Privacy notice

Last updated: 9 August 2026

This notice explains what personal data LinguaLens Insights handles, why, on what likely lawful basis, and how you can exercise your rights. It covers both our own website and accounts, and the learner programme data that training providers upload into their workspace.

Early-access starter document — not legal advice

LinguaLens Insights is in early access. This document has been written in plain language to describe honestly what the service does today. It has not been reviewed or approved by a solicitor, and it is not a substitute for professional legal advice for either party.

Some operator details are not yet finalised and are marked accordingly below. Details to be confirmed before customer onboarding.

Who we are

LinguaLens Insights is an early-access analytics and reporting service for language-training providers, operated from the United Kingdom by the operating company namedetails to be confirmed before customer onboarding.

Company registration number: company numberdetails to be confirmed before customer onboarding. Registered address: registered addressdetails to be confirmed before customer onboarding.

We have not appointed a statutory Data Protection Officer and do not claim to be required to. Data-protection enquiries will be handled by a named data-protection contactdetails to be confirmed before customer onboarding.

Controller and processor roles

These roles differ depending on the data, and the distinction matters:

  • We act as controller for the data we need to run the service itself: account and contact details of the people who sign up, billing information if and when billing is enabled, support correspondence, and authentication and security logs.
  • We act as processor for the learner and employee programme data that a training provider uploads into its workspace. The provider decides what to upload, why, and for how long; we process it on the provider's instructions in order to produce dashboards and reports.
  • Where we act as processor, the provider is the controller and remains responsible for having a lawful basis to collect the data and to share it with us, and for informing its own learners and client organisations.

A written data-processing agreement will be put in place with each provider before live customer data is onboarded.

What data we handle

  • Account and contact data: name, work email address, the provider workspace you belong to, your role in it, and preferences such as chosen site language and whether you are viewing demo or live data.
  • Provider-uploaded programme data: learner or employee records, enrolments, attendance, assessment results, CEFR levels (A1–C2) and programme costs. Client-viewer roles see learner records without direct contact details.
  • Authentication and security logs: sign-in and sign-out events, password-reset requests, timestamps, and technical request metadata generated by our hosting and authentication infrastructure.
  • Support correspondence: anything you send us about the service.

We do not ask providers to upload special-category data (such as health data) and the product is not designed to hold it. Please do not upload data you are not permitted to share.

Why we handle it, and our likely lawful bases

The lawful bases below are stated as our current assessment and are among the details we will confirm with legal advice before customer onboarding.

  • To create and secure your account, and to provide the dashboards, imports and reports you ask for — likely performance of a contract with the provider, or steps taken at its request before entering one.
  • To keep the service secure, detect abuse and maintain an auditable history — likely legitimate interests in operating a secure service.
  • To respond to your enquiries and give early-access support — likely legitimate interests or performance of a contract.
  • To comply with legal obligations that apply to us — legal obligation.
  • For learner programme data, the lawful basis is determined by the provider as controller, not by us.

We do not use your data for advertising, we do not sell it, and we do not carry out automated decision-making that produces legal effects about an individual.

Sharing and service providers

We do not sell personal data. We share it only with service providers who help us run the service — for example cloud hosting, managed database and authentication infrastructure, and transactional email delivery — and only to the extent needed to provide it.

A named list of these subprocessors, with their purpose and processing location, will be published here: the subprocessor listdetails to be confirmed before customer onboarding.

We may also disclose data where we are legally required to do so, or to establish or defend legal claims.

International transfers

Where a service provider processes personal data outside the United Kingdom, that transfer must be covered by an approved safeguard, such as UK adequacy regulations or the International Data Transfer Agreement / UK Addendum.

We have not yet finalised and published which processing locations apply, so we make no claim that all processing is UK-only. The confirmed position will be stated here: processing locations outside the UK, if anydetails to be confirmed before customer onboarding.

How long we keep data

Our retention principle is that personal data is kept only as long as it is needed for the purpose it was collected for, or as long as we are legally required to keep it, and is then deleted or anonymised.

  • Account data is kept while the account is active, and for a limited period afterwards to handle disputes and legal obligations.
  • Learner programme data is retained under the provider's instructions as controller. Learner records are soft-deleted so that reporting history remains auditable, and can be permanently removed on the provider's instruction.
  • Security logs are kept only as long as they remain useful for security and troubleshooting.

We are not quoting specific retention periods yet rather than inventing them. Confirmed periods per data category will be published here: retention periodsdetails to be confirmed before customer onboarding.

Security, and its limits

Each provider workspace is separated at the database level using row-level security policies, so one provider cannot read another provider's records. Access within a workspace is restricted by role — provider admin, client viewer and trainer — and client viewers see learner records without direct contact details. Data is transmitted over encrypted connections and stored on managed cloud infrastructure.

Being honest about the limits: LinguaLens Insights is an early-access product. We hold no security certifications (for example ISO 27001 or SOC 2), we make no compliance claims, we have not completed an independent penetration test or audit, and no service can be guaranteed to be perfectly secure. Assess this before uploading data about real individuals.

Your rights

Under UK data-protection law you may have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent where processing relies on consent. These rights have conditions and do not all apply in every situation.

If your data was uploaded into a provider's workspace, that provider is the controller: please contact the provider first. If you contact us instead, we will refer the request to the relevant provider and support them in responding.

Contacting us, and complaints

Privacy enquiries should be sent to our privacy contact addressdetails to be confirmed before customer onboarding. A monitored contact route will be published here before any customer is onboarded; until then, the reliable way to reach us is through the account you create on this site.

If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint, or by calling their helpline. We would appreciate the chance to address your concern first. Our ICO registration reference, where applicable: ICO registration referencedetails to be confirmed before customer onboarding.

Changes to this notice

As the product and our operating arrangements are finalised, this notice will be updated and the "last updated" date above will change. Material changes affecting providers will be communicated directly.

Still to be confirmed

The following details will be published here before any customer is onboarded:

  • Registered company name of the operating entity
  • Company registration number
  • Registered postal address
  • General enquiries email address
  • Privacy / data-protection enquiries email address
  • UK ICO data-controller registration reference (if registered)
  • Named data-protection contact, if one is appointed
  • Data-retention periods per data category
  • Hosting and service providers acting as subprocessors
  • Countries outside the UK where data is processed, if any

© 2026 LinguaLens Insights.