Privacy Policy
LINXED LIMITED
Privacy Policy
| Effective Date | 21st July 2026 |
|---|---|
| Last Updated | 25th July 2026 |
| Version | v1.0 |
| Document owner | Linxed Limited - Data Protection Officer / privacy@linxed.com |
| Reviewed by |
1. About this Privacy Policy
Linxed Limited ("Linxed", "we", "us", or "our") is committed to protecting the privacy and personal data of children, parents, educators, and educational institutions that use our services. This Privacy Policy explains how we collect, use, share, retain, and protect personal information when you access or use our educational technology platform, including our websites, mobile applications, integrated tools, and supporting services (collectively, the "Services").
This Privacy Policy applies to:
- Children who use our Services with parental, guardian, or institutional consent;
- Parents, guardians, and other adults responsible for a child's use of our Services;
- Educators, teachers, tutors, school administrators, and other education professionals;
- Educational institutions, schools, and education providers that license, deploy, or integrate our Services;
- Visitors to our public-facing websites and prospects who contact us.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please do not use our Services. Where you are providing information about a child, you confirm that you have the authority to do so and to consent to the processing described below.
2. Who we are (data controller information)
Linxed Limited is a company incorporated in Hong Kong, with its registered office in Hong Kong SAR.
For the purposes of the regulations listed below, Linxed Limited acts as the "data controller," "operator," "personal information processor," or equivalent responsible party in relation to the personal information described in this Policy:
- The EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the UK GDPR;
- The U.S. Children's Online Privacy Protection Act of 1998 ("COPPA");
- The U.S. Family Educational Rights and Privacy Act ("FERPA"), where Linxed acts as a school official with a legitimate educational interest under a contract with an educational institution;
- The Personal Information Protection Law of the People's Republic of China ("PIPL");
- The Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO");
- The Personal Data Protection Act 2012 of Singapore ("PDPA");
- Applicable U.S. state privacy laws including, where relevant, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").
Where Linxed provides Services to an educational institution under a written agreement, the institution may act as the "data controller" (or "educational agency or institution" under FERPA) and Linxed may act as a "data processor," "service provider," or "school official." In such cases the institution's own privacy notices and policies may apply alongside this Policy.
Contact details
For any privacy-related queries, requests, or complaints, please contact us at:
| Data Protection Officer | privacy@linxed.com |
|---|---|
| privacy@linxed.com | |
| Postal address | Linxed Limited, Hong Kong SAR |
| EU representative (Art. 27 GDPR) | Not currently appointed. Contact privacy@linxed.com |
| UK representative (Art. 27 UK GDPR) | Not currently appointed. Contact privacy@linxed.com |
3. Scope and key terms
In this Policy:
- "Personal information" or "personal data" means any information that relates to an identified or identifiable individual. The exact scope of what is considered personal data may vary by jurisdiction.
- "Child" means a user under the age of digital consent in the applicable jurisdiction. For the United States, a child is a user under 13. For the European Economic Area and the United Kingdom, a child is a user below the age set under Article 8 GDPR (between 13 and 16, depending on the member state). For mainland China under PIPL, a child is a user under 14. We treat any user reasonably identified as a child according to the most protective applicable threshold.
- "Parent" means a parent, legal guardian, or other adult with legal authority to consent on behalf of a child.
- "Educator" means a teacher, tutor, instructor, school administrator, or other adult acting in a professional capacity in connection with a child's education.
- "Institution" means a school, education provider, or other organization that has entered into a written agreement with Linxed for use of the Services.
4. Information we collect
The categories of personal information we collect depend on who you are, how you use the Services, and the consent or authorization received. The table below summarizes the principal categories. Specific details of fields collected per processing activity are maintained in our internal Record of Processing Activities (RoPA), available to data subjects and regulators on request.
| User category | Categories of personal information collected |
|---|---|
| Children | Account identifier (assigned by parent or institution); first name (or display name); year of school or class; learning activity data (lessons accessed, time on task, scores, progress markers); device and technical identifiers (IP address, browser type, operating system, app version); session and audit logs; content the child submits within learning activities. |
| Parents / guardians | Name; email address; phone number (optional); relationship to child; account credentials; billing information (where applicable, processed by our payment processor); communications with us; consent records, including evidence of parental consent given for the child's use of the Services. |
| Educators | Name; professional email address; role or job title; institution affiliation; account credentials; classes or groups managed; content created or shared within the Services; communications with us. |
| Institutional administrators | Name; professional email address; role; institution; account credentials; configuration and administrative decisions taken in the platform; communications with us. |
| All users | Cookies, device identifiers, and similar technologies (see Section 13); product analytics and usage data; support correspondence; survey responses (optional); technical and security telemetry; integration data passed to or from third-party services authorized by the user (e.g., Google Sheets, Google Drive - see Section 8). |
Sources of information
We collect personal information from the following sources:
- Directly from you when you register, configure your account, communicate with us, or use the Services;
- From a parent or guardian on behalf of a child;
- From an educator or institutional administrator on behalf of a child or class;
- Automatically through use of the Services, via cookies, device identifiers, analytics tools, and server logs;
- From third-party services that you or your institution authorize us to integrate with (for example, Google Workspace, Google Sheets, Google Drive, single sign-on providers, learning management systems);
- From payment processors, in respect of subscription and billing information.
5. Information about children (COPPA, GDPR-K, PIPL minor protections)
We design our Services with the protection of children in mind. We collect the minimum personal information from children that is necessary to provide the requested educational service. We do not collect personal information from a child without first obtaining verifiable consent from a parent, guardian, or authorized institution, as required by the law applicable to that child.
5.1 United States — COPPA
For users in the United States who are under 13, we comply with the Children's Online Privacy Protection Act and the related FTC Rule, including the following commitments:
- We do not collect more personal information from a child than is reasonably necessary to participate in the Services.
- We obtain verifiable parental consent before collecting, using, or disclosing personal information from a child, except in the limited circumstances permitted by COPPA (such as supporting the internal operations of the Service).
- Where the Services are provided to a child through their school, we may rely on the school's authorization in lieu of direct parental consent, but only for the use and benefit of the school and for no other commercial purpose.
- We do not condition a child's participation in a Service on the disclosure of more personal information than is reasonably necessary.
- We do not use personal information of children to engage in targeted advertising, to build advertising profiles, or to enable third-party advertising on the Services.
- Parents have the right to review the personal information we have collected from their child, to request its deletion, and to refuse further collection (see Section 11).
How we obtain verifiable parental consent
Depending on the registration pathway and the level of risk, we obtain verifiable parental consent using one or more of the following methods permitted by the FTC:
- A signed consent form returned by mail, fax, or electronic scan;
- A verified credit, debit, or other online payment instrument that provides notification of each transaction to the account holder;
- A government-issued identification check (e.g., a driver's license) compared against a database, with the identification deleted promptly after verification;
- A video-conference verification with trained personnel;
- Knowledge-based authentication using questions of sufficient difficulty;
- Where the Service is delivered through a school and used for an educational purpose only, written authorization from the school administrator acting under FERPA "school official" arrangements.
5.2 European Economic Area and United Kingdom - GDPR Article 8
Where a child is below the age of digital consent in their member state of residence (between 13 and 16 under Article 8 GDPR; 13 in the UK), we obtain consent from the holder of parental responsibility. We make reasonable efforts to verify that consent is given or authorized by the holder of parental responsibility, taking into account available technology. Special category data (including any data revealing health, racial or ethnic origin, religious beliefs, or similar) about children will only be processed on the basis of explicit consent or another lawful basis under Article 9 GDPR.
5.3 People's Republic of China - PIPL minor protections
For users in mainland China who are under 14, we process personal information only with the consent of the minor's parent or guardian and in accordance with the dedicated processing rules required under PIPL. We maintain a separate child personal information protection rule that supplements this Policy for PIPL-subject users.
5.4 Other jurisdictions
In jurisdictions not specifically addressed above, we apply the most protective of the following: (a) the age of digital consent specified by local law, or (b) the threshold under COPPA. Where local law imposes additional requirements (e.g., the Hong Kong PDPO, the Singapore PDPA, or U.S. state laws addressing minors), we comply with those requirements.
6. Purposes of processing and legal bases
We process personal information only for specified, legitimate purposes and only where we have a lawful basis to do so under applicable law. The table below summarizes the principal processing purposes and the corresponding lawful bases under GDPR / UK GDPR. Where you are located in a jurisdiction that uses a different legal-basis framework (e.g., PIPL, PDPA, PDPO), we apply the analogous lawful ground (consent, contract performance, legal obligation, or legitimate interest).
| Purpose | Lawful basis (GDPR / UK GDPR) |
|---|---|
| Creating and managing user accounts; providing access to the Services; delivering learning activities to children. | Performance of a contract (Art. 6(1)(b)); or consent (Art. 6(1)(a) and Art. 8) where the user is a child. |
| Verifying the identity of a parent or guardian and recording parental consent. | Compliance with a legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) in safeguarding children. |
| Communicating with users about their account, the Services, important changes, and support requests. | Performance of a contract (Art. 6(1)(b)); legitimate interests. |
| Processing payments and managing subscriptions (where applicable). | Performance of a contract (Art. 6(1)(b)); compliance with legal obligation (Art. 6(1)(c)). |
| Improving the Services, debugging, security monitoring, fraud and abuse prevention. | Legitimate interests (Art. 6(1)(f)) - operating a safe, secure, and reliable platform for children and educators. |
| Sending optional marketing or product-update communications to adults (parents, educators, administrators). | Consent (Art. 6(1)(a)); recipients may opt out at any time. |
| Complying with legal, regulatory, and law-enforcement obligations. | Compliance with a legal obligation (Art. 6(1)(c)). |
| Establishing, exercising, or defending legal claims. | Legitimate interests (Art. 6(1)(f)). |
We do not use children's personal information for behavioural advertising, profiling for marketing, or any purpose materially different from delivering the educational Service. We do not sell children's personal information.
7. How we share information
We share personal information only as described in this Policy. The categories of recipients are:
7.1 Service providers and sub-processors
We engage third-party service providers to host the platform, process payments, deliver communications, provide analytics, and support operations. These service providers act on our documented instructions and are bound by written contracts that impose confidentiality, security, and data-protection obligations consistent with applicable law (including Article 28 GDPR data-processing agreements where required). An up-to-date list of our sub-processors is available at https://linxed.com/sub-processors.
7.2 Educational institutions
Where a child is using the Services through an institutional account, the relevant institution and its authorized educators may access the child's information necessary to deliver education. Institutional administrators may manage their own users and may export the institution's data.
7.3 Third-party integrations authorized by you
When you choose to connect the Services to a third-party service (for example, your Google account for the use of Google Sheets and Google Drive), we share and receive information with that third party only as needed to provide the integration you authorized. See Section 8 for our specific commitments in respect of Google API services.
7.4 Legal and regulatory disclosures
We may disclose personal information when we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation, court order, or government request; (b) enforce our agreements or this Policy; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Linxed, our users (especially children), or the public.
7.5 Business transfers
In the event of a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of the transaction. We will notify affected users and seek to ensure that the recipient adopts privacy protections that are no less protective than those described in this Policy.
7.6 With your consent
We will share personal information for any other purpose only with your consent, or, in the case of a child, with verifiable parental or institutional consent.
7.7 What we never do
We do not:
- Sell personal information of any user, and in particular we do not sell children's personal information;
- Use children's personal information for behavioural advertising or third-party advertising profiling;
- Disclose children's personal information to third parties for marketing purposes;
- Use Google user data accessed through the Google APIs for any purpose other than as described in Section 8.
8. Google API services — limited-use disclosure
The Services integrate with Google APIs (including, where authorized by you, Google Sheets and Google Drive) to enable functionality that you specifically request. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8.1 What this means in practice
- We access Google user data only with your explicit authorization, granted through Google's OAuth consent flow.
- We use Google user data solely to provide or improve the user-facing features of the Services that are prominent in the requesting app's user interface.
- We do not transfer Google user data to third parties except (a) as necessary to provide or improve user-facing features, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets with notice.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data except (a) with your affirmative agreement for specific data, (b) where necessary for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
8.2 Scopes accessed
The Services request only the minimum Google OAuth scopes needed to deliver the features you have enabled. The scopes currently used are:
- https://www.googleapis.com/auth/spreadsheets
- https://www.googleapis.com/auth/drive.file
- openid
- profile
You may review and revoke these authorizations at any time at https://myaccount.google.com/permissions.
8.3 Storage and security of Google user data
Google user data accessed through the integration is processed in accordance with the security controls described in Section 12. Where data must be cached or stored to deliver the requested feature, it is retained only for as long as needed for that purpose and deleted on the earlier of (a) your revocation of the authorization, (b) deletion of your account, or (c) the end of the documented retention period for the relevant processing activity.
9. International data transfers
Linxed is headquartered in Hong Kong and uses service providers located in multiple jurisdictions. As a result, personal information may be transferred to, stored in, or accessed from countries other than your country of residence. The protections available in those countries may differ from those in your country. We apply appropriate safeguards in each case:
9.1 GDPR / UK GDPR transfers
Where personal information of individuals in the European Economic Area or the United Kingdom is transferred to a country that has not received an adequacy decision from the European Commission or the UK Government, we rely on appropriate safeguards as defined in Chapter V of the GDPR, including:
- The Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum or the UK International Data Transfer Agreement;
- Supplementary measures including encryption, pseudonymization, and access controls, where required by transfer impact assessment.
Data subjects may request a copy of the relevant safeguards by contacting us at the address in Section 2.
9.2 PIPL cross-border transfers
Cross-border transfers of personal information of individuals in mainland China are conducted under one of the mechanisms permitted by PIPL, including the Cyberspace Administration of China security assessment, the standard contract for cross-border transfers, or recognized certification, as applicable to the relevant data flow. We obtain separate consent for cross-border transfers where required and provide affected individuals with the notice required under PIPL.
9.3 PDPO and PDPA transfers
Cross-border transfers from Hong Kong are subject to the requirements of the PDPO. Transfers from Singapore are made with comparable protection as required by the PDPA, through contractual safeguards or other legally recognized means.
10. Data retention
We retain personal information only for as long as needed to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements, and to enforce our agreements. The criteria we apply include the nature and sensitivity of the data, the purposes for which we process it, applicable legal retention obligations, and the risks of unauthorized use or disclosure.
Indicative retention periods (subject to the active processing-activity records):
| Category | Indicative retention |
|---|---|
| Active child account data | For the duration of the child's enrolment in the Services; subject to parental or institutional instructions to delete. |
| Parental consent records | Seven (7) years after the child's account is closed, to demonstrate compliance under COPPA, GDPR Article 7(1), and equivalent regimes. |
| Educator and administrator account data | For the duration of the user's affiliation with the Services, plus a reasonable period thereafter for security and audit purposes. |
| Payment and billing records | As required by applicable tax and accounting laws (typically 7 years). |
| Security and audit logs | Up to 24 months, depending on the log type and applicable security framework requirements. |
| Marketing communications records | Until consent is withdrawn, plus a reasonable suppression-list retention period thereafter. |
| Backup copies | Rolling retention not exceeding 90 days, after which restored data is re-deleted on the next backup cycle. |
When personal information is no longer needed, we delete or irreversibly anonymize it, subject to permitted legal exceptions.
11. Your rights
Depending on where you are located and the law applicable to your relationship with Linxed, you have certain rights in respect of your personal information. We honour rights requests from data subjects directly and, where applicable, from parents on behalf of their children. Institutional account holders should contact their school administrator in the first instance.
11.1 Rights under GDPR / UK GDPR
- Right of access — to obtain confirmation of whether we process your personal data and a copy of that data.
- Right to rectification — to have inaccurate or incomplete personal data corrected.
- Right to erasure ("right to be forgotten") — in defined circumstances.
- Right to restriction of processing — in defined circumstances.
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object — to processing based on legitimate interests or for direct marketing.
- Rights related to automated decision-making and profiling — we do not currently make decisions about users based solely on automated processing that produce legal or similarly significant effects.
- Right to withdraw consent — at any time, without affecting the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint — with your local supervisory authority (see Section 16).
11.2 Parental rights under COPPA
If you are the parent or legal guardian of a child whose personal information has been collected by Linxed, you may at any time:
- Review the personal information collected from your child;
- Request that we delete the personal information collected from your child;
- Refuse to permit Linxed to further collect or use the child's personal information;
- Revoke previously given consent.
To exercise any of these rights, contact us at privacy@linxed.com. We may need to verify your identity before acting on your request.
11.3 Rights under PIPL
Subjects under PIPL have rights to know, to decide, to access, to copy, to transfer, to correct, to delete, and to obtain explanations regarding the processing of their personal information, and may withdraw consent at any time.
11.4 Rights under PDPO and PDPA
Subjects under the Hong Kong PDPO and Singapore PDPA have rights to access and correct their personal data and may withdraw consent (subject to legal and contractual restrictions).
11.5 Rights under U.S. state laws
Where applicable, residents of California, Virginia, Colorado, Connecticut, Utah, and other U.S. states with comprehensive privacy laws have rights to access, delete, correct, port, and opt out of certain processing activities. Linxed does not sell personal information and does not share personal information for cross-context behavioural advertising; the "Do Not Sell or Share" right therefore has no practical effect on our processing, but we honour requests in good faith.
11.6 How to exercise your rights
To exercise any right, contact privacy@linxed.com with sufficient information for us to identify you and process the request. We respond within the time periods required by applicable law (typically 30 days under GDPR; 45 days under most U.S. state laws). We will not discriminate against you for exercising a right.
12. How we protect personal information
We implement appropriate technical and organizational measures designed to protect personal information against unauthorized or unlawful processing and accidental loss, destruction, damage, alteration, or disclosure. These measures include:
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest, including database and backup encryption;
- Access controls based on the principle of least privilege, with multi-factor authentication for administrative access;
- Logging, monitoring, and intrusion detection across our production environment;
- Regular vulnerability scanning, patching, and code review;
- Background-checked personnel, confidentiality agreements, and periodic security and privacy training;
- Documented incident-response procedures including notification timelines aligned to applicable law (e.g., 72-hour notification to supervisory authorities under GDPR);
- Business-continuity and disaster-recovery procedures;
- Vendor due-diligence and ongoing risk assessment for all sub-processors with access to personal information.
No internet-based service can guarantee absolute security. We continuously improve our controls and align our security program to recognized frameworks (currently working toward SOC 2 Type I readiness and ISO/IEC 27001:2022 alignment).
13. Cookies and similar technologies
We use cookies, local storage, and similar technologies to operate the Services, remember your preferences, understand usage, and deliver features you request. We classify cookies into the following categories:
- Strictly necessary — required for authentication, security, and core functionality. These cannot be disabled.
- Preference — remember your settings and choices.
- Analytics — help us understand product usage in aggregate; configured for children's accounts to minimize identifiability.
- We do not use advertising cookies on children's accounts.
Where required by applicable law (including under the EU ePrivacy framework), we obtain consent before placing non-essential cookies, via our cookie-consent banner. You may withdraw or change your preferences at any time. For details of specific cookies in use, see our Cookie Notice at https://linxed.com/cookie-notice.
14. Marketing communications
We send marketing and product-update communications only to adults (parents, educators, administrators) who have opted in. We never send marketing communications to children. Every marketing email includes a one-click unsubscribe link. You can manage preferences at any time at https://linxed.com/preferences or by contacting us.
15. Changes to this Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify affected users by email, in-product notice, or another appropriate means before the change takes effect. The "Last Updated" date at the top of this Policy indicates when the most recent changes took effect. Previous versions are available on request.
For changes that materially affect children's personal information, we will obtain new verifiable parental consent where required by applicable law.
16. Supervisory authorities and complaints
You have the right to lodge a complaint with a supervisory authority if you consider that our processing of your personal information infringes applicable data-protection law. The relevant authorities include:
- Hong Kong — Office of the Privacy Commissioner for Personal Data (PCPD): https://www.pcpd.org.hk
- European Economic Area — the data protection authority of your member state (a list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en).
- United Kingdom — Information Commissioner's Office (ICO): https://ico.org.uk
- Singapore — Personal Data Protection Commission (PDPC): https://www.pdpc.gov.sg
- United States — Federal Trade Commission (for COPPA): https://www.ftc.gov; relevant U.S. state attorneys general.
- Mainland China — Cyberspace Administration of China (CAC): http://www.cac.gov.cn
We would, however, appreciate the opportunity to address your concerns directly before you approach a regulator. Please contact privacy@linxed.com.
17. How to contact us
If you have any questions, requests, or concerns about this Privacy Policy or our handling of personal information, please contact us at:
| Postal address | Linxed Limited, Hong Kong SAR |
|---|---|
| Email - general privacy queries | privacy@linxed.com |
| Email - Data Protection Officer | dpo@linxed.com |
| Email - parental-rights requests | parents@linxed.com |
| EU representative (Art. 27 GDPR) | Not currently appointed. Contact privacy@linxed.com |
| UK representative (Art. 27 UK GDPR) | Not currently appointed. Contact privacy@linxed.com |