Who We Are
Lingua Language School Oy ("Lingua", "we", "us", or "our") is a private limited company registered in Finland under business ID 1234567-8, with its registered office at Mikonkatu 12, 00100 Helsinki.
Lingua is the data controller for all personal data collected through our website (lingua.fi), booking systems, physical premises, and any other service we provide. This means we are responsible for deciding how and why your personal data is processed.
If you have any questions about this policy or our data practices, please contact our Data Protection Officer directly at privacy@lingua.fi before submitting a formal complaint.
Data We Collect
We collect personal data in several ways — directly from you when you interact with us, automatically when you use our website, and occasionally from third parties such as payment processors.
- Identity data Full name, date of birth, nationality, and any other identification you provide when registering.
- Contact data Email address, telephone number, and postal address.
- Academic data Language level assessments, course progress records, attendance, and teacher feedback notes.
- Payment data Billing address and transaction records. Payment card details are processed directly by our payment provider (Stripe) and are not stored on our systems.
- Communications Records of your correspondence with us via email, phone, or our contact form.
- Technical data IP address, browser type and version, time zone, operating system, and referring URLs, collected automatically when you visit our website.
- Usage data Pages visited, links clicked, session duration, and other behavioural data collected via cookies and analytics tools.
- Marketing preferences Your opt-in or opt-out choices for marketing communications, and any stated preferences regarding language or interests.
We do not collect any special category data (such as health, ethnic origin, religion, or biometric data) unless you explicitly provide it in a message to us, and we do not use it for any purpose beyond responding to your enquiry.
How We Use Your Data
We only use your personal data for the purposes set out below. We will never use it in ways that are incompatible with these purposes without first informing you.
| Purpose | Data used | Legal basis |
|---|---|---|
| Processing course enrolments and bookings | Identity, contact, academic, payment | Contract |
| Managing your student account and progress | Identity, academic, communications | Contract |
| Processing payments and issuing invoices | Identity, contact, payment | Contract |
| Sending course reminders and scheduling updates | Contact, academic | Contract |
| Responding to enquiries and support requests | Identity, contact, communications | Legitimate Interest |
| Sending newsletters and promotional offers | Contact, marketing preferences | Consent |
| Improving our website and services via analytics | Technical, usage | Consent |
| Complying with legal and tax obligations | Identity, contact, payment | Legal Obligation |
| Preventing fraud and ensuring security | Identity, technical | Legitimate Interest |
Legal Basis for Processing
Under the EU General Data Protection Regulation (GDPR), we are required to have a valid legal basis for each processing activity. We rely on four bases:
- Contract Processing is necessary to perform a contract with you — for example, fulfilling your course booking or managing your student account.
- Legal Obligation Processing is required to comply with Finnish or EU law, such as tax record-keeping requirements under the Finnish Accounting Act.
- Legitimate Interest Processing is in our legitimate business interests — for example, fraud prevention, security monitoring, or responding to your enquiries — and these interests are not overridden by your rights.
- Consent You have given us clear, specific, and freely given consent for a particular purpose, such as receiving marketing emails. You may withdraw consent at any time.
Data Sharing & Third Parties
We do not sell, trade, or rent your personal data to third parties. We share data only with trusted service providers who process it on our behalf, under strict data processing agreements.
- Stripe, Inc. Payment processing. Processes payment card data under its own PCI-DSS compliance. Data transferred to the USA under Standard Contractual Clauses.
- Mailchimp (Intuit) Email marketing for newsletters and course announcements, sent only to users who have opted in. Data transferred under SCCs.
- Google Analytics Website usage analytics with IP anonymisation enabled. Used only with your cookie consent.
- Vercel / Hetzner Website and application hosting. All servers are located within the European Economic Area.
- Legal authorities We may disclose data to Finnish courts, the Data Protection Ombudsman, or other public authorities where required by law or to protect our legal rights.
All third-party providers are required to process your data only on our documented instructions, maintain appropriate security measures, and delete or return it upon termination of their engagement.
Cookies & Tracking
Our website uses cookies — small text files stored on your device — to make the site work correctly and to help us understand how it is used. You can manage your cookie preferences at any time via our cookie settings panel.
Strictly necessary cookies cannot be disabled as they are essential for the site to function. All other categories require your consent.
How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes it was collected, or as required by law. Our standard retention periods are as follows:
- Student records Kept for 5 years after your last interaction with us, then deleted or anonymised. Academic progress notes are retained for 3 years.
- Financial & tax records Retained for 7 years as required by the Finnish Accounting Act (1336/1997).
- Contact form enquiries Retained for 2 years after the enquiry is resolved, unless it leads to a booking.
- Marketing data Retained until you withdraw consent or unsubscribe, plus a further 90 days for suppression list purposes.
- Website analytics Aggregated, anonymised data retained indefinitely. Individual session data deleted after 26 months.
When we no longer have a lawful basis to retain your data, we securely delete or anonymise it so it can no longer be attributed to you.
Your Rights
Under GDPR, you have the following rights regarding your personal data. These rights are not absolute and may be subject to legal exceptions in certain circumstances. We will respond to any valid request within 30 days.
To exercise any of these rights, contact our Data Protection Officer at privacy@lingua.fi. We may need to verify your identity before fulfilling the request. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
International Data Transfers
Some of our third-party service providers operate outside the European Economic Area (EEA), including in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place.
For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR, supplemented by transfer impact assessments where required.
You may request a copy of the Standard Contractual Clauses we use with specific providers by writing to privacy@lingua.fi.
Children's Privacy
Our services are designed for adults aged 16 and over. We do not knowingly collect personal data from children under 16 without verifiable parental or guardian consent.
If you are a parent or guardian and believe your child has provided personal data to us without your consent, please contact us immediately at privacy@lingua.fi and we will delete the information promptly.
For under-16 students enrolled in our courses with parental consent, the consent form and data processing agreement is concluded with the parent or guardian, who acts as the data subject for GDPR purposes.
Changes to This Policy
We review and update this Privacy Policy periodically to reflect changes in our practices, services, or applicable law. When we make material changes, we will:
- ▸ Update the "Last updated" and "Effective date" at the top of this page
- ▸ Notify enrolled students by email at least 14 days before the changes take effect
- ▸ Display a notice on our homepage for 30 days following a material update
Your continued use of our services after a policy update constitutes acceptance of the revised terms, unless you notify us otherwise. We maintain an archive of previous versions which is available on request.
Contact & Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
- Name & title Kaisa Virtanen, Data Protection Officer
- Email privacy@lingua.fi
- Phone +358 9 1234 5699 (Mon–Fri, 09:00–17:00)
- Postal address Lingua Language School Oy, FAO Data Protection Officer, Mikonkatu 12, 00100 Helsinki, Finland
- Supervisory authority Finnish Data Protection Ombudsman — tietosuoja.fi — PO Box 800, 00531 Helsinki
We aim to resolve all privacy enquiries within 30 days. For complex requests, we may extend this by a further 60 days and will notify you of any extension within the initial 30-day period.