Privacy Policy
We take children's privacy extremely seriously. This policy explains how we collect, use, store, and protect personal data.
Phoque ("we", "us", "our") is operated by TalentOptima Ltd, registered as a Limited Company (#15923883) in England & Wales. Registered Address: 2nd Floor, College House, 17 King Edwards Road, Ruislip, London HA4 7AE, United Kingdom.
Phoque is designed for students aged 13-18 preparing for UK examinations (GCSE, A-Level), and we have built our platform with privacy by design principles throughout.
This policy applies under UK GDPR. Phoque is operated from the United Kingdom by TalentOptima Ltd and is currently aimed at UK-resident learners. We do not actively target users in the European Economic Area (EEA). UK GDPR rights apply to all data subjects regardless of location.
This policy should be read alongside our Terms of Service and GDPR Compliance pages.
1. Who We Are
Data Controller
TalentOptima Ltd
Trading as: Phoque
Company #15923883 (England & Wales)
2nd Floor, College House
17 King Edwards Road
Ruislip, London HA4 7AE
United Kingdom
Data Protection Contact
Email: privacy@phoque.ai
For the purposes of UK GDPR and the Data Protection Act 2018, TalentOptima Ltd is the data controller responsible for your personal data.
2. Information We Collect
2.1 Information You Provide
Parent/Guardian Account:
- Full name and email address
- Password (encrypted)
- Payment information (processed via Stripe—we don't store card details)
Student Profile:
- First name (surname optional)
- Date of birth, year group, target grades
- Target examination board and qualification (e.g., Pearson Edexcel International GCSE)
2.2 Information We Collect Automatically
Learning Analytics
- • Session timestamps and duration
- • Lesson completion status
- • Response accuracy and timing
- • Navigation patterns
Technical Data
- • IP address (anonymised after 30 days)
- • Browser type and version
- • Device type
- • Approximate location (country only)
2.3 Learning DNA Profile
We analyse learning patterns to create a personalised profile that helps us adapt lessons. This includes:
Profiling Disclosure (UK GDPR Art. 22)
How we use profiling: Phoque builds a "Learning DNA" profile based on your interactions. This profile powers:
- • Adaptive difficulty: Adjusts lesson complexity based on your performance
- • Topic recommendations: Suggests what to study next
- • Grade predictions: Estimates potential exam grades (informational only)
Your rights: You can request human review of any automated decision, object to profiling, or request deletion of your Learning DNA at any time via privacy@phoque.ai.
2.4 Audio Processing in Speech Widgets
Some speech widgets can analyse a short recording to give pronunciation feedback. This is optional and only runs when you choose to record.
- • We process the recording to generate feedback for that attempt.
- • Raw audio recordings are not saved to your Phoque profile or lesson history.
- • We keep non-audio learning signals (for example score, attempt count, and feedback summary) to support learning progress.
3. How We Use Your Information
| Purpose | Legal Basis (UK GDPR) |
|---|---|
| Providing the learning service | Contract performance |
| Personalising lessons | Legitimate interest |
| Generating parent reports | Contract performance |
| Grade predictions | Legitimate interest |
| Processing payments | Contract performance |
| Marketing communications | Consent (opt-in only) |
| Improving our AI | Legitimate interest |
We do NOT:
- • Sell personal data to third parties
- • Use student data for advertising
- • Create advertising profiles from children's data
- • Share student data with schools without explicit consent
- • Use facial recognition or biometric identification
4. Children's Privacy
Phoque is designed for students aged 13-18. We comply with UK GDPR, the UK Age Appropriate Design Code, and the Data Protection Act 2018.
Parental Consent Required
Students under 18 can only access Phoque through a verified parent/guardian account.
Minimal Data Collection
We only collect data necessary for the learning experience.
No Behavioural Advertising
We never use children's data for advertising purposes.
Privacy by Default
Privacy-protective settings are enabled by default.
Age-Appropriate Design
No dark patterns, no engagement manipulation techniques.
Parental Access
Parents can view, export, or delete their child's data anytime.
6. International Data Transfers
Your data is primarily stored in the European Union (Ireland and Germany). When we transfer data outside the UK/EU, we use appropriate legal safeguards to protect your rights:
For US Transfers
- UK-US Data Bridge (for certified providers like OpenAI, Stripe)
- IDTA + UK Addendum (for non-certified US providers)
For Other Transfers
- UK International Data Transfer Agreement (IDTA)
- EU Standard Contractual Clauses + UK Addendum
- Transfer Impact Assessments where required
What this means for you: Wherever your data goes, it receives the same level of protection it would in the UK. We only work with providers who meet our strict security and privacy standards.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account data | Account + 2 years | Service provision |
| Payment records | 7 years | UK tax/legal requirements |
| Support communications | 3 years | Quality assurance |
| Technical logs | 90 days | Security/debugging |
After account deletion: Eligible live-store personal data is deleted within 72 hours. Backup-copy purge and verification are tracked separately and are not currently evidenced as complete within 30 days.
8. Your Rights
Under UK GDPR, you have the following rights:
Access
Request a copy of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion ("right to be forgotten")
Restriction
Limit how we process your data
Portability
Receive your data in a portable format
Objection
Object to processing based on legitimate interests
Withdraw Consent
Withdraw consent at any time
Complain
Lodge a complaint with the ICO
To exercise your rights: Email privacy@phoque.ai.
Response time: One calendar month from when we receive your request. If we need more time (up to two additional months for complex requests), we'll tell you why within the first month.
See our GDPR Compliance page for detailed instructions.
9. Data Security
Technical Measures
- Encryption in transit (TLS 1.3)
- Encryption at rest (AES-256)
- Field-level encryption for sensitive data
- Regular security audits
Organisational Measures
- Staff training on data protection
- Access controls (least privilege)
- Incident response procedures
- Regular policy reviews
What happens if there's a breach?
- • Notify the ICO within 72 hours (if required)
- • Notify affected users without undue delay
- • Take immediate steps to contain and remediate
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Email to your registered address
- Prominent notice on our website
- In-app notification
12. Contact Us
Privacy Questions
Email: privacy@phoque.ai
Data Protection, TalentOptima Ltd
2nd Floor, College House, 17 King Edwards Road,
Ruislip, London HA4 7AE, United Kingdom
