Executive Summary: Oxford Creative Group Ltd. is committed to protecting user privacy, enforcing data minimization, and ensuring full compliance with the UK General Data Protection Regulation (UK GDPR), EU GDPR, and global data protection standards.

1. Identification of Data Controller

This Privacy Policy applies to all services, content, and interactive features offered on oxfordcreattivegroup.org, operated by Oxford Creative Group Ltd. (referred to herein as "Company", "We", "Us", or "Our").

Registered Office Address: Oxford Business Park, John Smith Drive, Oxford OX4 2JY, United Kingdom.
Data Protection Office Email: legal@oxfordcreattivegroup.org

2. Categories of Information Collected

When you navigate our website, interact with evaluation tools, or submit contact forms, we may collect the following categories of data:

3. Legal Bases & Purposes for Data Processing

We process personal data only when a valid legal basis exists under applicable data protection legislation:

  1. Legitimate Interests (Art. 6(1)(f) UK GDPR): To analyze site traffic trends, ensure network security, evaluate conversational AI services, and optimize user experience.
  2. Consent (Art. 6(1)(a) UK GDPR): For processing marketing communications, optional analytics cookies, and voluntary contact submissions. You maintain the right to revoke consent at any time.
  3. Legal Compliance (Art. 6(1)(c) UK GDPR): To satisfy statutory record-keeping requirements, age verification restrictions (18+ enforcement), and legal disclosures requested by competent authorities.

4. Data Minimization & Retention Schedules

We implement strict data minimization principles. Personal data collected via contact forms is retained only as long as necessary to address your specific inquiry or maintain audit records for up to 24 months, after which it is securely deleted or anonymized.

5. Sub-Processors & Data Transfer Standards

We do not sell, rent, or trade your personal information to third-party data brokers. Technical telemetry may be processed by contractually bound sub-processors delivering hosting, DDoS mitigation, and analytical security services under strict Data Processing Agreements (DPAs).

If data transfers occur outside the United Kingdom or European Economic Area (EEA), we enforce recognized transfer mechanisms such as the UK International Data Transfer Agreement (IDTA) or standard contractual clauses (SCCs).

6. Individual Rights Under UK GDPR

As a data subject, you possess enforceable rights regarding your personal information:

To exercise any of these rights, contact our Data Protection Officer at legal@oxfordcreattivegroup.org.

7. Security Measures & Revisions

We enforce technical safeguards including 256-bit TLS encryption, strict access permission scoping, and regular infrastructure security reviews. This Privacy Policy is subject to periodic updates to reflect regulatory or technical changes.