Privacy Policy

This Privacy Policy provides you with the information that must be provided under:

  • General Data Protection Regulation ((EU) 2016/679) (GDPR)
  • The Hong Kong Personal Data (Privacy) Ordinance
  • The Australian Privacy Act 1988
  • The New Zealand Privacy Act 1993

Our website located at www.phonicshero.com (“Website”) and the Phonics Hero Mobile Application (iOS and Android) is owned and operated by Phonics Hero Limited (collectively referred to as “Phonics Hero”, “we”, “our” or “us”). This statement (“Privacy Policy”) describes the privacy practices we have adopted with respect to personal data in operating the Website and Mobile Application. The processing of some data is essential to the functioning of Website and Mobile Application, so if you do not accept the terms of this Privacy Policy, you should not use the Website and Mobile Application.

Definitions

“Personal data” – Data relating directly or indirectly to an individual from which it is practicable for the identity of the individual to be directly or indirectly ascertained.

“You” and “Your” – When used in this Privacy Policy, it includes any person who accesses the Website and submits personal data.

“Users” – Teachers and parents/guardians who register on our website become “Users”.

“Students” – “Users” may set up their students/children with accounts, which enable them to access the games and will track their performance. “Students” cannot set their own account up.

Age and Consent

Phonics Hero is intended for use by children under the supervision of a parent, guardian, or teacher. Students under the age of 18 are not permitted to create their own accounts. Accounts must be set up and managed by a parent, guardian, or teacher on the student’s behalf. By creating an account for a student, the parent, guardian, or teacher confirms that they have the legal authority to provide consent for the student’s use of the service and the processing of their personal data. We do not knowingly collect personal information directly from students without such consent.

Your Consent

By using the Website and Mobile Application, you consent to our collection and use of your personal data as described in this Privacy Policy. If we change our Privacy Policy and procedures, we will post those changes on the Website to keep you aware of what information we collect, how we use it, and under what circumstances we may disclose it.

Data Controller

When a teacher or parent/guardian sets up an account with Phonics Hero on behalf of their students, Phonics Hero acts as the “data controller”.

Collection of Personal Data and User Information

We may collect two types of information from you: user data and usage data.

1. User Data

Personal data you knowingly choose to disclose, collected on an individual basis when you register on the Website for a Phonics Hero account. We collect this data either directly from a parent or via the school.

1a. Via the School

School details: school name and country.

Teacher data: name, email address, class they manage, and password.

Student data: the names, class, teacher, and school attended by the Students who will use Phonics Hero. Each student is issued an anonymous username, so the names are only collected for the ease of teacher management and monitoring. The school can anonymise the data if they wish (first names, initials, or codenames).

1b. Via the Parents

Parent data (only when parents sign up privately): name, email address, password, and child’s name (first name or nickname can be used).

For parents, students, and teachers, we do not collect any “special category” data deemed sensitive, including disabilities, race, ethnicity, religion, sexual orientation, political views, trade union membership, and physical or mental health.

We collect data on the time and duration of visits to www.phonicshero.com and student scores in games.

2. Protecting Your Personal Data

Phonics Hero is committed to safeguarding web users’ personal information regarding its collection, use, retention, security, transfer, and access. Personal data is collected by lawful and fair means and only used for lawful purposes directly related to the functions and activities of Phonics Hero. We take all reasonable steps to ensure that personal data collected and retained is accurate and protected against unauthorized or accidental access, processing, erasure, or other use.

We use Amazon Web Services (AWS) for data hosting and storage in Sydney, Australia. AWS is recognized for its expertise in protecting data. Further information regarding AWS’ privacy and security practices can be found at aws.amazon.com/compliance/data-privacy-faq and aws.amazon.com/security.

3. Use of Your Personal Data

As the data controller, we will only use your personal information when the law allows us to. Typically, we will use your personal information in the following circumstances:

  • Where you have provided your consent.
  • Where we need to perform a contract.
  • Where necessary for our legitimate interests (or those of a third party), and your interests and rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

Use of Subprocessors

Phonics Hero uses the following subprocessors to provide its services. Each subprocessor is carefully selected to ensure compliance with data protection regulations, including GDPR. The subprocessors, their details, and the types of data disclosed to them are as follows:

  • Brevo (France)
    • Purpose: Email marketing delivery.
    • Data types disclosed: User’s name and email address.
    • Lawful basis for processing: Consent provided by the user.
    • Country where data is processed or stored: France.
    • Contact information: www.brevo.com
  • Mailchimp (USA)
    • Purpose: Email marketing delivery.
    • Data types disclosed: User’s name and email address.
    • Lawful basis for processing: Consent provided by the user.
    • Country where data is processed or stored: United States.
    • Contact information: www.mailchimp.com
  • Facebook (USA)
    • Purpose: Advertising.
    • Data types disclosed: Usage data, cookies, and device information.
    • Lawful basis for processing: Consent provided by the user when signing up for Facebook.
    • Country where data is processed or stored: USA.
    • Contact information: www.facebook.com
  • TapAd (USA)
    • Purpose: Cross-device tracking and advertising.
    • Data types disclosed: Usage data, cookies, and device information.
    • Lawful basis for processing: Consent provided by the user.
    • Country where data is processed or stored: USA.
    • Contact information: www.tapad.com
  • The Trade Desk (USA)
    • Purpose: Programmatic advertising.
    • Data types disclosed: Usage data, cookies, and device information.
    • Lawful basis for processing: Consent provided by the user.
    • Country where data is processed or stored: USA.
    • Contact information: www.thetradedesk.com
  • Braintree (USA)
    • Purpose: Payment processing.
    • Data types disclosed: Payment details, name, and email address.
    • Lawful basis for processing: Performance of a contract.
    • Country where data is processed or stored: USA.
    • Contact information: www.braintreepayments.com
  • Capsule (USA)
    • Purpose: Customer Relationship Management (CRM).
    • Data types disclosed: Name, email address, and other customer contact information.
    • Lawful basis for processing: Legitimate interests of Phonics Hero to manage customer relationships.
    • Country where data is processed or stored: USA.
    • Contact information: www.capsulecrm.com
  • Google Analytics (USA)
    • Purpose: Web traffic analysis.
    • Data types disclosed: IP address, website usage data.
    • Lawful basis for processing: Legitimate interests of Phonics Hero to monitor and improve its website.
    • Country where data is processed or stored: USA.
    • Contact information: www.analytics.google.com

If it is necessary to transfer your personal data to other countries, we will take reasonable steps to ensure that these subprocessors comply with GDPR and other applicable regulations.

4. Accessing and Correcting Your Data

You have the right to access the personal information we hold about you and request corrections if needed. Requests for access and correction should be made in writing via email to info@phonicshero.com. We will acknowledge your request within two working days and provide the information within one month.

5. Complaints and Privacy Breaches

If you believe there has been a breach of your privacy or our handling of your personal information is unfair, misleading, or inappropriate, you can contact us at info@phonicshero.com. We take complaints seriously and will respond promptly.

For UK residents, complaints can also be lodged with the Information Commissioner’s Office:

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK

6. Disclosures to Overseas Recipients

We may disclose your personal information to overseas recipients, including our third-party service providers. User data may be stored or processed in the following countries:

  • Australia – primary hosting and storage via Amazon Web Services (AWS Sydney).
  • United States – service providers including Braintree (payment processing), Capsule (customer relationship management), Mailchimp (email marketing), Facebook (advertising), Google Analytics (website analytics), TapAd (cross-device tracking), and The Trade Desk (programmatic advertising).
  • France – email marketing delivery via Brevo.
  • United Kingdom – administrative and customer support activities conducted by Phonics Hero staff.

While Phonics Hero Limited is registered in Hong Kong, we do not have operational staff or data processing activities taking place there.

All transfers of personal data to these countries are carried out in accordance with applicable data protection laws, including GDPR. We ensure that appropriate safeguards are in place with each overseas recipient to protect your personal data.

7. Data Retention

Phonics Hero retains personal data for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Student, parent, and teacher accounts are kept active during the subscription period and for a period of 24 months after the last activity or subscription expiry to allow users to reactivate their accounts and retain access to their learning history. After this period, personal data will be securely deleted or anonymized, unless a longer retention period is required by law.

Users may also request deletion of their data at any time by contacting us.

Changes to our Privacy Policy

Any changes to this Privacy Policy will be posted on this page. Please check regularly to ensure you are aware of the latest updates.

Last updated: April 2025