education4reel · privacy notice · 28 september 2026

your enquiry, your information.

this notice explains how samuel olagbaju’s personal student advisory service handles your enquiry.

who is responsible?

samuel olagbaju, trading as education4reel, is responsible for how this service uses your information. contact oef.lagos@gmail.com about your details or privacy rights.

what we collect and why

we collect your name, email, phone number, course interests, qualifications, study level, intake, country of residence, applicant route and university preferences to respond to your enquiry. a referrer is optional: please use a referral code or organisation rather than another person’s contact details.

we process your date of birth to check that you are at least 18, then discard it before saving the enquiry. we retain the age-check result and its date. this is a self-reported age check, not identity verification. please do not send passports, financial documents, health information or passwords through this website.

our purposes and lawful bases

for enquiry handling and relevant follow-up, our stated basis is legitimate interests in responding to a service you have requested. we limit contact to your enquiry, review the impact on you, and stop if you object. promotional email and whatsapp updates rely on separate, optional consent. choosing not to receive marketing does not prevent you from asking for advice.

we also have a legitimate interest in protecting the service against misuse, keeping minimal security records, and demonstrating how preferences and requests were handled. information is not sold, used for unrelated advertising or used to train an ai model by this application.

your choices

you can withdraw marketing consent or stop contact by emailing samuel, or by telling him in the conversation. withdrawing consent does not affect earlier lawful processing. marketing campaigns are not active. no university admission or eligibility decision is made automatically: course matching is a suggestion for human review.

who receives information?

enquiries are stored in samuel’s restricted workspace. the website does not send them to an education agency or university. if you choose to proceed with an application, we will explain which agency or institution will receive which information, why, and the relevant privacy notice before sharing. commercial recruitment arrangements must not prevent you from making an informed choice.

openai’s sites service and its cloudflare infrastructure host the website. supabase stores enquiries in a dedicated london (eu-west-2) database and manages adviser sign-in. pseudonymous abuse-prevention counters are held in cloudflare d1 for up to 24 hours. providers may process operational information internationally; london database storage does not mean all processing stays in the uk. the providers’ data processing terms describe their subprocessors and international-transfer safeguards, including applicable standard contractual clauses and uk provisions.

google docs, booking and payments

the cv viewer connects to google only when you select “load google docs view”. google may receive your ip address, browser information and google account cookies. you can instead open the document separately. google controls the document’s availability and its own processing; closing the viewer does not erase information google has already received.

booking and payment processing are not connected to this website yet. cal.com and stripe will have separate privacy information when activated. we will not collect card details in this enquiry form. this application adds no advertising pixels. optional visit counts are described below; hosting sign-in and optional external services may use their own cookies.

optional website visit counts

if you choose “allow counts” in visit preferences, we count landing-page views by mobile, tablet or desktop layout, tagged instagram or tiktok links, and approximate country when the hosting service provides it. we use these statistics to understand which layouts and channels need improvement. consent is the basis for this optional measurement. there is no visitor identifier, fingerprint, precise location or link to your enquiry. we do not store ip addresses in the analytics records, although hosting necessarily processes connections and abuse prevention uses temporary pseudonymous counters.

we store only combined daily totals, not individual visit histories. totals are reported for the latest 30 days; buckets older than 90 days are removed on the next counting request. your yes/no preference is stored on this device for 90 days without a unique identifier. change it at any time using “visit preferences” in the footer. stopping counts prevents future measurement; previously combined totals cannot be traced to you or individually removed. refusing has no effect on your enquiry.

how long we keep information

the retention schedule is 180 days for enquiries, measured from creation or the latest substantive contact; 90 days for saved social notes; 30 days for follow-up drafts; and 365 days for minimal accountability events. these are service policy choices, not periods set by uk gdpr. events contain action descriptions rather than student names or message text.

expired records are removed by a daily scheduled job and during workspace reviews. deleting a student also deletes related follow-up drafts from the active database. the adviser can download encrypted recovery copies with a seven-day retention policy. no separate automatic backup service is configured. deleted information is removed from the active application database; infrastructure-level retention follows the providers’ arrangements. any future legal need to retain a specific record will require a documented purpose and appropriate notice.

your rights and requests

you can ask for access, correction, deletion, restriction or a copy of your information, and object to processing based on legitimate interests. portability applies where its legal conditions are met. send a request to samuel’s email above. we will verify identity proportionately and normally respond within one month; if a permitted extension applies, we will explain it.

you can complain to the information commissioner’s office ↗. you may contact us first, but do not have to.

how we protect information

the dashboard uses managed adviser authentication with a second factor, server-side owner checks, database row-level policies, input limits, write-rate limits, encrypted website connections and non-caching responses. student passwords and application documents are not requested. the enquiry endpoint can accept submissions but cannot read student records. these controls reduce risk; they are not a guarantee of security or a certification of compliance.