Privacy Policy

Ontex Academy – Privacy Policy



Effective Date: 10 October 2025
Last Updated: 10 October 2025



Introduction



Ontex BV, headquartered in Belgium, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in compliance with applicable laws in the UK, Germany, Italy, Belgium, France, Australia, and Poland.



What Personal Data We Collect



We collect personal data when you interact with our website, register, purchase products, or contact support. This includes:



  • Name, email, phone number, address, country, language, birth year, gender
  • Payment information
  • Device and browser data
  • Social media interactions


Legal Basis for Processing



We process personal data based on:



  • Consent (e.g., marketing communications)
  • Contractual necessity (e.g., order fulfillment)
  • Legal obligations (e.g., tax compliance)
  • Legitimate interests (e.g., website security), provided these do not override your fundamental rights


Data Retention



We retain personal data only as long as necessary for the purposes collected, or as required by law. You may contact us for specific retention details.



Cookies and Tracking



We use cookies and similar technologies to improve user experience and site performance. See our Cookie Policy for details.



Your Rights



You have the right to:



  • Access and correct your data
  • Request deletion or restriction
  • Object to processing
  • Data portability
  • Withdraw consent
  • Lodge complaints with your national data protection authority


We aim to respond to all rights requests within 30 days. In some cases, we may request additional information to verify your identity.



Third-Party Sharing



We share personal data with:



  • Ontex affiliates for operational purposes (e.g., order fulfillment, support)
  • Service providers (e.g., IT, payment processors) under Data Processing Agreements (DPAs) that ensure confidentiality, security, and compliance with applicable laws


We conduct Data Protection Impact Assessments (DPIAs) where required, especially when introducing new technologies or high-risk processing. We ensure accountability for onward transfers by requiring all third parties to adhere to equivalent data protection standards.



International Transfers



We may transfer personal data outside the European Economic Area (EEA) and the United Kingdom. To ensure adequate protection, we implement:



  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) or UK Addendum to SCCs
  • Binding Corporate Rules (BCRs) where applicable
  • Transfer Impact Assessments (TIAs) in line with Schrems II guidance
  • Adequacy decisions where applicable (e.g., for countries recognized by the EU/UK as providing adequate protection)


You may request a copy of the relevant safeguards by contacting us.



Children’s Privacy



Our services are not intended for children under the age of digital consent, which varies by country:



  • UK: 13
  • Germany: 16
  • Italy: 14
  • Belgium: 13
  • France: 15
  • Australia: 15
  • Poland: 16


We do not knowingly collect data from children below these ages without verifiable parental consent. We use age verification mechanisms during registration and delete any data collected in violation of this policy. If you believe we have collected such data, please contact us immediately.



Disclosure to Law Enforcement



We may disclose personal data to law enforcement, regulators, or government agencies only when:



  • Required by law or court order
  • Necessary to comply with legal obligations
  • Proportionate and limited to what is strictly necessary


All such disclosures are documented and assessed for compliance with Article 48 GDPR, national laws, and relevant case law (e.g., Schrems II).



Security



We implement a range of technical and organizational measures to protect your personal data, including:



  • Encryption of data in transit and at rest
  • Access controls and role-based permissions
  • Regular security audits and vulnerability assessments
  • Incident response plans and breach notification procedures
  • Data minimization and secure disposal practices


Despite our efforts, no system is 100% secure. We encourage users to take precautions when sharing personal data online.



Contact and Complaints



If you have questions or concerns about this policy or your data, contact:



Ontex BV
Genthof 5, 9255 Buggenhout, Belgium
Email: dataprotection.uk@ontexglobal.com



Updates



We may update this policy to reflect legal, technical, or operational changes. The latest version will always be available on our website. We encourage you to review it periodically.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.