Privacy Policy
For Mandarin Audio, a trading name of icelabz solutions ltd, registered in England and Wales. Effective date . Version 1.1.0.
1. Who we are
The data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 is:
icelabz solutions ltd (trading as Mandarin Audio)Registered in England and Wales (Companies House)
Registered office: c/o Bromley Heath Accountancy Ltd, 42c Badminton Road, Downend, Bristol BS16 6BS, United Kingdom
Privacy email: privacy@icelabz.co.uk
Website: mandarinaudio.com
icelabz solutions ltd is the controller for any personal data processed in connection with the Mandarin Audio website (mandarinaudio.com), the Mandarin Audio mobile application, and related waitlist, account, lesson-progress and customer-support activities.
2. Scope of this policy
This policy explains what personal data we collect when you visit mandarinaudio.com, join the launch waitlist, register for an account, subscribe to the Mandarin Audio audio-lesson service, or contact our support team. It also describes how that data is used, how long it is held, who it is shared with, what your rights are, and how to exercise them.
This policy is published in English (English, United Kingdom). Mandarin Audio is operated by a single legal entity incorporated and based in England and Wales, and the policy applies to every visitor regardless of country of residence. You can always reach the canonical version of this policy at mandarinaudio.com/en-gb/privacy/.
3. Data we collect
We collect only the data we need to operate the Mandarin Audio service. The categories below correspond to the lawful bases and retention periods set out in the next sections.
3.1 Data you give us
- Waitlist email address — single field, captured before the product is generally available.
- Account email address and password — captured at sign-up to create your Mandarin Audio account.
- Optional profile fields after sign-up — display name, short bio, preferred locale, optional profile photograph.
- Customer-support correspondence — emails you send to our support address, plus any attachments you choose to include.
- Survey or feedback responses — voluntary responses to in-product surveys and feedback forms.
3.2 Data we collect automatically
- Lesson-progress data — which lessons you have started and completed, play count, last-played timestamp, and aggregate per-lesson time spent listening.
- Device and connection data — IP address, user agent string, referrer, approximate country derived from IP, and timestamps of access (used for fraud detection, abuse prevention and basic service telemetry).
- Cookies — strictly-necessary session cookies only. The marketing site does not currently deploy analytics or advertising cookies; see section 12 below.
3.3 Data we receive from third parties
- Payment data from Stripe — we use Stripe as our payment processor. Mandarin Audio does not store full payment-card numbers; we hold only the
stripe_customer_idreference and a redacted subset of payment-method fingerprint such as card-brand and last four digits, returned to us by Stripe under our written data-processor agreement. - Authentication from sign-in providers — if you sign in via Apple, Google or a similar single-sign-on provider, we receive your verified email address and basic profile identifier. We do not receive your social-account contacts, friends list, or any other social-graph data.
4. How we use your data
- To create and maintain your Mandarin Audio account.
- To provide the audio-lesson experience (authenticate your session, sequence the lessons, remember your progress, and stream audio from our content delivery network).
- To process subscription payments via Stripe and to issue receipts.
- To respond to support requests.
- To notify you of product updates, launch news and feature changes — for the marketing list (waitlist + opt-in for registered users), only with your explicit consent, which you can withdraw at any time.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with UK tax, accounting and corporate record-keeping obligations.
- To improve the product on an aggregate basis (counts, not profiles) where this is in our legitimate interest and does not override your rights.
We do not sell your personal data to anyone, and we do not perform automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Lawful bases (UK GDPR Article 6)
For each processing purpose we rely on a specific lawful basis under Article 6 of the UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Account creation and authentication | Contract — Article 6(1)(b) — necessary to perform the contract you have with us when you sign up. |
| Delivering the audio lessons and tracking your progress | Contract — Article 6(1)(b). |
| Processing payments via Stripe | Contract — Article 6(1)(b). |
| Marketing emails (waitlist + opted-in registered users) | Consent — Article 6(1)(a). Easy to withdraw, easy to give — both via the unsubscribe link in every email and via your account preferences. |
| Fraud, abuse and security-incident response | Legitimate interests — Article 6(1)(f). Balanced against your expectations; not used for marketing. |
| HMRC tax records, Companies House filings, statutory accounting | Legal obligation — Article 6(1)(c). |
6. Retention periods
We keep your data only for as long as we need it for the purpose for which it was collected:
- Account data — while your account is active and for up to 30 days after you close it, to allow restoration.
- Billing and tax records — 6 years from the date of the transaction, to satisfy HMRC requirements under the Income Tax Act 2007 and the Value Added Tax Act 1994.
- Lesson-progress data — 24 months from your last lesson (operational — used to power "continue where you left off").
- Customer-support correspondence — 24 months from the last exchange.
- Server security logs — 30 days, after which they are deleted automatically.
- Marketing list — deleted within 30 days of your withdrawal of consent, or within 30 days of two full years of inactivity, whichever comes first.
After the relevant period ends, the data is either deleted or anonymised for statistical purposes.
8. International transfers
We try to keep your data inside the United Kingdom. Where a recipient processes your data outside the UK, we use the ICO-approved safeguards:
- For Stripe: the UK International Data Transfer Agreement (IDTA) and Stripe's participation in the EU-US Data Privacy Framework (where eligible).
- For AWS: AWS UK / EU regions, with the AWS Data Processing Addendum and AWS's participation in the EU-US Data Privacy Framework.
- For Postmark: the EU Standard Contractual Clauses plus the UK Addendum.
On request we can provide a copy of the relevant safeguard document. Where personal data leaves the UK, we have assessed the destination country's data-protection laws and the safeguards in place to ensure your rights remain protected.
9. Your rights
Under the UK GDPR you have the following rights. None of these rights is absolute — in some cases we may need to keep certain data to comply with a legal obligation (for example, HMRC) or to defend a legal claim.
- Right of access — you can ask us for a copy of the personal data we hold about you.
- Right to rectification — you can ask us to correct data that is wrong or to complete data that is incomplete.
- Right to erasure — you can ask us to delete data, subject to our legal retention obligations.
- Right to restriction of processing — you can ask us to pause processing while a question is resolved.
- Right to data portability — for data you provided to us and that we process by automated means on the basis of consent or contract, you can ask us to provide a portable copy.
- Right to object — you can object to processing based on our legitimate interests, and we will stop unless we can show compelling legitimate grounds that override your interests.
- Right to withdraw consent — where we rely on your consent (for marketing emails), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to complain to the ICO — see section 15 below.
To exercise any of these rights, email privacy@icelabz.co.uk. We aim to respond within one calendar month. We will not charge you for responding to a valid request.
10. Children
Mandarin Audio is designed for adult language learners. The minimum age to create an account is 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 16 you should ask a parent or guardian to review this policy with you before creating an account.
If you are a parent or guardian and believe that your child has provided personal data to Mandarin Audio, please email privacy@icelabz.co.uk and we will delete the account and any associated data within 7 days.
11. Security
We protect your personal data with industry-standard technical and organisational measures:
- Encryption in transit — all web traffic is served over HTTPS using TLS 1.2 or higher.
- Encryption at rest — production database columns containing personal identifiers (email, profile fields) are encrypted at rest; backups are encrypted.
- Access control — staff access to personal data is on a need-to-know basis, with role-based permissions and audit logging.
- Two-factor authentication — required for all administrative access to Mandarin Audio systems.
- Vulnerability testing — annual third-party penetration test and continuous dependency-vulnerability scanning.
- Incident response — we will notify the ICO within 72 hours of becoming aware of any personal-data breach that meets the threshold under UK GDPR Article 33, and will inform affected users where required by Article 34.
No security measure is perfect, but we continually invest in reducing risk and responding quickly to incidents.
13. Changes to this policy
We may update this policy from time to time. The current effective date and version are shown at the top of this page. Material changes — meaning changes that affect how we collect, use, share or retain your personal data — will be announced to active registered users at least 14 days before they take effect, by email to the address on file and via an in-product banner.
Previous versions of this policy are preserved in our public source repository at github.com/icelabz/mandarinaudio-website.
14. Contact us
For any privacy query or to exercise your rights:
icelabz solutions ltd — Privacy TeamEmail: privacy@icelabz.co.uk
Postal: c/o Bromley Heath Accountancy Ltd, 42c Badminton Road, Downend, Bristol BS16 6BS, United Kingdom
We aim to acknowledge all privacy enquiries within 3 working days and to respond substantively within one calendar month. You can also use our Mandarin Audio account deletion page to request deletion by email confirmation.
15. Complaints to the ICO
If you believe that we have not handled your personal data fairly and lawfully, or you are not happy with our response to a request, you have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's OfficeWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint/
16. Account and selected-data deletion
You can request deletion of your Mandarin Audio account and associated personal data at mandarinaudio.com/en-gb/delete-account/, or request partial deletion of selected categories at mandarinaudio.com/en-gb/delete-data/. For security, the API sends a one-time magic link to the account email address; the link expires after 1 hour and must be confirmed before any deletion is scheduled.
After confirmation, Mandarin Audio applies a 7-day cooling-off period. The account-deletion worker then revokes any active Google Play subscription through the Google Play Developer API before reusing our AccountCleanupService to purge the requested data. You may cancel during the cooling-off period. We retain only data that icelabz solutions ltd must keep for legal, tax, security or billing-audit purposes, for the applicable retention period described in this policy.
An administrator can execute a confirmed request early or cancel it through authenticated API tools. This administrative process has no public website admin interface and does not change the user's magic-link confirmation or the retention obligations above.