agency as controller.
We will update this page when our processing changes. For material changes affecting customers, we give at least 30 days' notice by email before they take effect. The version number and effective date at the top of this page always reflect the current text.
For any privacy question or to exercise a right, write to privacy@admitai.io, or by post to the Data Protection Lead, 24 IT Solutions Ltd, London, United Kingdom.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right, but you are under no obligation to.
We will answer plainly, including the parts that are still in progress. Security reviews and DPIA questionnaires are welcome before you buy, not just after.