World ReadyWorld Ready
For Recruiters For Institutions Product Pricing Compare FAQ
Request a demo
← Legal policy · privacy

Privacy Policy.

  • Effective 1 September 2026
  • Version 1.0
  • World Ready Pte Ltd

Read this first. This policy covers personal data we decide what to do with — data about people who visit our website and people who use our platform on behalf of an organisation. It does not cover the student and applicant records our customers put into the platform. Those belong to our customers, not to us. Section 3 explains that split, and it is the most important section here.

contents
  1. 1Who we are
  2. 2What this covers
  3. 3What this does not cover
  4. 4What we collect
  5. 5Why we use it
  6. 6Cookies
  7. 7Who we share it with
  8. 8Where it goes
  9. 9How long we keep it
  10. 10How we protect it
  11. 11Your rights
  12. 12Regional information
  13. Australia
  14. EEA and United Kingdom
  15. Singapore
  16. 13Changes
  17. 14Contact
Contents
  1. 1Who we are
  2. 2What this covers
  3. 3What this does not cover
  4. 4What we collect
  5. 5Why we use it
  6. 6Cookies
  7. 7Who we share it with
  8. 8Where it goes
  9. 9How long we keep it
  10. 10How we protect it
  11. 11Your rights
  12. 12Regional information
  13. Australia
  14. EEA and United Kingdom
  15. Singapore
  16. 13Changes
  17. 14Contact

1.Who we are

World Ready Pte Ltd ("World Ready", "we", "us") is incorporated in Singapore, UEN 202406764D, registered office 200 Jalan Sultan, #11-01, Textile Centre, Singapore 199018.

We publish worldready.ai and license the World Ready platform — a white-labelled operations system used by international student recruitment businesses and by education providers to manage institution partnerships, agency networks, admission workflows and commissions. We also sell Course Data, a subscription to structured course and provider information.

We are a software company. We are not an education agent, a recruitment agency, a migration agent, a registered immigration adviser, a law firm, an education provider or a financial institution. We do not recruit students, and we do not decide who gets an offer, an enrolment or a visa.

Contact us about privacy

RoleDetails
Data Protection OfficerVienne Baker
Emailprivacy@worldready.ai
Security reportssecurity@worldready.ai
Post200 Jalan Sultan, #11-01, Textile Centre, Singapore 199018

2.What this policy covers

In short: data about you — as a visitor, an enquirer, a named platform user, or a job applicant.

This policy applies to personal data we handle as the organisation deciding what happens to it (a "controller" under Australian, EU and UK law; under Singapore law, the organisation carrying the obligations):

  • Website visitors — people who browse worldready.ai.
  • Enquirers — people who request a demo, email us, or talk to us about buying.
  • Platform users — the named individuals our customers invite in: admins, counsellors, branch staff, provider staff. This covers your account, authentication, configuration and service-usage records, which our Terms call Service Data.
  • Suppliers, partners and job applicants.

Where Service Data is also surfaced inside a customer's tenant — for example the audit history a customer relies on for its own compliance — the customer may use and retain it under its own policies. Our handling is governed by this policy; theirs by theirs.

3.What this policy does not cover

In short: the student and applicant records inside a customer's tenant are that customer's data, not ours. If you are a student and want to know what is held about you, ask the agency or institution you dealt with — not us.

This policy does not apply to personal data our customers, or the users they invite, enter into the platform about other people — prospective and enrolled students and their families, sub-agents and counsellors, institution contacts, and anyone else in a customer's records. Our Terms call all of it Customer Data.

For Customer Data:

  • Our customer controls it. They decide what to collect, why, how long to keep it, who may see it, and what to tell the people concerned.
  • We process it only on their instructions, under the Data Processing Terms in Schedule 1 of our Terms of Service. Singapore law calls us a data intermediary; Australian, EU and UK law call us a processor. Same idea: we hold the data, we do not own it, and we do not decide about it.
  • We do not use it for our own purposes. We do not sell it, we do not market from it, and we do not use it to train, fine-tune, evaluate or benchmark any machine-learning model.
  • If you are a student or applicant with a request — access, correction, deletion, or a complaint — contact the recruitment business or education provider holding your file. They can answer it; we cannot lawfully act on their data without their instruction. If you write to us and we can identify the relevant customer, we will pass your request to them and tell you we have done so.

If you are a customer: before you put other people's personal data into the platform, you must have the right to do so, and you must have told those people what you are doing — including that their data is handled by a service provider outside their country, and naming World Ready so they can find this policy. Because the platform is white-labelled, a student sees only your brand; if you don't name us, they have no way to understand where their data sits. That requirement is in Schedule 1 §3.2 of our Terms.

4.What we collect, and how

CategoryWhat it includesWhere it comes from
Identity and contact Name, business email, phone, job title, employer, country You give it to us — demo requests, emails, contracts, support tickets
Account and profile Username, tenant and role assignments, permission set, password (stored as a salted hash — we never see or store the password itself), multi-factor settings where enabled, display preferences Created when your organisation invites you; maintained by your organisation's administrators
Usage and audit Pages and records viewed, actions taken, records created or changed, sign-in and sign-out events, IP address, browser and device type, timestamps Generated as you use the platform. Much of it forms the read-only audit history your organisation relies on for its own compliance
Support and communications Emails, tickets, chat messages, call and meeting notes, and attachments You send it to us
Commercial Subscription and contract details, purchase orders, invoices, payment records, billing contacts You or your organisation give it to us; some comes from our accounting system
Website Pages visited, referring site, approximate location derived from IP, forms started or completed Collected by our website — see section 6
Recruitment CV, work history, right to work, interview notes, references You give it to us if you apply for a job

We do not deliberately collect sensitive categories of data about you in your capacity as a user or visitor — no health data, no racial or ethnic origin, no religious beliefs, no biometrics. If you volunteer something like that in a support message, we treat it as confidential and delete it when it is no longer needed.

Children. The platform is a business tool licensed to organisations. We do not knowingly create accounts for anyone under 18, and the website is not directed at children. Separately, Customer Data may include records about people under 18 — student applicants often are. Those records are our customers' responsibility under section 3, and we apply the same controls to them as to any other Customer Data, without exception.

5.Why we use it, and on what basis

PurposeBasis (EU/UK terms, where relevant)
Creating and managing accounts; authenticating users; applying permissionsPerformance of the contract with your organisation
Delivering, maintaining and supporting the platformPerformance of contract; legitimate interests
Security — detecting and investigating unauthorised access, abuse and fraud; maintaining audit trailsLegitimate interests; legal obligation
Service communications — outages, security notices, changes to terms. You cannot opt out of these while you hold an accountPerformance of contract; legal obligation
Billing, collections, tax and statutory accountingPerformance of contract; legal obligation
Improving and developing the platform, using usage data aggregated or de-identified where that is compatible with the purposeLegitimate interests
Marketing to business contacts. Every message has an unsubscribe link and we honour itConsent where required, otherwise legitimate interests
RecruitmentLegitimate interests; consent
Complying with the law; establishing or defending claimsLegal obligation; legitimate interests

What we don't do. We don't sell personal data. We don't share it with third parties for their own marketing. We don't make decisions about you by automated means that have legal or similarly significant effects.

6.Cookies and similar technologies

Our website uses strictly necessary cookies and local storage only — the small amount of state needed to serve pages, remember your display preferences, and protect our forms from abuse. These do not require consent.

We do not use advertising cookies, and we do not sell or share your browsing data with advertising networks.

If we introduce analytics or any other non-essential technology, we will update this section and ask for your consent where the law requires it, before we set anything.

Your browser lets you block or delete cookies. Blocking strictly necessary cookies may stop parts of the site working.

7.Who we share it with

In short: the suppliers who help us run the service, our advisers, whoever the law compels us to tell, and a buyer if the business is ever sold. Nobody else.

  • Sub-processors and suppliers. Every third party that handles personal data on our behalf is named — with its purpose and its country — on our Sub-processor list. That list is the single source of truth. Each is bound by a written contract limiting it to what we instruct. We give at least 30 days' notice before a new one starts (Schedule 1 §6 of our Terms).
  • Your own organisation. If your employer created your account, its administrators can see your account details and your activity in the audit history. That is by design — it is how they meet their own obligations.
  • Professional advisers — accountants, auditors, insurers and lawyers, under duties of confidence.
  • Authorities, where legally required. We tell you unless prohibited or where it would prejudice an investigation. We disclose the minimum the request requires and push back on requests that appear overbroad or unlawful.
  • A successor, if we merge, are acquired or sell part of the business. We will give notice and require any successor to continue protecting your personal data.

8.Where your data goes

World Ready Pte Ltd is incorporated in Singapore. Our personnel access personal data from Australia and Singapore. The hosting regions for the standard multi-tenant platform, and the country of every supplier, are listed on our Sub-processor list.

Dedicated and customer-hosted deployments. Some customers run the platform in their own cloud account or a dedicated environment. Where that applies to you, the hosting location, infrastructure and backup arrangements are those stated in your Order Form, and the locations on the Sub-processor list do not describe your deployment.

Wherever data goes, we require it to be protected by legally enforceable obligations comparable to those it had at home — normally a written contract on our standard terms, and for EEA or UK data the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum. For Australian customers, our contractual commitments are designed to help you meet APP 8, on the understanding that under s 16C of the Privacy Act 1988 you remain accountable for what we do — which is why our Data Processing Terms are written to be worth relying on.

Transfers of Customer Data are governed by the Data Processing Terms, not by this policy.

9.How long we keep it

DataRetention
Account and profileWhile the account is active, then 90 days after deactivation
Usage and security logs12 months
Audit history surfaced inside a tenantFor that customer's own retention period, which the customer sets
Support and correspondence24 months after the matter closes
Contracts, invoices, accounting recordsAs long as Singapore law requires — at least 5 years under the Companies Act and the Income Tax Act
Marketing contactsUntil you unsubscribe or ask us to delete you, then a minimal suppression record so we don't email you again by accident
Unsuccessful job applications12 months, or longer with your consent
Customer DataPer Schedule 1 §11 of our Terms and your organisation's own settings — not per this table

When a period ends we delete the data or de-identify it so it can no longer be linked to you. Backups roll off on their own cycle, which may run slightly longer; we don't restore a backup to bring deleted personal data back into service.

10.How we protect it

Our controls are set out in full, and honestly, in our Security Overview — including what we have, what we rely on our cloud provider for, and what we don't have yet. We hold no SOC 2 or ISO 27001 certification, and we will not imply otherwise. Our published position on claims we won't make is at /no-claims/.

No system is perfectly secure. We commit to appropriate measures, not to a guarantee.

Reporting a vulnerability. Email security@worldready.ai. We will acknowledge it, we won't pursue good-faith researchers who use that route, and we would much rather hear from you than read about it.

Data breaches. If a breach affects personal data we control, we assess it promptly and notify the Personal Data Protection Commission of Singapore and affected individuals where the PDPA requires it. Where Australian, EU or UK law applies, we meet those obligations too. If a breach affects Customer Data, our duty runs to the customer controlling it — we notify them within the timeframe committed in Schedule 1 §9 of our Terms, so they can meet their own deadlines.

11.Your rights

Depending on where you are, you may have the right to: access the personal data we hold about you and be told how we use it; correct it; delete it, where we have no overriding reason or legal duty to keep it; restrict or object to our using it, including objecting to direct marketing at any time — for marketing we will always stop; withdraw consent where consent is what we relied on; receive a copy in a portable, machine-readable format and, where technically feasible, have it transmitted to another provider; and not be subject to a solely automated decision with legal or similarly significant effects — we don't make any about you.

How to exercise them: email privacy@worldready.ai. We acknowledge promptly and respond within 30 days. Where the law applying to your request allows a longer period or an extension, we will tell you and rely on it only where we actually need it. We may need to verify your identity and will ask for the minimum that does the job. We do not charge, except where the law permits a fee for an access request and the request is manifestly excessive or repetitive — and we will tell you before charging anything.

If you are a student or applicant: see section 3. Your request needs to go to the agency or institution holding your file.

Complaints. Tell us first: privacy@worldready.ai. We would rather fix it than be reported. If you're not satisfied: Singapore — Personal Data Protection Commission, pdpc.gov.sg · Australia — Office of the Australian Information Commissioner, oaic.gov.au · UK — Information Commissioner's Office, ico.org.uk · EEA — your local supervisory authority.

12.Regional information

Australia

Where the Privacy Act 1988 (Cth) applies to our handling of personal data, we handle that data in accordance with the Australian Privacy Principles. This section assists our Australian customers and their students; it is not an admission as to whether the Act applies to World Ready Pte Ltd in any particular case.

  • What we hold and how we collect and hold it: sections 4 and 5. Access and correction: section 11. Complaints: section 11.
  • Overseas disclosure (APP 8.1): we are a Singapore company and disclose personal data to sub-processors in the countries named on the Sub-processor list.
  • Automated decision-making: we do not make automated decisions about individuals that could reasonably be expected to significantly affect their rights or interests. Our customers may use platform output to inform their own decisions about students; those are the customer's decisions, and the customer's disclosure obligations.
  • Notifiable Data Breaches: see section 10.

European Economic Area and United Kingdom

Where the GDPR or UK GDPR applies to our own processing: our lawful bases are in section 5; legitimate interests are relied on only after balancing them against your rights, and we will share that assessment on request; transfers out of the EEA/UK rely on Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, with a transfer risk assessment on file; and you may complain to your supervisory authority (section 11).

We do not currently have an EU or UK establishment or an Article 27 representative. If we appoint one, we will name them here.

Singapore

The PDPA applies to us in full as an organisation for the data described in section 2, and in part — the Protection Obligation, the Retention Limitation Obligation and the data breach notification obligations — for Customer Data we handle as a data intermediary. Our DPO's contact details are in section 1.

13.Changes to this policy

We update this policy when what we do changes. Every version carries a date, and previous versions are available on request from privacy@worldready.ai.

If a change materially and adversely affects how we handle personal data about you, we give at least 30 days' notice by email to account holders and by notice on the website before it takes effect. If you don't accept it, you may terminate your subscription before it takes effect and we will refund fees pre-paid for the unused period, as set out in clause 18 of our Terms.

14.Contact

World Ready Pte Ltd (UEN 202406764D) · 200 Jalan Sultan, #11-01, Textile Centre, Singapore 199018
Privacy privacy@worldready.ai · Security security@worldready.ai · General hello@worldready.ai

World ReadyWorld Ready
Product For providers For recruiters Pricing Compare FAQ Privacy Terms Legal What we won't claim Request a demo hello@worldready.ai

World Ready Pte Ltd (UEN 202406764D) · Singapore. Every feature described on this site traces to the platform's help documentation; nothing here is aspirational. Pricing shown is the proposed subscription model.