Legal
Privacy Notice
Effective and last updated: 6 August 2026 · Version 1.1
This notice explains how ComeTalk Studio (“CTS”, “we”, “us”) handles personal information when people visit our website, request access, use the teaching platform, receive lessons, complete assignments or contact support.
1. Who is responsible
ComeTalk Studio is operated by Jason Carter trading as ComeTalk Studio. Privacy questions and requests can be sent to lessons@cometalkstudio.com.
For teacher, account, website, security, support and service-operation data, CTS normally decides why and how the information is used and acts as controller or equivalent responsible organisation. Where a school, studio or teacher creates learner accounts and determines the educational purpose of lessons, assignments and records, that customer is normally the controller and CTS processes learner data on its instructions, subject to our own responsibilities for security, service integrity, fraud prevention and legal compliance.
2. Information we collect
Depending on the features used, we may process:
- teacher, guardian, administrator and organisation names, email addresses, roles, account settings and communications;
- learner display names or usernames, learning level, group membership, assigned teacher and preferred language;
- lesson instructions, generated lessons, assignments, answers, scores, completion history, feedback, review decisions, attendance and progress records;
- Dictionary entries, Flashcards, saved work and learning preferences;
- support requests, access requests, bug reports and service communications;
- technical and security information such as IP address, browser, device type, login events, audit events and server logs;
- billing records, plan, credits, invoices and transaction identifiers when paid services are used. CTS does not intend to store complete payment-card numbers; these are handled by the payment provider shown at checkout.
Customers should use a learner display name where possible and should not enter unnecessary sensitive information into lesson prompts, answers or account records.
3. How information is obtained
Information is provided directly by teachers, organisations, guardians and learners; generated through use of the service; received from authorised account administrators; or created automatically by security, logging and transaction systems.
4. Why we use information and legal bases
We use personal information to:
- create and manage accounts, workspaces, learner relationships and permissions;
- generate, store, deliver and adapt lessons and media;
- assign work, save responses, check suitable answers and support teacher review;
- provide Dictionary, translation, Flashcards, scheduling, attendance, reporting and guardian-access features;
- provide support, communicate service information and respond to requests;
- secure the service, detect misuse, investigate incidents and maintain audit records;
- administer subscriptions, credits, invoices and contractual rights;
- meet legal, accounting and regulatory obligations.
Where GDPR or UK GDPR applies, the legal basis will depend on the context and may include performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where consent is required. Schools, organisations and teachers are responsible for identifying and documenting their lawful basis for learner use where they act as controller.
5. Learners and children
Learner accounts are created or authorised by a teacher, school, studio, organisation, guardian or other adult with appropriate authority. The customer creating or managing a child’s account must provide legally required notices and obtain any required permissions.
CTS does not sell learner information, use learner information for behavioural advertising, or create unrelated advertising profiles. Access is limited according to account roles. Children should receive privacy information in clear, age-appropriate language from the responsible teacher or organisation.
6. AI-assisted functions
Authorised AI providers may process lesson prompts, lesson content, selected learner responses and media instructions when necessary to generate lessons, audio, images, contextual definitions, translations or supported checking. Customers should not include unnecessary names, contact details or sensitive data in prompts or answers. AI output can be inaccurate. Teachers remain responsible for reviewing teaching content and any open, uncertain or consequential assessment.
7. Service providers and disclosures
We may use service providers for hosting, security, DNS, email, AI functions, payment processing and support. Current or expected providers include netcup, Cloudflare, OpenAI, Resend and the payment provider identified at checkout. Providers receive information only as needed for their role and are subject to contractual and legal obligations appropriate to that role.
We may also disclose information where required by law, to protect users or the service, to investigate fraud or security incidents, or as part of a business reorganisation subject to appropriate safeguards.
8. International transfers
The primary CTS service is hosted in the European Union. Some providers may process information in other countries. Where data-protection law requires safeguards for an international transfer, CTS or the relevant customer will use an available legal mechanism such as an adequacy decision, approved contractual clauses or another lawful safeguard.
9. Cookies and browser storage
The authenticated service uses strictly necessary session and security technologies. The public website and lesson demonstration may use local browser storage for preferences and demonstration state. We do not currently use behavioural advertising cookies. Non-essential analytics or marketing technologies will not be introduced without the notice and consent controls required by applicable law.
10. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, maintaining learning records requested by the customer, resolving disputes, preventing abuse and meeting legal, tax and accounting requirements.
- Account, lesson and learner records are retained while needed to operate the service, preserve requested learning history, resolve disputes and meet legal obligations. Archiving a student revokes their access but does not automatically delete the teacher’s permitted historical records.
- Backups are retained on a rolling schedule and deleted through normal backup rotation.
- Security and audit logs are retained for a limited period based on operational and incident-response requirements.
- Financial records are retained for the period required by applicable law.
Customers should archive or delete learner accounts when they are no longer needed. Specific retention commitments agreed with an organisation will take precedence where stated in a data-processing agreement.
11. Security
CTS uses organisational and technical measures intended to protect information, including encrypted connections, password hashing, role-based permissions, restricted administrative access, server hardening, logging and backups. No online service can guarantee absolute security. Suspected incidents should be reported immediately to lessons@cometalkstudio.com.
12. Rights and choices
Depending on applicable law, individuals may have rights to be informed, access personal information, correct it, request deletion or restriction, object to certain processing, receive portable data, withdraw consent and complain to a supervisory authority. Requests involving learner education records may need to be directed first to the teacher or organisation that controls the account.
Send requests to lessons@cometalkstudio.com. We may verify identity, authority and account relationship before acting.
13. Complaints
Please contact us first so we can investigate. Where applicable, individuals may also complain to the data-protection authority in their country. EU and UK users can locate their relevant supervisory authority through official government or regulatory websites.
14. Changes
We may update this notice when the service, providers or legal requirements change. The current version and revision date will remain available on this website. Material changes affecting existing users will be communicated through the service or account contact where reasonably practicable.
