FourthRev Privacy Policy
Effective date: 6 August 2026
Version: 2.0
How FourthRev collects, uses, shares and protects personal information.
At a glance
| Item | Position |
|---|---|
| Who this policy is for | Website visitors, prospective and current learners, course applicants, employer and partner contacts, event attendees, and people who contact FourthRev. |
| What it covers | How FourthRev collects, uses, shares, stores and protects personal information across the United Kingdom, Australia and South Africa. |
| Main contact | privacy@fourthrev.com |
| Course-specific information | A course, partner, employer or collection form may provide additional privacy information. Read that information together with this policy. |
| Your choices | You can exercise applicable privacy rights, change marketing preferences, manage cookies and raise a complaint. |
Contents
- Executive summary
- Who we are and who is responsible
- Information we collect and its sources
- How and why we use information
- Sensitive information and reasonable adjustments
- Recordings, AI and automated processing
- Marketing and communications
- Who we share information with
- International transfers
- Security and data breaches
- How long we keep information
- Your rights and choices
- Cookies, complaints, contact and updates
1. Executive summary
FourthRev provides online education and career-development services with university, employer and industry partners. We use personal information to respond to enquiries, assess applications, enrol and support learners, deliver and improve courses, assess performance, issue awards, report to authorised employers and partners, protect our systems, comply with law and communicate about relevant services. We limit collection to what is reasonably necessary, use appropriate safeguards, and provide choices and rights under applicable law.
2. Who we are and who is responsible
The FourthRev entities, privacy roles and controller arrangements.
2.1 The FourthRev group
In this policy, FourthRev, we, us and our refer to the relevant FourthRev company that determines why and how your personal information is used. The FourthRev group includes:
- FourthRev Ltd, registered in England and Wales under company number 12333799, with registered office at Harwood House, 43 Harwood Road, London, England, SW6 4QP.
- FourthRev Pty Ltd, registered in Australia under ACN 632 361 061 and ABN 92 632 361 061, with registered address at 10 Oxley Road, Hawthorn, Victoria 3122.
- FourthRev Ltd, registered in South Africa as an external company under registration number 2022/237363/10, with registered address at 50 Sea Mist Crescent, Coral Grove, Milnerton, Cape Town, South Africa, 7441.
FourthRev delivers online courses and related learner, employer and partner services. We work with universities, awarding bodies, employers, industry organisations, instructors and other service providers.
2.2 Which entity is responsible
The responsible entity depends on the service, contract, location and decisions being made about the information:
- FourthRev Ltd in the United Kingdom generally manages the main FourthRev website, central marketing activity and group services, unless a collection notice says otherwise.
- FourthRev Pty Ltd is responsible where it contracts for or determines Australian processing activities.
- The South African external company is a responsible party where it determines processing activities in South Africa.
- For partner-delivered courses, FourthRev and the relevant university, employer or partner may act as independent controllers or responsible parties, joint controllers, or in a controller-processor relationship. The applicable course notice, enrolment terms or contract will explain the arrangement.
Where FourthRev and a partner are joint controllers, the parties allocate their responsibilities in an arrangement. A summary of the essence of that arrangement is available on request from privacy@fourthrev.com.
2.3 Privacy contacts and registrations
| Jurisdiction | Contact |
|---|---|
| United Kingdom | FourthRev Ltd is registered with the Information Commissioner under registration number ZA753319. Contact the UK Data Protection Officer through privacy@fourthrev.com. |
| Australia | Contact the Australian Privacy Officer through privacy@fourthrev.com. |
| South Africa | Information Officer: Jack Hylands. Deputy Information Officer: Ruan Swanepoel. Contact either officer through privacy@fourthrev.com. The FourthRev South Africa PAIA Manual is available through the privacy section of our website or on request. |
2.4 Additional notices
This policy is a general notice. Additional notices may apply to a particular course, partner arrangement, application form, event, research activity, cookie, employee, contractor or recruitment process. A more specific notice applies to that particular processing where it provides additional or different information.
3. Information we collect and its sources
The main categories of information and how FourthRev receives them.
3.1 What personal information means
Personal information includes information that identifies you directly and information that can reasonably be linked to you. The term includes personal data under United Kingdom data protection law and personal information under the Australian Privacy Act and South African POPIA.
3.2 Categories of information
| Type | What it includes | Usual source |
|---|---|---|
| Identity and contact | Name, preferred name, title, date of birth, learner or customer reference, employer, role, email address, telephone number and postal address. | You; a partner; employer; awarding body |
| Account and profile | Username, authentication credentials, profile picture, account settings, registered courses, community posts and messages. | You; platform activity |
| Application and eligibility | Application answers, education and employment history, goals, eligibility, admissions decisions and supporting documents. | You; partner; employer; authorised referrer |
| Identity documents | Passport, national identity document or other verification evidence where required for enrolment, examinations, funding, visas, awards or fraud prevention. | You; authorised verification provider |
| Course participation and performance | Attendance, engagement, progress, completion, assessment submissions, marks, feedback, academic-integrity records and support activity. | You; instructors; platform; partner; awarding body |
| Awards and credentials | Final result, certificate or credential details, issue date, expiry date and verification information. | Partner; awarding body; FourthRev |
| Communications and support | Enquiries, emails, calls, chats, complaints, feedback, support notes, safeguarding concerns and other information you choose to provide. | You; employer; partner; authorised representative |
| Recordings and transcripts | Audio, video, screen content, on-screen name, chat messages, call recordings, live-session recordings, transcripts and AI-generated summaries. | You; participants; recording and transcription tools |
| Accessibility and health | Reasonable-adjustment requests, accessibility needs, health or disability information and related evidence where necessary. | You; authorised representative; partner where appropriate |
| Payment and transaction | Payment status, invoices, transaction references, account-holder information and limited payment details. Card information may be handled directly by a payment provider. | You; employer; payment provider; finance systems |
| Survey and diversity | Survey responses and voluntary diversity information, including sensitive information where you choose to provide it. | You; partner where authorised |
| Marketing and engagement | Marketing preferences, communication history, event attendance, email opens, link clicks and campaign engagement. | You; cookies, pixels and communication tools |
| Technical, usage and location | IP address, browser, device, operating system, log-in time, audit logs, platform activity, cookie identifiers and approximate location inferred from an IP address. | Your device; website, platform and security tools |
| AI interaction data | Prompts, questions, uploaded content and outputs where you interact with an approved AI-enabled feature. | You; approved AI-enabled services |
| Legal, compliance and security | Consent records, contracts, complaints, legal correspondence, access logs, fraud indicators, incident records and evidence needed to protect rights or comply with law. | You; systems; advisers; authorities; partners |
3.3 Information you must provide
Some information is necessary to respond to an enquiry, assess an application, create an account, enter into or perform a contract, verify identity, deliver a course, provide an adjustment, issue an award or comply with law. If required information is not provided, we may be unable to process an application, enrol you, provide part of the service, verify an award or respond fully to a request. Information described as optional or voluntary is not required.
3.4 Information received indirectly
We may receive information from a university or industry partner, your employer, an awarding body, an authorised referrer, instructors, service providers, public professional sources or another person acting with authority. Where required, we or the organisation collecting the information will tell you about the collection.
3.5 Anonymous and aggregated information
We may remove identifying details and combine information to produce statistics and trends. Information that can no longer identify you is not treated as personal information. We do not attempt to re-identify properly anonymised information.
4. How and why we use information
Purposes, legal grounds and expected uses.
4.1 Our main purposes
| Purpose | Information used | Main UK lawful basis |
|---|---|---|
| Respond to enquiries and assess applications | Identity, contact, application, education and communications information. | Contract steps; legitimate interests in managing applications and services; consent where required. |
| Create accounts, enrol learners and deliver services | Identity, contact, account, application, course and transaction information. | Performance of a contract; legitimate interests where the customer is an organisation. |
| Deliver teaching, community and learner support | Account, participation, communications, recordings and support information. | Contract; legitimate interests in delivering safe and effective services. |
| Assess progress, academic integrity and course completion | Course activity, submissions, marks, attendance, identity and technical information. | Contract; legitimate interests in quality and integrity; legal or accreditation requirements where applicable. |
| Issue and verify awards or credentials | Identity, result, award and verification information. | Contract; legitimate interests in maintaining reliable credentials; legal or accreditation requirements. |
| Report to authorised employers and partners | Participation, attendance, progress, result and limited support information. | Contract and legitimate interests under the relevant business or partnership arrangement. Sensitive support information is not routinely shared unless necessary and lawful. |
| Provide accessibility and reasonable adjustments | Identity, communications, accessibility and health information. | Legal obligations; contract; explicit consent or another applicable sensitive-information condition. |
| Process payments and recover amounts due | Identity, contact, transaction, invoice and payment information. | Contract; legal obligation; legitimate interests in financial administration and debt recovery. |
| Operate, secure and improve our website, platform and services | Technical, usage, security, support, survey and aggregated information. | Legitimate interests in service delivery, security, fraud prevention, analytics and improvement; consent for non-essential cookies where required. |
| Investigate complaints, safeguarding matters and misuse | Identity, communications, support, course, technical and legal information. | Legitimate interests in protecting learners, staff, partners and services; legal obligations; legal claims. |
| Communicate service information and request feedback | Contact, account, course, communications and survey information. | Contract; legitimate interests in service administration and improvement. |
| Send marketing and event communications | Contact, preferences, enquiries and engagement information. | Consent, soft opt-in or legitimate interests where permitted by applicable marketing law. |
| Meet legal, regulatory, tax, accounting and contractual obligations | Relevant identity, transaction, course, security, legal and communications information. | Legal obligation; contract; legitimate interests; legal claims. |
| Manage corporate transactions and professional advice | Relevant business, contact, contract and due-diligence information. | Legitimate interests in obtaining advice, financing, restructuring or a sale; legal obligation. |
4.2 Australia and South Africa
Australian and South African privacy laws use different legal terminology from the United Kingdom. In those jurisdictions, FourthRev collects, uses and discloses personal information only where reasonably necessary for its functions or activities and where permitted by law, including on the basis of consent, contractual necessity, legal obligations, legitimate interests or other lawful grounds and exceptions.
4.3 Legitimate interests and new purposes
Where United Kingdom law permits us to rely on legitimate interests, we consider the purpose, necessity and likely impact on you. Our interests include delivering and improving education services, administering partner and employer relationships, protecting people and systems, preventing fraud, maintaining academic integrity, managing complaints and establishing or defending legal claims. We do not rely on legitimate interests where your rights and interests override ours. If we intend to use information for a materially different and incompatible purpose, we will identify a valid legal basis and provide additional information before doing so, unless law permits or requires the use without further notice.
5. Sensitive information and reasonable adjustments
Additional protection for health, disability, diversity and other sensitive information.
5.1 Sensitive and special-category information
Sensitive information can include health and disability information, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, biometric identifiers, sexual orientation and other information given additional protection by law. The precise definition differs by jurisdiction. We collect sensitive information only when it is necessary for a clear purpose and a valid legal condition applies.
5.2 Reasonable adjustments and accessibility
We may use health, disability or accessibility information to consider and implement reasonable adjustments, provide accessible learning, communicate with an authorised support person, protect health and safety, and meet anti-discrimination or other legal obligations. We limit access to people who need the information for the approved purpose.
5.3 Voluntary diversity information
Diversity questionnaires are voluntary unless a form clearly states otherwise. We generally use responses in aggregated form to understand participation and improve inclusion. We do not use voluntary diversity responses to make adverse admissions, assessment or employment decisions.
5.4 Safeguarding, emergencies and legal claims
Where necessary, we may process sensitive information to protect vital interests, respond to a safeguarding concern, establish or defend legal claims, comply with a legal obligation or meet another condition permitted by applicable law. We record the reason and apply proportionate safeguards.
5.5 Identity documents and biometrics
We request identity documents only where reasonably necessary for identity verification, examinations, funding, visa, accreditation, award or fraud-prevention requirements. We do not use biometric identification unless a specific service requires it and an additional notice explains the purpose and safeguards.
6. Recordings, AI and automated processing
How FourthRev uses recordings, transcription and AI-enabled services.
6.1 Calls and live sessions
FourthRev may record calls, webinars, teaching sessions or live support sessions for delivery, access, quality, training, safeguarding, note-taking and evidence purposes. We provide notice before or at the start of a recording. Where participation is optional, you can usually keep your camera and microphone switched off or use another contact method. Course-specific requirements may apply to assessments or identity checks.
6.2 Transcription and note-taking
Approved tools may create transcripts, summaries, action items or notes from calls and live sessions. These outputs can contain errors. Authorised personnel must review material information before relying on it for support, assessment, complaint handling or another decision affecting a person.
6.3 Artificial intelligence
FourthRev uses approved AI-enabled tools to support activities such as drafting, search, transcription, summarisation, classification, analytics, learner support and operational administration. AI tools are subject to access, confidentiality, supplier and data-protection controls appropriate to the use. Personnel must not enter personal or confidential information into an unapproved AI tool.
- AI output is reviewed by an authorised person where accuracy or impact matters.
- AI is not treated as an authoritative source merely because an output appears confident.
- Sensitive information is used with AI only where the tool, purpose, legal basis and safeguards have been approved.
- FourthRev does not sell learner information or authorise personnel to use it to train public AI models.
6.4 Automated decisions
FourthRev does not currently rely solely on automated processing to make decisions about learners that produce legal or similarly significant effects. If this changes, we will explain the information used, the kind of decision, the role of human review and the rights available before the processing begins. Automated tools may assist with routine routing, recommendations, risk indicators or administrative checks, but an authorised person remains responsible for material decisions.
6.5 Your information in AI features
Where you directly use an AI-enabled feature, the information you submit and the resulting output may be processed to provide the feature, maintain security, investigate misuse and improve the service within the limits described at collection. Do not submit information about another person unless you are authorised to do so.
7. Marketing and communications
How FourthRev communicates with individuals and business contacts.
7.1 Service communications
We send operational communications needed to manage an enquiry, application, enrolment, course, account, payment, event, policy update, support request or partner relationship. These are not marketing where they are necessary to provide the requested service or important information about it.
7.2 Marketing rules
| Location | How we market |
|---|---|
| United Kingdom | We use consent, the soft opt-in for similar services where all legal conditions are met, or permitted business-to-business marketing. Sole traders and certain partnerships are treated as individuals for electronic-marketing rules. |
| Australia | We send commercial electronic messages where there is express or reasonably inferred consent and the message meets identification and unsubscribe requirements. We also comply with the Australian Privacy Principles for direct marketing. |
| South Africa | We send unsolicited electronic marketing only where prior consent or the existing-customer exception applies, and we provide a clear opportunity to object or unsubscribe. |
| All locations | Every marketing message provides a straightforward way to opt out. We honour objections and retain a minimal suppression record where necessary to prevent further marketing. |
7.3 Business contacts
We may contact people in their professional capacity about an existing or prospective university, employer, supplier or industry relationship. We use professional contact details, keep communications relevant to the person’s role and respect objections.
7.4 Email engagement
Marketing and service emails may use links and pixels to measure delivery, opens, clicks, approximate location, email service and campaign performance. We use these technologies only as permitted by applicable law and subject to relevant consent or preference controls. You can disable non-essential tracking through available settings or contact us.
7.5 Marketing retention
If an individual marketing lead has no meaningful engagement with us for 18 months, we may ask whether they still wish to hear from us. If there is no response, we normally stop active marketing and delete or suppress the details by 24 months after the last meaningful engagement, unless another relationship or legal reason requires retention.
8. Who we share information with
Recipients, service providers and disclosure safeguards.
8.1 Recipient categories
| Recipient | Why information may be shared |
|---|---|
| FourthRev group personnel | Employees, workers, contractors and authorised personnel may access information on a need-to-know basis under confidentiality, security and role controls. |
| Universities, industry partners and awarding bodies | To administer applications, deliver courses, provide teaching, assess performance, issue awards, manage complaints and meet contractual or accreditation responsibilities. |
| Employers and organisational customers | Where an employer funds or sponsors participation, we may share agreed information such as enrolment, attendance, engagement, progress, completion and results. Sensitive support information is not routinely disclosed unless necessary and lawful. |
| Instructors, facilitators and support personnel | To deliver teaching, feedback, moderation, learner support, community management and safeguarding. |
| Technology and operational providers | To host websites and platforms, provide CRM, communications, forms, workflow automation, analytics, security, payments, support, video, transcription and other operational services. |
| AI-enabled service providers | To provide approved generative AI, chat, transcription, note-taking, analytics or embedded AI functionality under the applicable service terms and controls. |
| Professional advisers and insurers | For legal, audit, accounting, tax, insurance, security and other professional advice. |
| Authorities and regulators | Where required or permitted for legal, tax, regulatory, law-enforcement, safeguarding or security purposes. |
| Corporate transaction parties | To advisers, funders, investors or a prospective buyer in connection with financing, restructuring, merger, acquisition or sale, subject to confidentiality and lawful due diligence. |
8.2 Current service examples
Depending on the service and configuration, providers may include HubSpot, JustCall, Typeform, Zapier, n8n, Canvas, Google, Meta, LinkedIn, website and cloud-hosting providers, payment providers, video-conferencing providers, and approved AI services such as Claude, ChatGPT, JustCall AI, WINN.AI and Granola. The provider list changes as services are reviewed or replaced.
8.3 Roles and contracts
A recipient may act as FourthRev’s processor or operator, an independent controller or responsible party, or a joint controller, depending on the activity. We use appropriate processing, data-sharing, joint-controller, confidentiality and transfer terms for the relevant role. Providers acting on our instructions may use information only for the contracted service and authorised purposes, subject to applicable law.
8.4 Legal requests
If we receive a court order, warrant, regulatory demand or other legal request, we assess its validity, scope and impact before disclosing information. We seek legal advice where appropriate and disclose only what is reasonably required, unless law prevents us from telling you.
FourthRev does not sell personal information.
9. International transfers
Where information may be processed and how transfers are protected.
9.1 Transfer locations
FourthRev operates across the United Kingdom, Australia and South Africa and works with international partners and service providers. Personal information may therefore be accessed, stored or processed in those countries, the United States, countries in the European Economic Area and other locations in which an authorised partner, provider or subprocessor operates.
9.2 Transfer safeguards
| Origin | Safeguards |
|---|---|
| United Kingdom | We use an adequacy regulation or data bridge where available, or appropriate safeguards such as the United Kingdom International Data Transfer Agreement, the United Kingdom Addendum to standard contractual clauses, and any required transfer-risk assessment and supplementary measures. |
| Australia | We take reasonable steps under Australian Privacy Principle 8 before disclosing personal information to an overseas recipient, subject to the exceptions permitted by law. |
| South Africa | We transfer personal information outside South Africa only where the conditions in section 72 of POPIA or another applicable provision are met. |
| Contractual services | Contracts, access controls, encryption, data minimisation, supplier review and incident obligations may be used in addition to the legal transfer mechanism. |
9.3 Further information
You can contact privacy@fourthrev.com to ask about the countries and safeguards relevant to a particular service or transfer. We may provide a summary rather than commercially sensitive contractual terms.
10. Security and data breaches
How FourthRev protects information and responds to incidents.
10.1 Security measures
FourthRev uses proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, misuse, disclosure or access. Measures may include:
- role-based access, user authentication and multi-factor authentication;
- encryption in transit and, where appropriate, at rest;
- device, endpoint, network, cloud and security monitoring;
- logging, vulnerability management, testing and incident response;
- staff and contractor confidentiality obligations, policies and training;
- supplier assessment, data-protection terms and access restrictions;
- backups, business continuity and disaster-recovery arrangements; and
- data minimisation, retention controls and secure deletion or anonymisation.
No system is completely secure. You are responsible for protecting your credentials, using appropriate device security and reporting suspected compromise promptly.
10.2 Security incidents
We investigate suspected security incidents, take steps to contain and remediate them, preserve appropriate evidence and assess the effect on individuals. Where FourthRev is the controller or responsible party, we notify the relevant regulator and affected individuals when applicable law requires it. Where FourthRev acts as a processor or operator, we notify and support the relevant controller or responsible party.
10.3 Reporting concerns
Please contact privacy@fourthrev.com immediately if you notice unusual activity, receive a suspicious communication, believe your account has been compromised, or think personal information has been sent to the wrong person.
11. How long we keep information
Retention periods and deletion criteria.
11.1 Our approach
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, partner or accreditation requirements, legal claims, security, tax, accounting and regulatory obligations. We then delete, securely destroy or anonymise it.
11.2 Typical retention periods
| Category | Typical period or criteria |
|---|---|
| Learner account and core course information | Normally up to 3 years after the learner last accesses the account or the course relationship ends, whichever is later, unless a partner, accreditation, complaint, legal or contractual requirement justifies longer retention. |
| Recordings and transcripts | For as long as needed to deliver and support the course, call or event and then according to the applicable recording schedule. A specific course notice may state a different period. |
| Award verification | The minimum information needed to verify a qualification or credential may be kept long term and, where necessary, indefinitely, subject to periodic review. |
| Website enquiries and individual marketing leads | Normally 2 years from the last meaningful engagement. A minimal suppression record may be kept longer to honour an opt-out. |
| Financial and payment records | Normally 6 years after the end of the relevant financial year and up to 7 years where a longer legal requirement applies. |
| Website and communication analytics | For the duration stated in the relevant cookie or technology setting, normally no longer than 2 years. |
| Prospective or former partner contacts | Reviewed at least annually and removed or updated when no longer relevant. |
| Complaints, safeguarding, legal and security records | For the life of the matter and the applicable limitation, regulatory, evidence or risk-management period. |
11.3 Backups and legal holds
Deleted information may remain temporarily in secure backups until it is overwritten through the normal backup cycle. We may suspend deletion where information is subject to a complaint, investigation, litigation hold, regulatory requirement or another lawful preservation need.
12. Your rights and choices
How to access, correct, delete or object to the use of information.
12.1 Making a request
Email privacy@fourthrev.com and describe what you need. You do not have to use legal wording. We may ask for information reasonably necessary to verify your identity, authority and the scope of the request. Rights are not absolute and may be limited by law, another person’s rights, confidentiality, legal privilege, academic integrity, regulatory duties or a valid retention need.
12.2 Rights by jurisdiction
| Jurisdiction | Main rights |
|---|---|
| United Kingdom | Access; correction; erasure; restriction; objection; data portability where applicable; withdrawal of consent; direct-marketing objection; and safeguards concerning qualifying automated decisions. You may complain to the Information Commissioner’s Office. |
| Australia | Access to and correction of personal information; a privacy complaint; direct-marketing opt-out; and, in relevant cases, information about the source of marketing information. You may complain to the Office of the Australian Information Commissioner. |
| South Africa | Access; correction or deletion; objection to processing; withdrawal of consent; direct-marketing rights; protections concerning automated decisions; and a complaint to the Information Regulator. Access to records may also be requested under PAIA. |
| All locations | You can unsubscribe from marketing at any time and change non-essential cookie choices through Cookie Settings. |
12.3 Response periods and fees
We respond within the period required by the law that applies. United Kingdom requests are generally answered within one month, subject to a permitted extension. Australian access or correction requests are generally answered within 30 days. South African requests are handled within the applicable POPIA or PAIA period. Requests are usually free. We charge a fee only where law permits it and tell you in advance.
12.4 Requests relating to a partner
If another organisation is responsible for the information or FourthRev holds it only as that organisation’s processor or operator, we may refer the request to that organisation or respond under its instructions. We will explain this where we can.
12.5 Withdrawing consent
Where we rely on consent, you may withdraw it at any time. Withdrawal does not make earlier lawful processing unlawful. It may affect our ability to provide an optional feature, communication or service that depends on the consent.
13. Cookies, complaints, contact and updates
Online technologies, escalation routes and policy changes.
13.1 Cookies and similar technologies
Our website, platform and communications use cookies, pixels, tags, local storage and similar technologies. These can keep you signed in, remember preferences, protect accounts, measure use, improve services and support relevant advertising.
| Category | Purpose |
|---|---|
| Strictly necessary | Security, authentication, network management, load balancing and functions needed for the service to work. These technologies do not require consent where the law provides an exemption. |
| Functional | Remember choices and provide enhanced features. |
| Analytics | Understand visits, platform use, performance and service improvement. |
| Advertising and social media | Measure campaigns, limit repetition and provide relevant advertising or social-media features. |
| Email and communication tracking | Measure delivery, opens, clicks and engagement where permitted. |
Non-essential technologies are used only after the required permission has been obtained. The cookie banner allows you to accept or reject non-essential categories and Cookie Settings allows you to change your choice. Your browser or device may also provide controls. Blocking some technologies can reduce functionality.
Third-party technologies may include Google Analytics, Meta, LinkedIn, HubSpot and our website, learning, communication and hosting providers. The current cookie list, provider, purpose and duration are available through Cookie Settings or the Cookie Notice on our website.
13.2 Contact FourthRev
| Contact | Detail |
|---|---|
| Privacy enquiries and rights requests | privacy@fourthrev.com |
| United Kingdom | FourthRev Ltd, Harwood House, 43 Harwood Road, London, England, SW6 4QP. Contact the UK Data Protection Officer through the privacy email address. |
| Australia | FourthRev Pty Ltd, 10 Oxley Road, Hawthorn, Victoria 3122. Contact the Australian Privacy Officer through the privacy email address. |
| South Africa | FourthRev Ltd, 50 Sea Mist Crescent, Coral Grove, Milnerton, Cape Town, 7441. Information Officer: Jack Hylands. Deputy Information Officer: Ruan Swanepoel. |
| PAIA | The FourthRev South Africa PAIA Manual and request information are available through the privacy section of our website and from privacy@fourthrev.com. |
13.3 Complaints
Please contact us first so that we can investigate and try to resolve the concern. Include enough information for us to understand the issue and the outcome you seek. We may ask for clarification or identity verification. If you remain dissatisfied, you may contact the regulator that applies to you:
- United Kingdom: Information Commissioner’s Office, ico.org.uk.
- Australia: Office of the Australian Information Commissioner, oaic.gov.au.
- South Africa: Information Regulator, inforegulator.org.za.
13.4 Changes to this policy
We review this policy at least annually and sooner when our services, technologies, partners, legal obligations or information practices change materially. We publish the current version on our website and update the effective date. We take reasonable steps to bring material changes to your attention before or when they take effect, for example by email, an account notice or a website message.
13.5 Version record
| Version | Effective date | Summary |
|---|---|---|
| 2.0 | 6 August 2026 | New consolidated group privacy policy replacing the version dated 29 July 2021. Updated for United Kingdom, Australian and South African requirements, current service providers, AI-enabled processing, recordings, international transfers, retention and jurisdiction-specific rights. |