Last updated: September 2026

Who we are

Wonkhe is published by Thesis House Ltd, a company registered in England and Wales (company number 08784934). Our registered office is 5 Technology Park, Colindeep Lane, Colindale, London NW9 6BX and our correspondence address is 31–35 Kirby Street, London EC1N 8TE. Thesis House Ltd was previously known as Wonkhe Ltd – it is the same company, and this policy replaces any earlier Wonkhe Ltd privacy policy.

Thesis House Ltd is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO), registration number ZA296124.

This policy applies to wonkhe.com and to the other publications, websites, newsletters, events and services operated by Thesis House Ltd, including Research Agenda, The Post-18 Project and Policy Partners, wherever they link to it.

It explains what personal data we collect, why, what we do with it, who we share it with, and what your rights are. It covers:

  • email briefing subscribers
  • paid subscription users
  • visitors to our websites
  • people who comment on our articles
  • people who contact us
  • event attendees and speakers
  • article contributors

Our commitments

Any personal data we hold about you will be:

  1. used lawfully, fairly and transparently;
  2. collected only for the specific purposes we’ve explained, and not used in ways incompatible with them;
  3. relevant and limited to those purposes;
  4. accurate and kept up to date;
  5. kept only as long as necessary;
  6. kept securely.

The legal bases we rely on

We only use your personal data where the law allows us to. Most commonly that will be because:

  • Contract – we need it to deliver a service you or your organisation has asked for (for example, sending you a briefing you’ve subscribed to, or running an event you’ve booked).
  • Legitimate interests – it’s necessary for our legitimate business interests (for example, understanding our audience, promoting our services to people who work in higher education, keeping our sites secure, or reporting usage to a subscribing organisation), and those interests aren’t overridden by your rights.
  • Legal obligation – we’re required to (for example, keeping financial records for HMRC).
  • Consent – where we’ve asked for it, such as for non-essential cookies. You can withdraw consent at any time.

Where we rely on legitimate interests for direct marketing, you always have the right to object and we’ll stop.

What we collect and why

Email briefings

When you sign up to a free briefing (such as the Wonkhe Monday Briefing or the Daily Briefing) we ask for your name, email address, job title, organisation, role level and professional area. We use this to send you the briefing and to understand who reads us, which shapes what we write.

We use Campaign Monitor to send briefings and we collect statistics on opens and clicks to improve the service (Campaign Monitor privacy notice).

We may also contact briefing subscribers about our subscription services, events, products or research, or those we endorse. We don’t let third parties email our list.

You can unsubscribe at any time using the link in any email, or by emailing briefing@wonkhe.com.

Paid subscriptions

Our paid services (including Wonkhe Pass, Wonkhe SUs, HE Counsel and Policy Update) operate under a contract between Thesis House Ltd and a subscribing organisation. If you’re a named user under one of those subscriptions we hold your name, work email address, job title and organisation, plus login details and records of your use of the service.

We’ll contact you about the service from time to time. We share usage information with the subscribing organisation when asked – limited to what’s relevant, such as the number of users, names and engagement levels – so the organisation can see the value of its subscription. Subscriber logins and content are delivered through our WordPress-based sites.

Our websites

When you visit our websites we use analytics tools to collect standard internet log information and details of visitor behaviour, such as pages viewed, referring site, browser type and approximate location. We use this to understand how our sites are used and to improve them. We currently use Google Analytics, via Google Tag Manager (Google privacy policy). We don’t attempt to identify individual visitors from this data and we don’t allow Google to do so on our behalf.

Our sites run on WordPress. Standard server logs, including IP addresses, are kept for security purposes.

Cookies

Our sites use cookies and similar technologies. Some are essential – they make the site work, keep you logged in and remember your preferences. Others are used for analytics and are only set with your consent. You can change your choices at any time through the cookie settings on our site, and you can also block cookies through your browser settings. Blocking essential cookies may stop parts of the site (such as subscriber logins) from working.

Comments

If you comment on an article we ask for your name and email address, and optionally a website address. These are stored on our WordPress site with your comment, along with your IP address. Your name (or the pseudonym you choose) is published with the comment; your email address is never published or passed to a third party, and we’ll only use it to contact you about your comment. If you opt in to email notifications of follow-up comments we’ll use your email for that only, and delete it if you ask us to stop. See also our moderation policy.

Contacting us

Emails to our shared inboxes (team@, briefing@, events@, finance@, press@ and similar) are handled in Groove, a shared inbox tool (Groove privacy policy), and we use Google Workspace for email and documents (Google privacy policy). We keep correspondence so we have context when you contact us again. We don’t add you to any mailing list from correspondence unless you’ve asked us to.

Events

When you book an event we ask for what we need to run it – usually your name, email address, job title and organisation, and sometimes dietary and accessibility requirements, session choices or a pre-event survey. We use this to run the event, communicate with you before and after it (joining instructions, programme, follow-up materials) and to understand our event audience.

Dietary and accessibility information may reveal health or religious information. We collect it only to meet your needs at the event, share it only with the venue or caterer where necessary, and delete it after the event.

We use Ticket Tailor for bookings (privacy policy), Stripe for card payments (privacy policy), Xero for invoicing (privacy policy), Campaign Monitor for delegate emails, Typeform for feedback (privacy policy) and Google Workspace to manage event data. Online events and webinars are run on Zoom (privacy statement); if you join one, Zoom processes your name, email address and connection data, and sessions may be recorded – we’ll tell you at the start if they are.

We sometimes take photographs or video at in-person events for use in our publications and promotion. We’ll tell you at the event, and you can let a member of the team know if you’d rather not be included.

Speakers’ names, titles, organisations and biographies are published as part of event promotion.

Article contributors

If you write for us we hold your name, contact details, job title, organisation and biography, and publish your name and bio with your article. If we pay you we hold the details needed to do so in Xero.

Who we share your data with

Beyond the service providers listed above, we may share personal data with:

  • IT, hosting and system administration providers acting as our processors;
  • professional advisers – lawyers, accountants, auditors, bankers and insurers;
  • HMRC, the ICO, regulators and other authorities where we’re required to report;
  • subscribing organisations, as described under paid subscriptions;
  • a buyer or successor if we sell, transfer or merge any part of our business, in which case they may use your data as set out in this policy.

We do not sell personal data, and we do not share it with third parties for their own marketing.

We require all our processors to keep your data secure, to use it only on our instructions and for the purposes we specify, and to comply with data protection law.

International transfers

Some of our providers store or process data outside the UK, including in the United States. Where that happens we make sure appropriate safeguards are in place – either the country has been found by the UK government to provide adequate protection, or the provider is certified under the UK–US Data Bridge, or we have the ICO’s International Data Transfer Agreement (or the UK Addendum to the EU standard contractual clauses) in place. Contact us if you’d like details of the safeguards for a particular provider.

How long we keep your data

We keep personal data only as long as we need it for the purposes we collected it, including to meet legal, accounting and tax obligations. As a guide:

  • briefing subscriber data – until you unsubscribe, after which we keep a suppression record so we don’t email you again;
  • paid subscription user data – for the life of the subscription and 12 months after it ends;
  • event data – two years after the event, except financial records which we keep for six years;
  • correspondence – three years;
  • comments – for as long as the article is published.

We may keep data longer if there’s a complaint or we reasonably believe litigation is possible. We may anonymise data so it no longer identifies you, in which case we may keep and use it without further notice.

Security

We have appropriate technical and organisational measures in place to protect your data from accidental loss and unauthorised access, use, alteration or disclosure. Access is limited to staff, contractors and providers who need it, and who are bound by confidentiality. We have procedures for handling suspected data breaches and will notify you and the ICO where we’re legally required to.

Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased where there’s no good reason for us to keep it;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • ask us to restrict processing in certain circumstances;
  • receive your data in a portable format (data portability) where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time where we rely on it.

We don’t make decisions about you using solely automated processing.

To exercise any of these rights, email team@wonkhe.com or write to us at the address below. There’s no fee, though we may charge a reasonable fee or refuse a request that’s clearly unfounded, repetitive or excessive. We may need to confirm your identity first. We’ll respond within one month, or tell you if a complex request will take longer.

If you’re unhappy with how we’ve handled your data, we’d like the chance to put it right, so please contact us first. You also have the right to complain to the ICO at ico.org.uk or on 0303 123 1113.

Children

Our services are aimed at people working in and around higher education. We don’t knowingly collect personal data from anyone under 13. If you think we have, please contact us and we’ll delete it.

Changes to this policy

We’ll post any changes on this page and update the date at the top. If a change is significant, we’ll tell subscribers by email.

Contact us

Data protection officer: Mark Leach, Chief Executive, Thesis House Ltd Email: team@wonkhe.com Phone: 0203 633 5564 Post: Thesis House Ltd, 31–35 Kirby Street, London EC1N 8TE