V3
Effective as of April 5, 2026

Privacy Policy

This Global Privacy Policy (“Policy”) describes how LINGOPASS TECNOLOGIA LTDA, CNPJ 42.567.596/0001-56 (“Lingopass”), handles personal data within the Lingopass Ecosystem. It is based on the most protective standard (GDPR) and includes jurisdiction-specific addenda. It applies to users, client employees, applicants, scholarship recipients, and visitors in Brazil, Latin America, the Americas, and Europe.

CLAUSE 1 — WHO WE ARE AND SCOPE

1.1. Lingopass, a data controller based in Brazil, complies with the LGPD in all data processing activities. When services are provided to individuals located in the European Union, the GDPR also applies (Art. 3(2)); in the United Kingdom, the UK GDPR applies; and in the Americas, applicable local laws apply.

1.2. Most data subjects are employees of corporate clients. When the processing is part of a program contracted by the employer, the corresponding legal bases and any exemptions applicable to employment data in certain jurisdictions are observed.

CLAUSE 2 — DATA WE PROCESS

2.1. We process: (i) registration data (name, email, phone number, CPF when applicable); (ii) usage, progress, and engagement data; (iii) assessment and placement test results; (iv) voice samples for proficiency assessment, under the “no voiceprint” principle; (v) payment data (processed by a third-party provider); (vi) browsing data and cookies; and (vii), on Empowering Talents, voluntarily provided socioeconomic and diversity data.

2.2. As a precaution, the voice is treated as sensitive personal data, strictly for the purpose of proficiency assessment, with minimal retention and secure disposal; it does not generate a biometric identifier nor is it used for identification.

CLAUSE 3 — PURPOSES AND LEGAL BASES

3.1. We process personal data for the purposes and on the legal bases listed below, in combination (in layers) when necessary:

  • Provision of services and account management — LGPD: Performance of a contract (Art. 7, V); GDPR: Performance of a contract (Art. 6(1)(b)).
  • Corporate program (client employee) — LGPD: Performance of a contract / legitimate interest of the employer; GDPR: Contract / legitimate interest (Art. 6(1)(b)(f)).
  • Voice Assessment (Proficiency) — LGPD: Specific and distinct consent (Art. 11, I); GDPR: Explicit consent (Art. 9(2)(a)).
  • Customer Support and Service Communications — LGPD: Performance of a contract / legitimate interest; GDPR: Contract / legitimate interest.
  • Marketing (where applicable) — LGPD: Consent; GDPR: Consent.
  • Security, fraud prevention, and auditing — LGPD: Legitimate interest / legal obligation; GDPR: Legitimate interest / legal obligation.
  • Compliance with Legal and Tax Obligations — LGPD: Legal obligation (Art. 7, II); GDPR: Legal obligation (Art. 6(1)(c)).
  • Product improvement, statistical and scientific research — LGPD: anonymized/aggregated data, outside the scope of the Law (Art. 12); when the use of identifiable sensitive data is essential, specific and prominent consent (Art. 11, I) or processing by a partner research organization (Art. 11, II, “c”). GDPR: statistical and scientific research purposes subject to the safeguards of Art. 89(1) and, for sensitive data, explicit consent (Art. 9(2)(a)) or Art. 9(2)(j).
  • Sustainability/ESG and diversity reports for corporate clients — LGPD/GDPR: anonymized or aggregated data, without re-identification, in accordance with the legitimate interest of the client-employer as the data controller for these indicators.

3.2. In the context of recruitment, Lingopass does not base its assessment solely on the candidate’s consent, but rather on a contractual basis or the employer’s legitimate interest, with human oversight.

CLAUSE 4 — SHARING AND OPERATORS

4.1. We share data with operators/subprocessors that are strictly necessary (cloud services, proficiency assessments, live classes, payments, artificial intelligence), under contract and with security measures in place. The updated list is available in the Trust Center. We do not sell personal data.

CLAUSE 5 — INTERNATIONAL TRANSFER

5.1. Operational data is preferably stored in Brazil. Transfers between Brazil and the European Economic Area do not require any additional mechanisms, due to the mutual adequacy in effect since January 27, 2026. For other countries, we adopt standard clauses from the ANPD (Res. 19/2024) and/or the European Union, with additional safeguards, and, where applicable, specific transfer provisions under local law (e.g., intra-group transfers).

CLAUSE 6 — RETENTION AND DISPOSAL

6.1. We retain data for as long as necessary to fulfill our purposes and legal obligations. Retention periods: account (during the account’s active period and for up to 3 years after closure), financial and transaction data (up to 7 years), communications (up to 2 years), learning data (up to 5 years), and voice samples (minimum retention period consistent with the evaluation). Once these periods have expired, the data is securely deleted or anonymized.

CLAUSE 7 — RIGHTS OF THE ACCOUNT HOLDER

7.1. The data subject may exercise the rights to confirmation, access, correction, anonymization, portability, erasure, information regarding sharing, withdrawal of consent, and objection (LGPD Art. 18), as well as the corresponding rights under the GDPR (Arts. 15–22), including the right to review automated decisions.

7.2. Requests are processed through the [email protected] channel within the legally prescribed timeframes.

CLAUSE 8 — AUTOMATED DECISIONS AND AI

8.1. We use AI for scoring and recommendations. Data subjects have the right to request a review and challenge automated decisions that affect them (LGPD Art. 20 / GDPR Art. 22), with meaningful human oversight. Further details are provided in the AI Governance Policy.

CLAUSE 9 — SECURITY

9.1. We have implemented the technical and organizational measures described in the Information Security Policy and in the Trust Center (encryption, access control, MFA, logging, vulnerability management). In the event of an incident, we notify the Authority and the data subjects within the legally required timeframes (ANPD: within 3 business days; GDPR: within 72 hours to the Authority).

CLAUSE 10 — CHILDREN AND ADOLESCENTS

10.1. The services are intended for individuals 18 years of age or older, except as provided for in the Child and Adolescent Protection Policy, with verifiable parental consent where applicable and in accordance with applicable jurisdictional rules (EU: 16, which may be lowered to 13; U.S.: 13, under COPPA).

CLAUSE 11 — COOKIES

11.1. We use cookies in accordance with our Cookie Policy, with granular consent and the option to opt out just as easily as to opt in.

CLAUSE 12 — SUPERVISOR AND REPRESENTATIVE

12.1. Data Protection Officer (DPO): Alexandrine Brami — [email protected]. Before offering services to data subjects in the European Union and the United Kingdom, Lingopass will appoint a representative in those jurisdictions (Article 27 of the GDPR and the UK GDPR).

CLAUSE 13 — RESEARCH, STATISTICS, AND SUSTAINABILITY (ESG) REPORTS

13.1. Lingopass may process data for statistical and scientific research purposes and to prepare performance, diversity, and sustainability (ESG) reports requested by corporate clients. As a general rule, this processing is carried out exclusively on anonymized or aggregated data from which it is not possible to re-identify the data subject, in accordance with Article 12 of the LGPD and the safeguards set forth in Article 89(1) of the GDPR (data minimization, pseudonymization, and access restriction). Anonymization follows a standard based on the risk of re-identification, in line with ANPD guidelines.

13.2. The sustainability and diversity reports provided to clients contain only aggregated statistical indicators, with no data that directly or indirectly identifies individual employees, especially when such data involves sensitive information voluntarily reported through Empowering Talents (socioeconomic and diversity data).

13.3. When, in exceptional cases, a research purpose requires the use of sensitive personal data in an identifiable form—including voice samples—the processing shall be subject to the data subject’s specific and explicit consent (LGPD Art. 11, I; GDPR Art. 9(2)(a))—or it will be conducted by a qualified research organization as defined in LGPD Art. 5, XVIII, under an agreement that defines roles and safeguards. Lingopass, as a for-profit company, does not rely solely on the legal basis of “studies by a research organization” for its own processing of identifiable data.

13.4. The security safeguards set forth in Clause 9 and the time limits set forth in Clause 6 apply; anonymized data is retained indefinitely, as it does not constitute personal data.

CLAUSE 14 — AMENDMENTS

14.1. This Policy may be updated; relevant changes will be communicated, and previous versions will be archived, along with their effective dates.

ADDENDUMS BY JURISDICTION (updated to V1.1)

Brazil — LGPD (Law 13,709/2018)

Data protection officer identified; ANPD standard clauses for transfers to countries without an adequacy decision; incident reporting to the ANPD and the data subject within 3 (three) business days (ANPD Resolution No. 15/2024); data subject support channel.

European Union and the United Kingdom — GDPR / UK GDPR

Application based on extraterritoriality (Art. 3(2)) when data is offered to individuals in the EU/UK; representative (Art. 27) prior to the offer; explicit consent for sensitive data; DPIA for large-scale processing (Art. 35); rights under Arts. 15–22, including the right to review automated decisions (Art. 22); transfers between the EU and Brazil without additional safeguards, pursuant to the mutual adequacy decision of January 27, 2026.

United States

There is no general federal law; state privacy laws (in effect in about 20 states by 2026) and industry-specific regulations apply. Key points for Lingopass:

• Employment/B2B data: Various state laws exempt employee data and B2B context data—since most data subjects are employees of corporate clients, some of these laws may not apply.

• COPPA: Processing data from children under 13 requires verifiable parental consent (in accordance with the Policy on the Protection of Children and Adolescents).

• FERPA: When the client is an educational institution, educational records are subject to specific rules; Lingopass acts as a “school official” under the institution’s supervision.

• Opt-out / universal signals: Compliance with opt-out mechanisms (including Global Privacy Control) for cookies and marketing, in accordance with applicable state law.

Canada

Federal law: PIPEDA (Bill C-27/CPPA was not passed), which does not prohibit international transfers but holds the exporter accountable.

Quebec — Bill 25: stricter rules, similar to the GDPR — consent for sensitive data, a privacy impact assessment (PIA) prior to technology projects that process personal data, notification when automated decisions are made, and the rights to opt-out and data portability. For data subjects in Quebec, these requirements must be observed (in line with our RIPD and the AI clause).

Mexico — LFPDPPP (effective as of March 21, 2025)

Privacy notice in accordance with the new law (identification of processed data, sensitive data, and purposes that do or do not require consent). Domestic and international transfers without consent are permitted only in the cases set forth in Article 36, including transfers between companies within the same group that share common policies—a useful foundation for the structure of multinational clients. Current competent authority following the dissolution of the INAI.

Chile — Law 21,719

New GDPR-style regulations, fully effective on December 1, 2026 (data breach notifications, strengthened rights, steep penalties). Ensure compliance before the regulations take effect.

The Rest of Latin America

Argentina (Law 25,326, with a reform currently pending) and Uruguay have been deemed compliant by the European Union, which facilitates data transfers to and from Europe. Colombia (Law 1581/2012), Peru (Law 29733), Ecuador (LOPDP), and Paraguay (law to be enacted in 2025): compliance with local laws, covered by this Policy and the DPA. None of these jurisdictions requires local data residency in accordance with Brazilian standards.

Note: For data subjects in the United States and Canada, it is recommended that a local attorney review the policy when it involves the processing of personal information of minors (COPPA), use by educational institutions (FERPA), or data subjects in Quebec (Bill 25).

Take free conversation classes:
I am a Student
An arrow pointing to the upper-right corner. Represents a link to another page
Get the latest news and exclusive content in our newsletters.
Thank you for signing up!
Invalid email address. Please try again or use a different email address.
Powered by major partners:
Cubo Itaú Startups 2022 LogoDomo Invest LogoAWS EdStart Member LogoGlobal Compact LogoEndeavor LogoSantander X LogoMicrosoft for Startups Logo
©Lingopass - All rights reserved. Terms of Use and Privacy Policy