Privacy policy
What we collect, why we hold it, and how you get it back or have it deleted.
Last updated:
1. Who we are
Menés Academy (“we”, “us”) is a study-abroad consultancy assisting students with admission to universities in Europe. We work with applicants from many countries, and because the universities, scholarship bodies and consulates we deal with are located in the European Union, we handle your data to the standard set by the EU General Data Protection Regulation regardless of where you live.
For the purposes of the GDPR we act as the data controller for the personal data described in this policy. Data protection contact: .
2. What we collect
- Identity and contact details — name, date of birth, nationality, country and city of residence, email address, telephone number.
- Academic records — diplomas, transcripts, language certificates, CV and motivation letters.
- Application data — target universities and programmes, intake, application status and outcomes.
- Financial data for scholarship purposes — household income documentation required for the ISEE parificato and DSU applications. We do not collect or store card or bank credentials.
- Immigration data — passport details and visa documentation required for pre-enrolment and consular appointments.
- Account and technical data — authentication records, and standard server logs including IP address.
3. Why we hold it, and on what legal basis
- To perform our contract with you — preparing and submitting university, scholarship and visa applications on your behalf.
- Consent — where we transmit your documents to a university, regional scholarship body, consulate or translation provider. You may withdraw consent at any time, though doing so may make it impossible to continue your application.
- Legitimate interests — operating and securing the student portal, and improving our services.
- Legal obligation — retaining records required by accounting and tax rules.
4. Who we share it with
We share your data only where it is necessary to advance your application, and only with:
- Universities and their admissions offices;
- Regional scholarship bodies (for example ER.GO, DiSCo Lazio, EDISU Piemonte);
- Consulates, embassies and the Universitaly pre-enrolment portal;
- Sworn translators, CIMEA and legalisation services;
- Our infrastructure providers, who process data on our instructions under a data processing agreement.
We do not sell your personal data, and we do not share it with advertisers.
5. Where your data is stored, and international transfers
Our student portal and database are hosted by Supabase. Because our students apply from one country and study in another, your data will necessarily cross borders: your documents are sent to universities, regional scholarship bodies and consulates in the European Union, and may be processed on infrastructure outside your country of residence.
Where personal data leaves the European Economic Area, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. If your country has its own data-protection law that grants you additional rights, those rights are not reduced by this policy.
6. How long we keep it
- Enquiries that do not become clients — 24 months from last contact, then deleted.
- Student files — for the duration of your engagement and 5 years afterwards, so that we can support later visa renewals and reissue documents.
- Accounting records — for the period our accounting and tax obligations require, typically 10 years.
7. Your rights
You have the right to:
- Access the personal data we hold about you and receive a copy;
- Have inaccurate data corrected;
- Have your data erased where we no longer have a lawful basis to keep it;
- Restrict or object to processing;
- Receive your data in a portable, machine-readable format;
- Withdraw consent at any time;
- Complain to the data-protection authority in your own country, or to any EU supervisory authority where your data was sent.
To exercise any of these rights, write to . We respond within 30 days.
8. Security
Portal access requires a password, and every record is protected by database-level row security so that one student can never read another student's file. Uploaded documents are held in private storage and served only through short-lived signed links. Access by our staff is limited to the advisors assigned to your file.
9. Cookies
We use a single essential cookie to keep you signed in to the student portal. We do not use advertising or third-party tracking cookies. Fonts are loaded from Google Fonts, which receives your IP address as part of that request.
10. Applicants under 18
Our services are intended for applicants aged 16 and over. Where an applicant is under 18, we require a parent or legal guardian to be involved and to countersign the service agreement.
11. Changes
If we change this policy materially we will notify current students by email and update the date at the top of this page.