Regulatory Compliance
Lingoodle is an Irish company and builds its data practices to the standards of the EU General Data Protection Regulation (GDPR). Because we serve enterprise clients and process children's data, data protection is designed into how we work.
Under the GDPR, Lingoodle acts as a data processor on behalf of enterprise clients (the data controllers). We process only the minimum personal data required to deliver our Mandarin immersion programme, and we apply additional care when handling data relating to children.
EU Data Residency
Our learning platform is hosted in the EU (AWS Ireland), and we use EU data residency options with our other providers wherever they are available. This covers categories of personal data including student records, parent and guardian contact information, and payment metadata. Session recordings are made for safeguarding and held securely for 30 days.
Our sub-processors are contractually bound by GDPR-compliant Data Processing Agreements.
Data Encryption
Our sub-processors each maintain industry-standard encryption for data in transit and at rest, as part of their published security practices.
Sub-Processors
Lingoodle works with a carefully selected set of sub-processors, each bound by GDPR-compliant Data Processing Agreements (DPAs). The following table details our current sub-processors and their roles.
| Sub-Processor | Purpose | Notes |
|---|---|---|
| Moodle (Moodle Pty Ltd) | Learning management platform | EU-hosted on AWS (Ireland). |
| Zoom | Video delivery for 1-on-1 sessions | Used to deliver live Mandarin immersion sessions between tutors and students. |
| Stripe | Payment processing | Handles enterprise billing and payment transactions. PCI DSS Level 1 certified. |
| Airtable | Operations and enrolment records | Stores enterprise account details, child first name and seat allocation, and programme status. |
| Brevo | Programme and transactional email | Sends enrolment and programme emails. Processes parent, guardian and enterprise contact names and email addresses. |
| Netlify | Website hosting | Hosts the Lingoodle website and handles information submitted through forms on the site. |
All sub-processors are reviewed on a regular basis. Enterprise clients are notified in advance of any changes to this list, in accordance with their Data Processing Agreement.
Tutor Vetting Process
Every Lingoodle tutor undergoes a rigorous vetting process before being permitted to deliver sessions. Our commitment to child safety is reflected in the following requirements.
- Background checks: All tutors are subject to comprehensive background checks prior to engagement.
- Garda vetting: Tutors based in Ireland undergo Garda vetting through the National Vetting Bureau, in compliance with the National Vetting Bureau (Children and Vulnerable Persons) Acts 2012 to 2016.
- Reference verification: Professional and character references are obtained and verified for every tutor.
- Mandatory safeguarding training: All tutors complete mandatory child safeguarding training before delivering any sessions, with refresher training conducted on a regular basis.
- Ongoing performance monitoring: Tutors are subject to continuous performance monitoring, including session quality reviews and adherence to safeguarding protocols.
Parental Consent
Lingoodle requires parental or guardian consent before a child takes part and before we process a child's personal data. The consent process is designed around GDPR Article 8.
- Parents or legal guardians are presented with a clear, plain-language explanation of what data will be collected, how it will be used, and who will have access to it.
- Consent is sought from the child's parent or legal guardian before participation begins.
- Parents can withdraw consent at any time. Upon withdrawal, the child's personal data will be deleted in accordance with our data retention policies, and sessions will cease.
Enterprise clients are responsible for facilitating the parental consent process within their organisations. Lingoodle provides the necessary materials and tools to support this.
Incident Response
Lingoodle follows a defined process to address any security breach or data protection incident promptly.
- Security incidents involving personal data are reported to the relevant supervisory authority within 72 hours, as required under Article 33 of the GDPR.
- Affected data controllers (enterprise clients) are notified without undue delay, with full details of the nature of the breach, the categories of data affected, and the measures taken to address the incident.
- Where a breach is likely to result in a high risk to the rights and freedoms of individuals, affected data subjects are notified directly.
We review our incident response approach to keep it aligned with current best practices.
Security Contact
If you have any questions about our security practices, wish to report a vulnerability, or need to discuss data protection matters, please contact our security team.
Security enquiries: hello@lingoodle.com
Data protection enquiries: hello@lingoodle.com
For enterprise security or data protection questions, please contact us at hello@lingoodle.com.