Back to login

Staff & Instructor Privacy Notice

ItemDetails
Established26 September 2026
Last updated26 September 2026
Version1.0

Items marked "Instructors only" apply only to instructors. They do not apply to staff.

This Privacy Notice is provided in Japanese and English. If there is any inconsistency between the two versions, the Japanese version prevails.


1. Introduction

This Privacy Notice explains how ELT Education Inc. ("we", "us" or "our") handles the personal data of users of the business system "ELT Core Platform" (the "System") that we operate.

This notice does not form part of any employment contract or service agreement with users.

1.1 Who this notice applies to

WhoScreen usedHow we refer to them
Staff (including our employees and contractors, and the employees and contractors of the UK company ELT School of English Limited)Staff screen (https://staff.elt-force.com)Staff
InstructorsInstructor screen (https://instructor.my-elt.com)Instructors
Anyone who opens a login page (before logging in)https://staff.elt-force.com/login, https://instructor.my-elt.com/login—

Staff and instructors are together referred to as "users".

1.2 What data this notice covers

This notice covers the personal data of the users themselves.

In this notice, "personal data" means personal information and personal data as defined in Japan's Act on the Protection of Personal Information (APPI). For users to whom the UK GDPR or the EU GDPR applies, it also includes personal data as defined in those laws.

The personal data of customers (students and guardians) that users view in the course of their work is not covered by this notice. Users are obliged to protect the personal data of customers that they learn through their work. The details are set out in their contracts and our internal rules.

1.3 Applicable law

We handle personal data in accordance with Japan's APPI. The statements and rights in this notice that are based on the UK GDPR (United Kingdom) and the EU GDPR apply where, and to the extent that, those laws apply.


2. Who we are and how to contact us

2.1 The business operator

ItemDetails
NameELT Education Inc. (株式会社ELTエデュケーション)
Address5-32-12 Shiba, Minato-ku, Tokyo 108-0014, Japan
RepresentativeTatsuya Tanaka, Representative Director

2.2 Privacy contact

We accept questions, requests and complaints about how personal data is handled at the following contact.

ItemDetails
Email address…
Where this notice is publishedInstructor screen: https://instructor.my-elt.com/privacy, Staff screen: https://staff.elt-force.com/privacy

2.3 Our relationship with the UK company

The UK company ELT School of English Limited is a separate legal entity from us. We operate the System, and employees and contractors of the UK company also use it as staff. In addition, some instructors have their contract with the UK company.

For this reason, we and the UK company use users' personal data jointly as follows.

ItemDetails
Statement of joint useWe and ELT School of English Limited jointly use the personal data described below
Personal data used jointlyOf the personal data described in Section 3, the data that employees and contractors of the UK company handle in their work (such as instructors' profiles, contact details, contracts, pay, lesson records, instructor notes and customer ratings, and staff members' names, email addresses and work records)
Parties to the joint useELT Education Inc.; ELT School of English Limited (Company No. 04497523, 35 Ballards Lane, London N3 1XW, United Kingdom)
Purposes of useUs: the purposes described in Section 4. The UK company: managing staff who are its employees or contractors, and managing the instructors it contracts with (assigning lessons, calculating and paying fees, quality management, and work-related communication)
Party responsible for managing the personal dataELT Education Inc. (address and representative as in 2.1)

The role of each company under the UK GDPR / EU GDPR, by purpose of processing, is as follows.

ProcessingRole
Operating the System, security and responding to failuresWe are the controller
Employment, contracts and pay of people who have a contract with the UK companyThe UK company is the controller; we are a processor
Assigning lessons, quality management of instructors and work-related communicationThe two companies are joint controllers
Evaluating the work of staffThe company that carries out the evaluation is the controller

Requests and complaints about processing carried out as joint controllers can be made to the contact in 2.2.


3. Personal data we collect and where it comes from

The main personal data we handle in the System is as follows.

3.1 Data common to staff and instructors

CategoryItemsSource
Identification and contactName, email addressThe user; within our organisation (invitation, recruitment and contracting)
AuthenticationPassword, role, account status, login times, multi-factor authentication (MFA) settings, Google account ID (if Google login is linked)The user's own actions; records made by the System
EngagementScheduled date of leaving or contract endWithin our organisation

3.2 Data for instructors only

CategoryItemsSource
Contract and payBank account, contract details, rates of pay and allowances, contracting entity, contract periods, payment currency, etc.The instructor; within our organisation (recruitment and contracting)
Contact detailsEmail addresses, telephone numbers, WhatsApp, call links used for lessons, etc.Same as above
ProfileDate of birth, gender, CV, education, qualifications and work history, self-introduction, etc.Same as above
Instructor notesWork-related notes recorded by our staff (with categories such as reliability and significant incidents)Our staff
Customer ratingsRatings and comments given by customersCustomers
Work recordsLesson records (date and time, customer name, location, late submission and its reason, etc.), lesson schedulesEntered by the instructor; within our organisation
CalendarEvents in the instructor's Google CalendarGoogle Calendar

3.2a Work records of staff

CategoryItemsSource
ResponsibilitiesCustomers, deals and meetings the staff member is responsible forWithin our organisation; entered by the user
Creating and updating recordsThe fact that the staff member created or updated records such as customer notes, instructor notes, deals and meeting recordsThe user's own actions
Carrying out processingThe fact that the staff member carried out actions such as changing a customer's enrolment status, refunds and plan changes, contract changes, and deletion requests and approvalsThe user's own actions
Data import and exportThe fact that the staff member imported or exported dataThe user's own actions

Activity logs and audit logs (3.4) are also treated as work records of staff.

3.2b Meeting records

The System contains records of meetings with customers (such as counselling sessions and trial lessons). Users are recorded as the person responsible for a meeting.

CategoryItemsSourceApplies to
Responsibility for meetingsThe staff member responsible for the meeting; staff members who created or updated the recordEntered by our staff; our customer management tool (HubSpot)Staff
Responsibility for trial lessonsThe instructor responsible for the trial lesson; the instructor's feedbackSame as aboveInstructors only
Meeting detailsDate and time, method, outcome, next action, internal notesSame as aboveThose recorded as responsible

3.3 Data we obtain from sources other than the user

DataSourceApplies to
Customer ratingsCustomers (recorded by our staff)Instructors only
Calendar eventsGoogle CalendarInstructors only
Instructor notesOur staffInstructors only
Name and email address of the person responsibleOur customer management tool (HubSpot)Staff

3.4 Data recorded automatically

TypeDetailsApplies to
Activity logsWhat was done and when, IP address, browser information (User-Agent), device identifier, etc.All users
Audit logsDetails of changes to data (values before and after the change), IP address, browser informationAll users
Authentication informationInformation needed for multi-factor authentication (MFA) and for keeping you logged in, trusted devicesAll users
reCAPTCHADevice and interaction information sent from the browser to Google on the login and password reset screensEveryone who opens these screens

3.5 Special category data and photographs

We do not aim to collect special care-required personal information such as health information (special category data under the GDPR) in the System. However, such information may be included in free-text fields or attachments such as CVs, notes and meeting records. If so, we handle it in accordance with this notice.

If we handle photographs of instructors and staff (such as profile photos) in the future, we will set the purpose and retention period, revise this notice and let you know.


4. Purposes of use and legal bases

We use personal data for the following purposes.

The legal basis under the GDPR is determined for each company that carries out the processing (2.3). For people who have a contract with the UK company, processing carried out by the UK company relies on the UK company's legal basis; all other processing relies on our legal basis.

PurposeMain dataApplies toLegal basis under the GDPR
Issuing, authenticating and managing accountsName, email address, authentication information, engagement informationAll usersInstructors: performance of a contract (Article 6(1)(b)). Staff: legitimate interests (f)
Work-related communication and sending notices about contracts, lessons and the SystemName, email address, other contact detailsAll usersInstructors: performance of a contract (b). Staff: legitimate interests (f)
Assigning lessons, communication and schedule managementProfile, contact details, calendar events, lesson schedulesInstructors onlyPerformance of a contract (b)
Calculating and paying fees and preparing invoicesContract and pay information, lesson recordsInstructors onlyPerformance of a contract (b), legal obligation (c: tax and accounting)
Quality management of instructors and decisions on assignmentInstructor notes, customer ratings, lesson recordsInstructors onlyLegitimate interests (f)
Evaluating the work of staff (including performance evaluation)Work records, meeting records, activity logsStaffLegitimate interests (f)
Showing the person responsible in customer managementName and email address of the person responsibleStaffLegitimate interests (f)
Ensuring security, preventing fraud and auditingActivity logs, audit logs, authentication information, reCAPTCHA assessmentsAll usersLegitimate interests (f)
Operating the System; detecting, investigating and recovering from failuresActivity logs, error informationAll usersLegitimate interests (f)
Improving the System (usage analytics)Pseudonymous ID, role, type of taskAll usersLegitimate interests (f)
Complying with laws and responding to disputes and legal claimsAs necessaryAll usersLegal obligation (c), legitimate interests (f)
Work incidental to the purposes aboveAs necessary for the purposes aboveAll usersSame as for each purpose above

4.1 Our legitimate interests

For processing based on "legitimate interests", the interests we seek to protect are as follows.

ProcessingOur interest
Account management and work-related communication (staff)Operating the business system securely and keeping it in a state where work can be carried out. We do not rely on consent for people in an employment relationship. If we send instructors a bulk email about something other than work-related communication, such as training information, we will treat that as a separate purpose based on legitimate interests
Quality management and assignment of instructorsAssigning suitable instructors to customers and maintaining the quality of lessons
Evaluating the work of staffUnderstanding how work is being carried out and evaluating it fairly. Activity logs are recorded mainly for security purposes, but may also be used to evaluate work
Security, fraud prevention and auditingProtecting the data of users and customers from unauthorised access and mistakes, and being able to investigate the cause of problems
Operating the System and responding to failuresOperating the System reliably and detecting and recovering from failures quickly
Improving the SystemMaking the screens and features of the System easier to use. This is not used to evaluate individuals (Section 6)

4.2 Instructor notes and customer ratings (instructors only)

ItemDetails
PurposeQuality management of instructors and decisions on lesson assignment
Who can see themStaff of our company and of the UK company. Other instructors cannot see them
How instructors can find out the contentsThey are not shown on the instructor screen. You can request disclosure from the contact in Section 13 (except in the cases in 13.3)

5. Information you need to provide

CategoryInformationIf not provided
Required under the contract (all users)Name, email address, passwordWe cannot issue an account and you cannot use the System
Required under the contract (instructors only)Primary email address, telephone number (1), call link used for lessons, bank account, contracting entity, payment currencyWe cannot contact you or pay your fees, and cannot perform the contract
Optional (staff)Linking Google loginYou can log in with your password
Optional (instructors only)Secondary email address, second telephone number, WhatsAppThere is no disadvantage if you do not provide them, but it may be harder for us to contact you

Users for whom we have made multi-factor authentication (MFA) mandatory cannot log in without setting it up.


6. Usage analytics (PostHog)

To improve the screens and features of the System, we use the usage analytics tool PostHog (provided by PostHog Inc., United States). We send PostHog only events from our servers that show the results of tasks.

6.1 Information we send

Information sentApplies to
Pseudonymous ID, role, type of app, information indicating the type of taskAll users (based on legitimate interests)

We do not send names, email addresses, free text and the like. PostHog is configured to anonymise IP addresses.

If we start measuring on-screen interactions or recording screens, we will revise this notice and let you know in advance, and obtain any consent required by law.

6.2 Purpose and uses we exclude

The usage data sent to the analytics tool (6.1) is used to improve the System and is not used to evaluate individuals (including the quality management of instructors and the performance evaluation of staff). The purposes of use of work records (such as lesson records, instructor notes and meeting records) are as described in Section 4.

You can object to this processing through the contact in Section 13.

6.3 Retention and transfer

Retention is described in Section 11 and the transfer to the United States in Section 10.


7. Storage on your device and transmission to external parties

7.1 Storage on your device (browser)

The System stores information in the browser's local storage to keep you logged in, for security, and for screen settings and convenience. This is not used for advertising or behavioural tracking.

CategoryDetails
Needed for authentication and securityLogin state, device identifier, etc.
Screen settingsSidebar open/closed, table display settings, volume, tutorial progress, etc.
For convenienceRecently viewed customers, recent searches, dismissed announcements, etc.

7.2 Content loaded from external parties

ProviderPurposeWhere
Google reCAPTCHAFraud prevention for login and password resetThe login and password reset screens of both screens
Google IdentityGoogle login, linking a Google accountStaff screen

Google's Privacy Policy (https://policies.google.com/privacy) and Terms of Service (https://policies.google.com/terms) apply to reCAPTCHA.

7.3 Communication for displaying teaching materials

To display teaching materials, the browser may communicate directly with the following recipients. The information sent to SoundCloud and Google Cloud Storage is described in Appendix A.

RecipientPurposeScreen
SoundCloudPlaying audio for teaching materialsTeaching material screens (both screens)
AmazonShowing cover images of teaching materialsTeaching material screens (both screens)
Google Cloud StorageShowing PDFs of teaching materialsTeaching material screens (both screens)

SoundCloud sets cookies in the browser to play audio. SoundCloud's Privacy Policy (https://soundcloud.com/pages/privacy) applies to SoundCloud's cookies.


8. Service providers and recipients

We entrust the handling of personal data to, or send personal data to, the following companies and others. We may add or change service providers as our business requires.

RecipientPurposeData receivedLocation
Google CloudRunning the System and storing dataData handled in the SystemBelgium (europe-west1)
Google Workspace (Gmail)Sending emails such as invitations and password resetsRecipient email address, nameUnited States and other countries
Google reCAPTCHAFraud prevention for login and password resetDevice and interaction information sent from the browserUnited States and other countries
Google (login linking)Google login on the staff screenGoogle account ID, email addressUnited States and other countries
Google CalendarImporting instructors' lesson eventsEvents in the instructor's calendarUnited States and other countries
HubSpotCustomer management (we receive staff members' names and email addresses as persons responsible)Name and email address of the person responsibleUnited States
PostHog Inc.Usage analytics (Section 6)The information in 6.1United States
SlackNotifying errors in the SystemError details (may include personal data)United States

We are the contracting party for Google's services. For PostHog Inc.'s sub-processors, please see its list (https://posthog.com/subprocessors).


9. Provision to third parties and joint use

Apart from the service providers in Section 8 and the joint use in 2.3, we do not provide users' personal data to third parties, except where permitted by the APPI or other laws, such as where required by law.

For information sent directly from the browser to external services, please see Section 7 and Appendix A.


10. International transfers

We store or process personal data in the following countries.

DestinationDetailsTreatment under the APPITreatment under the UK / EU GDPR
Belgium (EU)Storage in Google CloudThe EU has been designated by Japan's Personal Information Protection Commission as having a level of protection equivalent to Japan (PPC Notice No. 1 of 2019)Transfers from the UK to the EU are covered by adequacy regulations
United KingdomJoint use with ELT School of English Limited (2.3)The UK has been designated as having an equivalent level of protectionTransfers from the UK to Japan rely on the UK's adequacy regulations. We apply the Personal Information Protection Commission's Supplementary Rules to personal data received from the EU or the UK on the basis of an adequacy decision
United StatesUsage analytics by PostHog Inc. (Section 6)We ensure the system required by Article 28 of the APPI through our contract with PostHog Inc. and other measures. For information on the personal information protection system of the United States, please see the Personal Information Protection Commission's research report (https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/)PostHog Inc. participates in the EU-US Data Privacy Framework and its UK Extension (UK–US Data Bridge). Its DPA also includes the Standard Contractual Clauses (SCC) and the UK IDTA Addendum (https://posthog.com/dpa)
United States and other countriesGoogle Workspace (Gmail), reCAPTCHA, Google login, Google Calendar, HubSpot, Slack (Section 8)We ensure the system required by Article 28 of the APPI through our contracts with each company and other measures. For the United States, please see the research report aboveProtected by the Standard Contractual Clauses (SCC) and the UK IDTA Addendum included in our contracts with each company, or by each company's participation in the EU-US Data Privacy Framework and its UK Extension

Users may ask the contact in Section 13 for information about the safeguards put in place by our service providers outside Japan.


11. Retention periods

We keep personal data for as long as necessary to achieve the purposes of use, for the periods required by law, and for as long as necessary to respond to disputes and legal claims. The retention periods, or the criteria for determining them, for the main data are as follows.

DataRetention period or criteria
Account information (staff)Kept after leaving or the end of the contract for as long as necessary to check details when re-contracting and to respond to disputes and enquiries. We do not delete it automatically after a set period
Account and profile (instructors only)Kept after the end of the contract for as long as necessary to check details when re-contracting and to respond to disputes and enquiries. We do not delete it automatically after a set period
Records of fees, invoices and contracts (instructors only)Kept for the periods required by law, such as Japanese and UK tax law (up to 10 years). After that, kept for as long as necessary to respond to disputes and legal claims
Instructor notes and customer ratings (instructors only)In principle, 3 years after the end of the contract
Activity logs and audit logsIn principle, 3 years from recording
Usage analytics (PostHog)PostHog's retention period (currently 1 year)

If we receive a request for deletion or similar during the retention period, we will respond in accordance with Section 13 and the applicable law.


12. Security measures

We take the following measures to prevent the leakage, loss or damage of personal data and otherwise to keep it secure.

CategoryMeasures
Organisational measuresWe have appointed a person responsible for handling personal data and set basic handling rules and a procedure for responding to breaches (12.1). Activity logs and audit logs allow us to check how data is being handled
Human measuresUsers handle personal data learned through their work in accordance with the confidentiality obligations in their respective contracts (employment contracts and service agreements)
Physical measuresData is stored in Google Cloud data centres (Belgium)
Technical measuresWe take measures such as access control according to role and the sensitivity of information, multi-factor authentication, password protection, encryption of communication and prevention of unauthorised access
Understanding the external environmentWe take security measures after understanding the legal systems of the countries where personal data is stored or processed (Belgium, the United Kingdom and the United States)

12.1 Response to breaches

If personal data is leaked, lost or damaged, or there is a risk of this, we will in principle respond as follows.

  • Reporting to the person responsible: anyone who notices the incident reports it to the person responsible immediately.
  • Preventing further harm: we take necessary measures, such as suspending accounts and resetting passwords.
  • Investigating the facts and the cause: we find out what happened, when and how.
  • Identifying the impact: we identify the individuals affected and the scope of the personal data involved.
  • Preventing recurrence: we take measures suited to the cause.
  • Reporting to supervisory authorities and notifying individuals: where required by law, we report to the Personal Information Protection Commission (and to the ICO or other supervisory authorities where users in the UK or the EU are involved) and notify the individuals affected.

13. Your rights and how to make a request

13.1 Rights you can exercise

Subject to the applicable law and the requirements of each right, users may be able to exercise the following rights.

RightDetails
Disclosure and accessDisclosure of your personal data held by us, and a copy of it
Disclosure of records of provision to third partiesDisclosure of records of personal data provided to third parties (APPI)
Correction, addition and deletionCorrection where the contents are not accurate, etc.
Suspension of use and erasureSuspension of use and erasure
Restriction of processingRestriction of processing (GDPR)
Data portabilityReceiving your data in a structured format (GDPR)
ObjectionObjection to processing based on legitimate interests (GDPR)

Information that can be checked or changed in Account Settings (such as your email address and password) can be checked or changed there.

13.2 How to make a request

ItemDetails
Contact…
Identity verificationWe verify your identity by your sending the request from the email address registered in the System. We may ask for additional information where necessary
FeesFree of charge. However, for requests that are manifestly unfounded or excessive, we may, to the extent permitted by law, charge a reasonable fee or refuse to act on the request
Response timeWe respond to requests under the APPI without delay. We generally respond to requests under the GDPR within 1 month (this may be extended where permitted by law)

13.3 When we cannot comply with a request

To the extent permitted by the applicable law, we may refuse all or part of a request in the following cases. If we refuse, we will tell you so and why, to the extent required by law.

  • Where we are legally required to keep the data (for example, records of fee payments)
  • Where it is needed to respond to disputes or legal claims
  • Where disclosure may harm the life, body, property or other rights and interests of you or a third party (such as customers or other staff and instructors)
  • Where disclosure may seriously interfere with the proper conduct of our business or that of the UK company
  • Other cases permitted by the applicable law

14. Automated decision-making

We do not make decisions in the System based solely on automated processing (including profiling) that produce legal effects on users or similarly significantly affect them.


15. Complaints and the right to complain to a supervisory authority

We accept complaints about how personal data is handled at the contact in Section 13.

Users may also lodge a complaint with the following supervisory authorities.

AuthorityDetails
Personal Information Protection Commission (Japan)https://www.ppc.go.jp/
Information Commissioner's Office (ICO, United Kingdom)https://ico.org.uk/make-a-complaint/
Supervisory authorities of EU member statesWhere the EU GDPR applies, the supervisory authority of the country where you live, where you work, or where the alleged infringement took place (list: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en)

16. Changes to this notice

  • We may revise this notice in response to changes in law or as our business requires. The date of revision and the version are shown at the top of this notice.
  • We will notify you of significant changes, such as new purposes of use, new service providers or new international transfer destinations, in accordance with the law, on the System's screens, by email or by other appropriate means.

Appendix A: List of external transmissions

When you open the System's screens, the browser sends information to the following external recipients. Because of how internet communication works, your IP address and browser information (User-Agent) are sent to every recipient.

RecipientInformation sentPurposeWhere
Google (reCAPTCHA)Device and interaction informationFraud prevention for login and password resetThe login and password reset screens of both screens
Google (Google Identity)Google account login informationGoogle login, linking a Google accountStaff screen
SoundCloudThe URL of the teaching material audio being played; cookies set by SoundCloudPlaying audio for teaching materialsTeaching material screens (both screens)
Google Cloud StorageThe URL of the teaching material PDF being shownShowing PDFs of teaching materialsTeaching material screens (both screens)

What our servers send is described in Section 8.