Privacy Policy

Last updated: August 2026 (version 2026-08-01)

1. Controller and Contact

New World English ("NWE", "we", "us") is the data controller for personal data processed via nwenglish.com and all subdomains. Our Data Protection Officer can be reached at privacy@nwenglish.com. We respond to Data Subject Access Requests within 30 days of receipt.

2. Information We Collect

  • Identity: name, email, display name, avatar.
  • Profile: country, phone, birth date, English level, learning goals, time zone.
  • Usage: lesson history, messages, homework, reviews, progress reports.
  • Payment: Stripe customer id. Card numbers never reach our servers β€” tokenized by Stripe.
  • Technical: IP address, browser, locale, cookies (essential cookies are mandatory; analytics and marketing cookies are opt-in).
  • Tutor verification: identity documents, certifications, payout bank details (Tutors only).

3. Legal Basis for Processing

For users in the EEA, UK, or Switzerland, GDPR Article 6 requires us to identify a lawful basis for each processing activity. The table below lists each processing purpose, the category of personal data involved, and the lawful basis we rely on.

Processing purpose Data category Lawful basis (GDPR Art. 6)
Account registration, lesson booking, payment, tutor payout Identity, profile, usage, payment Contract (6(1)(b))
Tax and accounting record retention, KYC/AML for tutors Financial, identity documents Legal obligation (6(1)(c))
Security logging, fraud detection, dispute resolution Technical logs, communications Legitimate interest (6(1)(f))
Analytics and marketing cookies, marketing email Browsing behaviour, email engagement Consent (6(1)(a)) β€” withdraw anytime
Service improvements, product analytics, A/B testing Aggregated usage data Legitimate interest (6(1)(f))

For users in Japan, we process personal data per the Act on the Protection of Personal Information (APPI), specifying the purpose of use at or before collection and obtaining consent where required. Where GDPR and APPI both apply, we apply the stricter standard.

4. Purpose of Use

We use your personal data to:

  • Operate, maintain, and improve the Service.
  • Register your account, verify identity, and authenticate logins.
  • Process bookings, payments, refunds, and payouts.
  • Deliver lessons and facilitate messaging and homework review.
  • Send transactional email (password reset, lesson reminders, payout notices).
  • Send marketing email β€” only with opt-in consent; withdrawable anytime.
  • Detect fraud, abuse, and unauthorized access.
  • Comply with legal obligations (tax, KYC, law enforcement requests).

5. Disclosure to Third Parties

We do not sell your personal information. We share it only:

  • With the Tutor or Student involved in a Lesson Agreement (identity, communications, homework).
  • With the sub-processors listed in Section 7 (Stripe, Google, Resend, Sentry).
  • When required by law, court order, or law enforcement request.
  • In connection with a merger, acquisition, or sale of all or part of NWE's business.
  • With your consent.

6. Sensitive Information

We do not knowingly collect information about your ideology, creed, religion, race, nationality, political opinion, medical history, or criminal record, except where required for legal compliance (e.g. KYC screening) and you consent in writing. If you believe we have collected such information in error, contact privacy@nwenglish.com.

7. International Transfers

Your data may be processed outside your home country by the following sub-processors, each covered by Standard Contractual Clauses, an adequacy decision, or equivalent safeguards:

  • Stripe (payment processing) β€” United States. Stripe Privacy
  • Google (Calendar, OAuth, reCAPTCHA, Meet) β€” United States.
  • Resend (transactional email delivery) β€” United States.
  • Sentry (error monitoring) β€” United States / EU depending on configuration.
  • Cloudflare / CDN (DDoS protection, edge caching) β€” global.

For EU/UK users, transfers to third countries are made under the European Commission's Standard Contractual Clauses or rely on an adequacy decision.

8. Retention Periods

  • Financial records (Stripe customer id, payments, invoices): 7 years β€” legally required for tax audit in JP/EU/US.
  • Tutor KYC documents: 5 years after the last transaction (AML compliance).
  • Messages between users: 1 year after the last message, then deleted.
  • Homework submissions: retained for the lifetime of the account, then deleted or anonymized.
  • Inactive accounts: 2 years of no login β†’ personal data anonymized; financial skeleton retained per above.
  • Server logs: 90 days.
  • Cookie consent records: 3 years.

9. Data Security

  • Passwords hashed with Bcrypt.
  • Session and reset tokens are 32-byte cryptographic randoms hashed with SHA-256 before storage.
  • HTTPS enforced site-wide; HSTS enabled in production.
  • Card data never touches our infrastructure β€” tokenized by Stripe.
  • Access controls, audit logs, and encryption at rest on backups.
  • Annual security review and pen-test; staff trained on APPI and GDPR.

10. Your Rights (GDPR Articles 15–22, APPI)

  • Access (GDPR Art. 15; APPI Β§28): request a copy of your personal data.
  • Rectification (Art. 16; APPI Β§29): correct inaccurate data via Settings or by contacting the DPO.
  • Erasure (Art. 17): request account anonymization. Financial records are retained for 7 years for tax audit; your identity is wiped but the payment skeleton remains.
  • Portability (Art. 20): machine-readable JSON export at /account/export.
  • Objection (Art. 21; APPI Β§30): stop processing for direct marketing at any time.
  • Withdrawal of consent (Art. 7(3)): cookie preferences and marketing consent are withdrawable without affecting the lawfulness of prior processing.
  • Restriction (Art. 18): request temporary halt while a rectification claim is investigated.
  • Complaint to supervisory authority β€” you may lodge a complaint with your local data protection authority.

11. Cookies

Essential cookies (authentication, CSRF, locale) are set on first visit. Analytics and marketing cookies are only set after you accept them in the cookie banner. You can revisit your choice by clearing the cookie_consent_id cookie. For details on each category, see the cookie banner.

12. Children's Privacy

Students under 18 must register through a parent or guardian account. Parents have full access to the child's data, communications, and bookings. We do not knowingly collect personal data from children under 13 except via a parent-managed account. We process children's data on the legal basis of parental contract and consent. Verified parental requests for access, correction, or deletion are honoured within 30 days.

13. Communications Monitoring

We may review, scan, or analyze messages, homework, and other communications for fraud prevention, dispute resolution, regulatory compliance, product improvement, research, and enforcing our Terms. We use automated methods where possible and may conduct limited manual review where necessary. We do not sell reviews or analyses of your communications, nor use them to send third-party marketing.

14. External Services

The Service integrates with external tools β€” Zoom, Google Meet, Google Calendar, LINE, and others. If you link an external account, we exchange only the information necessary for the integration. The external provider's terms and privacy policy apply to your use of their service.

15. Data Erasure and Backups

When you request erasure, we anonymize your personal data in the production database. Information you have shared with other users (reviews, forum postings) may remain visible but attribution to you is removed. Residual copies in our backup systems may persist for up to 60 days; backups are access-controlled and not actively queried.

16. Data Subject Access Requests

Email privacy@nwenglish.com from the address on your account. We respond within 30 days. If we cannot verify your identity, we may request additional information. You may lodge a complaint with your local supervisory authority if you believe our processing violates GDPR or APPI.

17. Subcontractors and Trustees

Where we entrust personal data processing to a subcontractor, we execute a written agreement imposing confidentiality and data-protection obligations consistent with this Policy and applicable law. We supervise subcontractors on an ongoing basis.

18. Continuous Improvement

We periodically review and update our personal-data management system. Adjustments reflect changes in business environment, social expectations, advances in information security technology, and establishment or revision of laws.

19. Revisions to This Policy

We may revise this Policy at any time. Material revisions are announced by email or in-product notice and, where required by GDPR or APPI, we will obtain your consent (e.g. via the re-accept flow). The "Last updated" date above reflects the most recent revision.

20. Governing Law and Jurisdiction

This Policy is governed by the laws of Japan. The Tokyo District Court or Tokyo Summary Court has exclusive jurisdiction over any dispute arising out of or relating to this Policy.

21. Language

This Policy is written in English. Translations into Japanese, Chinese, and other languages are provided for convenience only. In case of conflict, the English version prevails.

22. Contact

For any privacy-related question or request, contact privacy@nwenglish.com. For account or service questions, contact support@nwenglish.com. For legal notices, contact legal@nwenglish.com.