How SpokenEdge collects, uses, and protects your information.
Effective: June 10, 2025FERPA · COPPA · GDPRData never sold
Spoken Edge ("we", "us", or "our") operates the SpokenEdge platform —
a real-time multilingual communication tool for educational institutions. This Privacy Policy explains
what personal information we collect, why we collect it, how we use and protect it, and your rights. By
using SpokenEdge you agree to this policy. Where applicable, a school's use is also governed by our
Terms of Service and a Data Processing Agreement between Spoken Edge and the
institution.
01
Who We Are and Our Role
Spoken Edge acts as a data processor on behalf of the educational institutions
("schools") that subscribe to our platform. Each school is the data controller for
its students', teachers', and administrators' personal data. We process that data only as instructed
by the school and as necessary to deliver the service.
For data we collect about our own business relationships (e.g. billing contacts), we act as an
independent data controller.
02
Information We Collect
Account & profile information
Full name, email address, phone number (optional)
Role: admin, teacher, or student
Grade level and preferred language (students only)
School name and institution identifier
Usage and session data
Session start/end times and duration
Text messages exchanged within a session
Translation requests and output (via Google Cloud Translation API)
Text-to-speech requests and audio output (via Google Cloud TTS API)
Technical & analytics data
Log data: IP addresses, browser type, pages visited, timestamps
Audit log events: administrative actions for security and compliance
Billing information
Collected and processed exclusively by Stripe. We never see or store full card
numbers, CVV codes, or bank account details. We retain only Stripe-issued customer and subscription
identifiers.
03
How We Use Your Information
Provide, operate, and improve the SpokenEdge platform
Authenticate users and maintain account security
Enable real-time multilingual communication between teachers and families
Process translation and text-to-speech via Google Cloud APIs
Generate usage reports for school administrators
Process subscription payments through Stripe
Send essential service communications (account setup, security alerts, billing receipts)
Investigate and resolve support requests
Comply with legal obligations
Important
We do not use student data for advertising, behavioural profiling, or any purpose
unrelated to providing educational services.
04
Third-Party Services and Data Processors
We share data with the following processors solely to deliver our service:
Google Cloud · Translation & TTS
Session text submitted for translation or speech synthesis. Google does not use
this data to train its models under enterprise terms.
Stripe · Payment Processing
Billing contact name/email and subscription details. Card data is handled
exclusively by Stripe and never passes through our servers.
Cloud Host · Infrastructure
Application data at rest and in transit, hosted on SOC 2 certified infrastructure
with encryption at rest.
We do not sell, rent, or trade personal information to any third party for their own commercial
purposes.
05
FERPA Compliance (US Educational Records)
For US schools, student data processed through SpokenEdge constitutes "education records" under the
Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g. We act as a
"school official" with a legitimate educational interest:
We use student education records only to provide the contracted educational service
We do not disclose education records to outside parties without consent, except as required by
law
We return or securely destroy student records upon request or subscription termination
We will notify the school of any confirmed data breach affecting student records
School administrators may review, correct, and request deletion of their students' records
FERPA Status
SpokenEdge operates under the FERPA "school official" exception. Schools maintain ultimate control
over their student records.
06
COPPA Compliance (Children Under 13)
The Children's Online Privacy Protection Act (COPPA) applies to services directed at
children under 13. Students are registered by school administrators — not by the children
themselves. Under COPPA's school-consent exception, schools provide consent on behalf of
parents for educational purposes.
We collect only the minimum information necessary to provide the service
We do not direct advertising to children or build behavioural profiles
Parents may request access, correction, or deletion via their school administrator
School administrators may delete student accounts at any time from their dashboard
COPPA Status
Student accounts are created and managed by school administrators, not directly by students or
parents.
07
GDPR and UK GDPR Rights (EU and UK Users)
If you are in the EU or UK, you have the following rights under the GDPR / UK GDPR:
Right of access
Request a copy of the personal data we hold about you.
Right to rectify
Request correction of inaccurate or incomplete data.
Right to erasure
Request deletion where there is no compelling reason to continue processing.
Right to restrict
Request we restrict processing in certain circumstances.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests.
To exercise any of these rights, email info@spokenedge.com. We respond within 30 days. You
may also lodge a complaint with your national data protection authority.
Legal Basis
(a) Performance of a contract · (b) Legitimate interests (security, analytics) · (c) Compliance
with legal obligations.
08
Data Retention
While active
Active accountsData retained for the full duration of the school
subscription.
90 days
Post-subscriptionSchool data retained after termination for data
export, then permanently deleted.
7 years
Billing recordsPayment and invoice records retained to comply with
financial regulations.
12 months
Audit logsSecurity and administrative audit logs retained for
compliance review.
30 days
Database backupsBackups retained for disaster recovery, then
overwritten.
School admins can request immediate deletion by emailing info@spokenedge.com.
09
Data Security
We implement the following technical and organisational security measures:
TLS 1.2+ encryption in transit
bcrypt password hashing (never plaintext)
SHA-256 one-way reset token hashes
Short-lived JWT sessions with auto-expiry
Multi-tenant data isolation per school
Tamper-evident audit logs
Rate limiting on all authentication endpoints
Production access restricted to authorised staff
Security concern?
If you believe your account has been compromised, contact us immediately at
info@spokenedge.com.
10
Cookies and Tracking
We use only essential session cookies required for authentication. We do not use:
Third-party advertising or tracking cookies
Analytics cookies (e.g. Google Analytics) that track users across sites
Fingerprinting or other cross-site tracking technologies
Authentication tokens are stored in your browser's localStorage solely to maintain your login
session.
11
Data Transfers
Our infrastructure is primarily hosted in the United States. If you access from the EU, UK, or another
jurisdiction with data-transfer restrictions, your data may be transferred to and processed in the
US. We rely on the EU–US Data Privacy Framework and/or Standard Contractual
Clauses (SCCs) for such transfers where required.
12
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify school administrators of material
changes by email at least 30 days before the changes take effect. The "Effective
date" at the top always reflects the current version. Continued use constitutes acceptance of the
updated policy.
13
Contact Us
For privacy-related questions, data access requests, or to report a security concern — we aim to
respond within 5 business days and resolve enquiries within 30 days.