Regulatory Compliance

Lingoodle is an Irish company and builds its data practices to the standards of the EU General Data Protection Regulation (GDPR). Because we serve enterprise clients and process children's data, data protection is designed into how we work.

Under the GDPR, Lingoodle acts as a data processor on behalf of enterprise clients (the data controllers). We process only the minimum personal data required to deliver our Mandarin immersion programme, and we apply additional care when handling data relating to children.

EU Data Residency

Our learning platform is hosted in the EU (AWS Ireland), and we use EU data residency options with our other providers wherever they are available. This covers categories of personal data including student records, parent and guardian contact information, and payment metadata. Session recordings are made for safeguarding and held securely for 30 days.

Our sub-processors are contractually bound by GDPR-compliant Data Processing Agreements.

Data Encryption

Our sub-processors each maintain industry-standard encryption for data in transit and at rest, as part of their published security practices.

Sub-Processors

Lingoodle works with a carefully selected set of sub-processors, each bound by GDPR-compliant Data Processing Agreements (DPAs). The following table details our current sub-processors and their roles.

Sub-Processor Purpose Notes
Moodle (Moodle Pty Ltd) Learning management platform EU-hosted on AWS (Ireland).
Zoom Video delivery for 1-on-1 sessions Used to deliver live Mandarin immersion sessions between tutors and students.
Stripe Payment processing Handles enterprise billing and payment transactions. PCI DSS Level 1 certified.
Airtable Operations and enrolment records Stores enterprise account details, child first name and seat allocation, and programme status.
Brevo Programme and transactional email Sends enrolment and programme emails. Processes parent, guardian and enterprise contact names and email addresses.
Netlify Website hosting Hosts the Lingoodle website and handles information submitted through forms on the site.

All sub-processors are reviewed on a regular basis. Enterprise clients are notified in advance of any changes to this list, in accordance with their Data Processing Agreement.

Tutor Vetting Process

Every Lingoodle tutor undergoes a rigorous vetting process before being permitted to deliver sessions. Our commitment to child safety is reflected in the following requirements.

  • Background checks: All tutors are subject to comprehensive background checks prior to engagement.
  • Garda vetting: Tutors based in Ireland undergo Garda vetting through the National Vetting Bureau, in compliance with the National Vetting Bureau (Children and Vulnerable Persons) Acts 2012 to 2016.
  • Reference verification: Professional and character references are obtained and verified for every tutor.
  • Mandatory safeguarding training: All tutors complete mandatory child safeguarding training before delivering any sessions, with refresher training conducted on a regular basis.
  • Ongoing performance monitoring: Tutors are subject to continuous performance monitoring, including session quality reviews and adherence to safeguarding protocols.

Parental Consent

Lingoodle requires parental or guardian consent before a child takes part and before we process a child's personal data. The consent process is designed around GDPR Article 8.

  • Parents or legal guardians are presented with a clear, plain-language explanation of what data will be collected, how it will be used, and who will have access to it.
  • Consent is sought from the child's parent or legal guardian before participation begins.
  • Parents can withdraw consent at any time. Upon withdrawal, the child's personal data will be deleted in accordance with our data retention policies, and sessions will cease.

Enterprise clients are responsible for facilitating the parental consent process within their organisations. Lingoodle provides the necessary materials and tools to support this.

Incident Response

Lingoodle follows a defined process to address any security breach or data protection incident promptly.

  • Security incidents involving personal data are reported to the relevant supervisory authority within 72 hours, as required under Article 33 of the GDPR.
  • Affected data controllers (enterprise clients) are notified without undue delay, with full details of the nature of the breach, the categories of data affected, and the measures taken to address the incident.
  • Where a breach is likely to result in a high risk to the rights and freedoms of individuals, affected data subjects are notified directly.

We review our incident response approach to keep it aligned with current best practices.

Security Contact

If you have any questions about our security practices, wish to report a vulnerability, or need to discuss data protection matters, please contact our security team.

Security enquiries: hello@lingoodle.com

Data protection enquiries: hello@lingoodle.com

For enterprise security or data protection questions, please contact us at hello@lingoodle.com.