Staff & Instructor Privacy Notice
| Item | Details |
|---|---|
| Established | 26 September 2026 |
| Last updated | 26 September 2026 |
| Version | 1.0 |
Items marked "Instructors only" apply only to instructors. They do not apply to staff.
This Privacy Notice is provided in Japanese and English. If there is any inconsistency between the two versions, the Japanese version prevails.
1. Introduction
This Privacy Notice explains how ELT Education Inc. ("we", "us" or "our") handles the personal data of users of the business system "ELT Core Platform" (the "System") that we operate.
This notice does not form part of any employment contract or service agreement with users.
1.1 Who this notice applies to
| Who | Screen used | How we refer to them |
|---|---|---|
| Staff (including our employees and contractors, and the employees and contractors of the UK company ELT School of English Limited) | Staff screen (https://staff.elt-force.com) | Staff |
| Instructors | Instructor screen (https://instructor.my-elt.com) | Instructors |
| Anyone who opens a login page (before logging in) | https://staff.elt-force.com/login, https://instructor.my-elt.com/login | — |
Staff and instructors are together referred to as "users".
1.2 What data this notice covers
This notice covers the personal data of the users themselves.
In this notice, "personal data" means personal information and personal data as defined in Japan's Act on the Protection of Personal Information (APPI). For users to whom the UK GDPR or the EU GDPR applies, it also includes personal data as defined in those laws.
The personal data of customers (students and guardians) that users view in the course of their work is not covered by this notice. Users are obliged to protect the personal data of customers that they learn through their work. The details are set out in their contracts and our internal rules.
1.3 Applicable law
We handle personal data in accordance with Japan's APPI. The statements and rights in this notice that are based on the UK GDPR (United Kingdom) and the EU GDPR apply where, and to the extent that, those laws apply.
2. Who we are and how to contact us
2.1 The business operator
| Item | Details |
|---|---|
| Name | ELT Education Inc. (株式会社ELTエデュケーション) |
| Address | 5-32-12 Shiba, Minato-ku, Tokyo 108-0014, Japan |
| Representative | Tatsuya Tanaka, Representative Director |
2.2 Privacy contact
We accept questions, requests and complaints about how personal data is handled at the following contact.
| Item | Details |
|---|---|
| Email address | … |
| Where this notice is published | Instructor screen: https://instructor.my-elt.com/privacy, Staff screen: https://staff.elt-force.com/privacy |
2.3 Our relationship with the UK company
The UK company ELT School of English Limited is a separate legal entity from us. We operate the System, and employees and contractors of the UK company also use it as staff. In addition, some instructors have their contract with the UK company.
For this reason, we and the UK company use users' personal data jointly as follows.
| Item | Details |
|---|---|
| Statement of joint use | We and ELT School of English Limited jointly use the personal data described below |
| Personal data used jointly | Of the personal data described in Section 3, the data that employees and contractors of the UK company handle in their work (such as instructors' profiles, contact details, contracts, pay, lesson records, instructor notes and customer ratings, and staff members' names, email addresses and work records) |
| Parties to the joint use | ELT Education Inc.; ELT School of English Limited (Company No. 04497523, 35 Ballards Lane, London N3 1XW, United Kingdom) |
| Purposes of use | Us: the purposes described in Section 4. The UK company: managing staff who are its employees or contractors, and managing the instructors it contracts with (assigning lessons, calculating and paying fees, quality management, and work-related communication) |
| Party responsible for managing the personal data | ELT Education Inc. (address and representative as in 2.1) |
The role of each company under the UK GDPR / EU GDPR, by purpose of processing, is as follows.
| Processing | Role |
|---|---|
| Operating the System, security and responding to failures | We are the controller |
| Employment, contracts and pay of people who have a contract with the UK company | The UK company is the controller; we are a processor |
| Assigning lessons, quality management of instructors and work-related communication | The two companies are joint controllers |
| Evaluating the work of staff | The company that carries out the evaluation is the controller |
Requests and complaints about processing carried out as joint controllers can be made to the contact in 2.2.
3. Personal data we collect and where it comes from
The main personal data we handle in the System is as follows.
3.1 Data common to staff and instructors
| Category | Items | Source |
|---|---|---|
| Identification and contact | Name, email address | The user; within our organisation (invitation, recruitment and contracting) |
| Authentication | Password, role, account status, login times, multi-factor authentication (MFA) settings, Google account ID (if Google login is linked) | The user's own actions; records made by the System |
| Engagement | Scheduled date of leaving or contract end | Within our organisation |
3.2 Data for instructors only
| Category | Items | Source |
|---|---|---|
| Contract and pay | Bank account, contract details, rates of pay and allowances, contracting entity, contract periods, payment currency, etc. | The instructor; within our organisation (recruitment and contracting) |
| Contact details | Email addresses, telephone numbers, WhatsApp, call links used for lessons, etc. | Same as above |
| Profile | Date of birth, gender, CV, education, qualifications and work history, self-introduction, etc. | Same as above |
| Instructor notes | Work-related notes recorded by our staff (with categories such as reliability and significant incidents) | Our staff |
| Customer ratings | Ratings and comments given by customers | Customers |
| Work records | Lesson records (date and time, customer name, location, late submission and its reason, etc.), lesson schedules | Entered by the instructor; within our organisation |
| Calendar | Events in the instructor's Google Calendar | Google Calendar |
3.2a Work records of staff
| Category | Items | Source |
|---|---|---|
| Responsibilities | Customers, deals and meetings the staff member is responsible for | Within our organisation; entered by the user |
| Creating and updating records | The fact that the staff member created or updated records such as customer notes, instructor notes, deals and meeting records | The user's own actions |
| Carrying out processing | The fact that the staff member carried out actions such as changing a customer's enrolment status, refunds and plan changes, contract changes, and deletion requests and approvals | The user's own actions |
| Data import and export | The fact that the staff member imported or exported data | The user's own actions |
Activity logs and audit logs (3.4) are also treated as work records of staff.
3.2b Meeting records
The System contains records of meetings with customers (such as counselling sessions and trial lessons). Users are recorded as the person responsible for a meeting.
| Category | Items | Source | Applies to |
|---|---|---|---|
| Responsibility for meetings | The staff member responsible for the meeting; staff members who created or updated the record | Entered by our staff; our customer management tool (HubSpot) | Staff |
| Responsibility for trial lessons | The instructor responsible for the trial lesson; the instructor's feedback | Same as above | Instructors only |
| Meeting details | Date and time, method, outcome, next action, internal notes | Same as above | Those recorded as responsible |
3.3 Data we obtain from sources other than the user
| Data | Source | Applies to |
|---|---|---|
| Customer ratings | Customers (recorded by our staff) | Instructors only |
| Calendar events | Google Calendar | Instructors only |
| Instructor notes | Our staff | Instructors only |
| Name and email address of the person responsible | Our customer management tool (HubSpot) | Staff |
3.4 Data recorded automatically
| Type | Details | Applies to |
|---|---|---|
| Activity logs | What was done and when, IP address, browser information (User-Agent), device identifier, etc. | All users |
| Audit logs | Details of changes to data (values before and after the change), IP address, browser information | All users |
| Authentication information | Information needed for multi-factor authentication (MFA) and for keeping you logged in, trusted devices | All users |
| reCAPTCHA | Device and interaction information sent from the browser to Google on the login and password reset screens | Everyone who opens these screens |
3.5 Special category data and photographs
We do not aim to collect special care-required personal information such as health information (special category data under the GDPR) in the System. However, such information may be included in free-text fields or attachments such as CVs, notes and meeting records. If so, we handle it in accordance with this notice.
If we handle photographs of instructors and staff (such as profile photos) in the future, we will set the purpose and retention period, revise this notice and let you know.
4. Purposes of use and legal bases
We use personal data for the following purposes.
The legal basis under the GDPR is determined for each company that carries out the processing (2.3). For people who have a contract with the UK company, processing carried out by the UK company relies on the UK company's legal basis; all other processing relies on our legal basis.
| Purpose | Main data | Applies to | Legal basis under the GDPR |
|---|---|---|---|
| Issuing, authenticating and managing accounts | Name, email address, authentication information, engagement information | All users | Instructors: performance of a contract (Article 6(1)(b)). Staff: legitimate interests (f) |
| Work-related communication and sending notices about contracts, lessons and the System | Name, email address, other contact details | All users | Instructors: performance of a contract (b). Staff: legitimate interests (f) |
| Assigning lessons, communication and schedule management | Profile, contact details, calendar events, lesson schedules | Instructors only | Performance of a contract (b) |
| Calculating and paying fees and preparing invoices | Contract and pay information, lesson records | Instructors only | Performance of a contract (b), legal obligation (c: tax and accounting) |
| Quality management of instructors and decisions on assignment | Instructor notes, customer ratings, lesson records | Instructors only | Legitimate interests (f) |
| Evaluating the work of staff (including performance evaluation) | Work records, meeting records, activity logs | Staff | Legitimate interests (f) |
| Showing the person responsible in customer management | Name and email address of the person responsible | Staff | Legitimate interests (f) |
| Ensuring security, preventing fraud and auditing | Activity logs, audit logs, authentication information, reCAPTCHA assessments | All users | Legitimate interests (f) |
| Operating the System; detecting, investigating and recovering from failures | Activity logs, error information | All users | Legitimate interests (f) |
| Improving the System (usage analytics) | Pseudonymous ID, role, type of task | All users | Legitimate interests (f) |
| Complying with laws and responding to disputes and legal claims | As necessary | All users | Legal obligation (c), legitimate interests (f) |
| Work incidental to the purposes above | As necessary for the purposes above | All users | Same as for each purpose above |
4.1 Our legitimate interests
For processing based on "legitimate interests", the interests we seek to protect are as follows.
| Processing | Our interest |
|---|---|
| Account management and work-related communication (staff) | Operating the business system securely and keeping it in a state where work can be carried out. We do not rely on consent for people in an employment relationship. If we send instructors a bulk email about something other than work-related communication, such as training information, we will treat that as a separate purpose based on legitimate interests |
| Quality management and assignment of instructors | Assigning suitable instructors to customers and maintaining the quality of lessons |
| Evaluating the work of staff | Understanding how work is being carried out and evaluating it fairly. Activity logs are recorded mainly for security purposes, but may also be used to evaluate work |
| Security, fraud prevention and auditing | Protecting the data of users and customers from unauthorised access and mistakes, and being able to investigate the cause of problems |
| Operating the System and responding to failures | Operating the System reliably and detecting and recovering from failures quickly |
| Improving the System | Making the screens and features of the System easier to use. This is not used to evaluate individuals (Section 6) |
4.2 Instructor notes and customer ratings (instructors only)
| Item | Details |
|---|---|
| Purpose | Quality management of instructors and decisions on lesson assignment |
| Who can see them | Staff of our company and of the UK company. Other instructors cannot see them |
| How instructors can find out the contents | They are not shown on the instructor screen. You can request disclosure from the contact in Section 13 (except in the cases in 13.3) |
5. Information you need to provide
| Category | Information | If not provided |
|---|---|---|
| Required under the contract (all users) | Name, email address, password | We cannot issue an account and you cannot use the System |
| Required under the contract (instructors only) | Primary email address, telephone number (1), call link used for lessons, bank account, contracting entity, payment currency | We cannot contact you or pay your fees, and cannot perform the contract |
| Optional (staff) | Linking Google login | You can log in with your password |
| Optional (instructors only) | Secondary email address, second telephone number, WhatsApp | There is no disadvantage if you do not provide them, but it may be harder for us to contact you |
Users for whom we have made multi-factor authentication (MFA) mandatory cannot log in without setting it up.
6. Usage analytics (PostHog)
To improve the screens and features of the System, we use the usage analytics tool PostHog (provided by PostHog Inc., United States). We send PostHog only events from our servers that show the results of tasks.
6.1 Information we send
| Information sent | Applies to |
|---|---|
| Pseudonymous ID, role, type of app, information indicating the type of task | All users (based on legitimate interests) |
We do not send names, email addresses, free text and the like. PostHog is configured to anonymise IP addresses.
If we start measuring on-screen interactions or recording screens, we will revise this notice and let you know in advance, and obtain any consent required by law.
6.2 Purpose and uses we exclude
The usage data sent to the analytics tool (6.1) is used to improve the System and is not used to evaluate individuals (including the quality management of instructors and the performance evaluation of staff). The purposes of use of work records (such as lesson records, instructor notes and meeting records) are as described in Section 4.
You can object to this processing through the contact in Section 13.
6.3 Retention and transfer
Retention is described in Section 11 and the transfer to the United States in Section 10.
7. Storage on your device and transmission to external parties
7.1 Storage on your device (browser)
The System stores information in the browser's local storage to keep you logged in, for security, and for screen settings and convenience. This is not used for advertising or behavioural tracking.
| Category | Details |
|---|---|
| Needed for authentication and security | Login state, device identifier, etc. |
| Screen settings | Sidebar open/closed, table display settings, volume, tutorial progress, etc. |
| For convenience | Recently viewed customers, recent searches, dismissed announcements, etc. |
7.2 Content loaded from external parties
| Provider | Purpose | Where |
|---|---|---|
| Google reCAPTCHA | Fraud prevention for login and password reset | The login and password reset screens of both screens |
| Google Identity | Google login, linking a Google account | Staff screen |
Google's Privacy Policy (https://policies.google.com/privacy) and Terms of Service (https://policies.google.com/terms) apply to reCAPTCHA.
7.3 Communication for displaying teaching materials
To display teaching materials, the browser may communicate directly with the following recipients. The information sent to SoundCloud and Google Cloud Storage is described in Appendix A.
| Recipient | Purpose | Screen |
|---|---|---|
| SoundCloud | Playing audio for teaching materials | Teaching material screens (both screens) |
| Amazon | Showing cover images of teaching materials | Teaching material screens (both screens) |
| Google Cloud Storage | Showing PDFs of teaching materials | Teaching material screens (both screens) |
SoundCloud sets cookies in the browser to play audio. SoundCloud's Privacy Policy (https://soundcloud.com/pages/privacy) applies to SoundCloud's cookies.
8. Service providers and recipients
We entrust the handling of personal data to, or send personal data to, the following companies and others. We may add or change service providers as our business requires.
| Recipient | Purpose | Data received | Location |
|---|---|---|---|
| Google Cloud | Running the System and storing data | Data handled in the System | Belgium (europe-west1) |
| Google Workspace (Gmail) | Sending emails such as invitations and password resets | Recipient email address, name | United States and other countries |
| Google reCAPTCHA | Fraud prevention for login and password reset | Device and interaction information sent from the browser | United States and other countries |
| Google (login linking) | Google login on the staff screen | Google account ID, email address | United States and other countries |
| Google Calendar | Importing instructors' lesson events | Events in the instructor's calendar | United States and other countries |
| HubSpot | Customer management (we receive staff members' names and email addresses as persons responsible) | Name and email address of the person responsible | United States |
| PostHog Inc. | Usage analytics (Section 6) | The information in 6.1 | United States |
| Slack | Notifying errors in the System | Error details (may include personal data) | United States |
We are the contracting party for Google's services. For PostHog Inc.'s sub-processors, please see its list (https://posthog.com/subprocessors).
9. Provision to third parties and joint use
Apart from the service providers in Section 8 and the joint use in 2.3, we do not provide users' personal data to third parties, except where permitted by the APPI or other laws, such as where required by law.
For information sent directly from the browser to external services, please see Section 7 and Appendix A.
10. International transfers
We store or process personal data in the following countries.
| Destination | Details | Treatment under the APPI | Treatment under the UK / EU GDPR |
|---|---|---|---|
| Belgium (EU) | Storage in Google Cloud | The EU has been designated by Japan's Personal Information Protection Commission as having a level of protection equivalent to Japan (PPC Notice No. 1 of 2019) | Transfers from the UK to the EU are covered by adequacy regulations |
| United Kingdom | Joint use with ELT School of English Limited (2.3) | The UK has been designated as having an equivalent level of protection | Transfers from the UK to Japan rely on the UK's adequacy regulations. We apply the Personal Information Protection Commission's Supplementary Rules to personal data received from the EU or the UK on the basis of an adequacy decision |
| United States | Usage analytics by PostHog Inc. (Section 6) | We ensure the system required by Article 28 of the APPI through our contract with PostHog Inc. and other measures. For information on the personal information protection system of the United States, please see the Personal Information Protection Commission's research report (https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/) | PostHog Inc. participates in the EU-US Data Privacy Framework and its UK Extension (UK–US Data Bridge). Its DPA also includes the Standard Contractual Clauses (SCC) and the UK IDTA Addendum (https://posthog.com/dpa) |
| United States and other countries | Google Workspace (Gmail), reCAPTCHA, Google login, Google Calendar, HubSpot, Slack (Section 8) | We ensure the system required by Article 28 of the APPI through our contracts with each company and other measures. For the United States, please see the research report above | Protected by the Standard Contractual Clauses (SCC) and the UK IDTA Addendum included in our contracts with each company, or by each company's participation in the EU-US Data Privacy Framework and its UK Extension |
Users may ask the contact in Section 13 for information about the safeguards put in place by our service providers outside Japan.
11. Retention periods
We keep personal data for as long as necessary to achieve the purposes of use, for the periods required by law, and for as long as necessary to respond to disputes and legal claims. The retention periods, or the criteria for determining them, for the main data are as follows.
| Data | Retention period or criteria |
|---|---|
| Account information (staff) | Kept after leaving or the end of the contract for as long as necessary to check details when re-contracting and to respond to disputes and enquiries. We do not delete it automatically after a set period |
| Account and profile (instructors only) | Kept after the end of the contract for as long as necessary to check details when re-contracting and to respond to disputes and enquiries. We do not delete it automatically after a set period |
| Records of fees, invoices and contracts (instructors only) | Kept for the periods required by law, such as Japanese and UK tax law (up to 10 years). After that, kept for as long as necessary to respond to disputes and legal claims |
| Instructor notes and customer ratings (instructors only) | In principle, 3 years after the end of the contract |
| Activity logs and audit logs | In principle, 3 years from recording |
| Usage analytics (PostHog) | PostHog's retention period (currently 1 year) |
If we receive a request for deletion or similar during the retention period, we will respond in accordance with Section 13 and the applicable law.
12. Security measures
We take the following measures to prevent the leakage, loss or damage of personal data and otherwise to keep it secure.
| Category | Measures |
|---|---|
| Organisational measures | We have appointed a person responsible for handling personal data and set basic handling rules and a procedure for responding to breaches (12.1). Activity logs and audit logs allow us to check how data is being handled |
| Human measures | Users handle personal data learned through their work in accordance with the confidentiality obligations in their respective contracts (employment contracts and service agreements) |
| Physical measures | Data is stored in Google Cloud data centres (Belgium) |
| Technical measures | We take measures such as access control according to role and the sensitivity of information, multi-factor authentication, password protection, encryption of communication and prevention of unauthorised access |
| Understanding the external environment | We take security measures after understanding the legal systems of the countries where personal data is stored or processed (Belgium, the United Kingdom and the United States) |
12.1 Response to breaches
If personal data is leaked, lost or damaged, or there is a risk of this, we will in principle respond as follows.
- Reporting to the person responsible: anyone who notices the incident reports it to the person responsible immediately.
- Preventing further harm: we take necessary measures, such as suspending accounts and resetting passwords.
- Investigating the facts and the cause: we find out what happened, when and how.
- Identifying the impact: we identify the individuals affected and the scope of the personal data involved.
- Preventing recurrence: we take measures suited to the cause.
- Reporting to supervisory authorities and notifying individuals: where required by law, we report to the Personal Information Protection Commission (and to the ICO or other supervisory authorities where users in the UK or the EU are involved) and notify the individuals affected.
13. Your rights and how to make a request
13.1 Rights you can exercise
Subject to the applicable law and the requirements of each right, users may be able to exercise the following rights.
| Right | Details |
|---|---|
| Disclosure and access | Disclosure of your personal data held by us, and a copy of it |
| Disclosure of records of provision to third parties | Disclosure of records of personal data provided to third parties (APPI) |
| Correction, addition and deletion | Correction where the contents are not accurate, etc. |
| Suspension of use and erasure | Suspension of use and erasure |
| Restriction of processing | Restriction of processing (GDPR) |
| Data portability | Receiving your data in a structured format (GDPR) |
| Objection | Objection to processing based on legitimate interests (GDPR) |
Information that can be checked or changed in Account Settings (such as your email address and password) can be checked or changed there.
13.2 How to make a request
| Item | Details |
|---|---|
| Contact | … |
| Identity verification | We verify your identity by your sending the request from the email address registered in the System. We may ask for additional information where necessary |
| Fees | Free of charge. However, for requests that are manifestly unfounded or excessive, we may, to the extent permitted by law, charge a reasonable fee or refuse to act on the request |
| Response time | We respond to requests under the APPI without delay. We generally respond to requests under the GDPR within 1 month (this may be extended where permitted by law) |
13.3 When we cannot comply with a request
To the extent permitted by the applicable law, we may refuse all or part of a request in the following cases. If we refuse, we will tell you so and why, to the extent required by law.
- Where we are legally required to keep the data (for example, records of fee payments)
- Where it is needed to respond to disputes or legal claims
- Where disclosure may harm the life, body, property or other rights and interests of you or a third party (such as customers or other staff and instructors)
- Where disclosure may seriously interfere with the proper conduct of our business or that of the UK company
- Other cases permitted by the applicable law
14. Automated decision-making
We do not make decisions in the System based solely on automated processing (including profiling) that produce legal effects on users or similarly significantly affect them.
15. Complaints and the right to complain to a supervisory authority
We accept complaints about how personal data is handled at the contact in Section 13.
Users may also lodge a complaint with the following supervisory authorities.
| Authority | Details |
|---|---|
| Personal Information Protection Commission (Japan) | https://www.ppc.go.jp/ |
| Information Commissioner's Office (ICO, United Kingdom) | https://ico.org.uk/make-a-complaint/ |
| Supervisory authorities of EU member states | Where the EU GDPR applies, the supervisory authority of the country where you live, where you work, or where the alleged infringement took place (list: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en) |
16. Changes to this notice
- We may revise this notice in response to changes in law or as our business requires. The date of revision and the version are shown at the top of this notice.
- We will notify you of significant changes, such as new purposes of use, new service providers or new international transfer destinations, in accordance with the law, on the System's screens, by email or by other appropriate means.
Appendix A: List of external transmissions
When you open the System's screens, the browser sends information to the following external recipients. Because of how internet communication works, your IP address and browser information (User-Agent) are sent to every recipient.
| Recipient | Information sent | Purpose | Where |
|---|---|---|---|
| Google (reCAPTCHA) | Device and interaction information | Fraud prevention for login and password reset | The login and password reset screens of both screens |
| Google (Google Identity) | Google account login information | Google login, linking a Google account | Staff screen |
| SoundCloud | The URL of the teaching material audio being played; cookies set by SoundCloud | Playing audio for teaching materials | Teaching material screens (both screens) |
| Google Cloud Storage | The URL of the teaching material PDF being shown | Showing PDFs of teaching materials | Teaching material screens (both screens) |
What our servers send is described in Section 8.