top of page

Privacy Policy

STEP UK

Privacy Policy


Updated on: 27/11/2025

STEP UK (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains how we collect, use, store, and share your information when you register, purchase a test bundle, access the test portal, or communicate with our team.

By using our website and services, you agree to the practices described in this policy.

1. Who We Are

STEP UK is an English language testing provider offering online English proficiency assessments and optional certification services.

Data Controller:
STEP UK
Email: support@step-uk.com
Website: www.step-uk.com

We follow the UK General Data Protection Regulation (UK GDPR).

2. Data We Collect

We collect the following categories of personal data:

A. Information You Provide

  • Full name

  • Email address

  • Phone number (optional)

  • Country of residence

  • Account login details

  • Profile photograph (required for identity verification)

  • Payment confirmation (from the payment processor, not card details)

  • Test submissions and recorded responses

  • Support inquiries or emails you send us

B. Automatically Collected Data

  • IP address

  • Device and browser information

  • Login times and test activity logs

  • Security monitoring data (fraud or misconduct detection)

C. Payment Information

All payments are processed securely through third-party providers such as Stripe or Zoho Commerce.
We do not store or have access to your full card details.

3. How We Use Your Information

We use your data for the following purposes:

  • To create and manage your STEP UK account

  • To process test bundle purchases

  • To send instructions, test dates, reminders, and important updates

  • To verify your identity using your profile photo

  • To deliver and monitor the online test

  • To issue certificates (if included in your bundle)

  • To maintain academic integrity and prevent misconduct

  • To provide customer support

  • To comply with legal or regulatory requirements

We do not sell your data.

4. Legal Basis for Processing

We process your data under the following legal bases:

  • Contract: to deliver the test you purchased

  • Consent: when you upload a profile photo or agree to communication

  • Legitimate interest: fraud prevention, test integrity, and security

  • Legal obligation: record-keeping and compliance

5. How Long We Keep Your Data

We keep your personal data only as long as necessary:

  • Account information: while your account is active

  • Test records: up to 24 months for verification and quality checks

  • Certificates: maintained for verification purposes

  • Support communication: up to 12 months

You may request deletion sooner if allowed by law.

6. Sharing Your Data

We only share your data when necessary:

  • With exam processing partners: for test delivery and scoring

  • With payment providers: to process your purchase

  • With identity/security tools: to verify test integrity

  • With certificate issuers: if your bundle includes a certificate

  • With legal authorities: only when required by law

We never share your data with marketing companies or unrelated third parties.

7. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data

  • Correct inaccurate information

  • Request deletion of your data

  • Restrict or object to processing

  • Request a copy of your data

  • Withdraw consent at any time (where applicable)

To exercise these rights, contact us at support@step-uk.com.

8. Cookies & Tracking Technologies

Our website uses cookies for:

  • Security

  • Login and session management

  • Improving performance

  • Analytics (anonymised)

You can manage cookies through your browser settings.

9. Security of Your Information

We implement technical and organisational measures to protect your data, including:

  • Encrypted transmission (HTTPS)

  • Secure servers

  • Access controls

  • Fraud detection and exam integrity monitoring

However, no system is 100% secure, and we encourage safe password practices.

10. Children’s Privacy

STEP UK tests are intended for individuals aged 16+ unless otherwise authorised.
We do not knowingly collect data from children without consent.

11. Changes to This Policy

We may update this Privacy Policy when necessary.
Updated versions will be posted on this page with a new “Last updated” date.

12. Contact Us

If you have questions or concerns about your data, please contact:

STEP UK Support Team
Email: support@step-uk.com
Website: www.step-uk.com

bottom of page