Privacy Policy
Effective Date: 2026-08-09
Last Updated: 2026-08-09
This Privacy Policy describes how Langly UK ("Langly UK", "we", "our", or "us") collects, uses, stores, discloses, transfers and otherwise processes personal data when individuals access or use the Langly platform, including our websites, mobile applications, web applications, services, APIs and all related functionality (collectively, the "Service").
This Privacy Policy has been prepared to comply with applicable privacy and data protection legislation, including, where applicable:
- Regulation (EU) 2016/679 ("GDPR");
- United Kingdom GDPR and the UK Data Protection Act 2018;
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
- Children's Online Privacy Protection Act (COPPA);
- Personal Information Protection and Electronic Documents Act (PIPEDA);
- Australian Privacy Act 1988;
- Applicable consumer protection legislation;
- Any other mandatory privacy legislation applicable to the jurisdiction in which the Service is offered.
Where local mandatory laws grant individuals greater rights than those described in this Privacy Policy, those mandatory legal rights shall prevail to the extent required by applicable law.
1. About Langly
Langly is an online collaborative vocabulary learning platform allowing users to create, organize, maintain and study vocabulary collections ("Vocabs"). Users may create private, shared or public vocabulary collections, collaborate with other users, manage permissions, organise words into categories, and use various learning tools designed to improve language acquisition.
The Service is available through supported web browsers and compatible mobile applications for supported operating systems.
Certain premium functionality is available through paid subscriptions processed by third-party payment providers.
The Service is currently under continuous development. Certain functionality may be added, modified, suspended or removed without prior notice where permitted by applicable law.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- Visitors of our website;
- Registered users;
- Premium subscribers;
- Users accessing the Service through OAuth providers;
- Parents or legal guardians contacting us regarding children;
- Individuals submitting reports, complaints or feedback;
- Individuals communicating with our support or legal contact addresses.
This Privacy Policy does not apply to third-party services, websites or applications that are not operated by Langly UK, even where accessible through links within the Service.
Third-party providers remain independently responsible for their own privacy practices. Users should review the privacy documentation of those providers before using their services.
3. Data Controller
For the purposes of applicable data protection legislation, the data controller is:
Langly UK
Sole Proprietorship
2094 Nagykovácsi
Széna utca 5.
Hungary
Registration Number: 92231791-2-33
Tax Number: HU92231791
Representative:
Bence Körmendy-Rácz
Owner
4. Contact Information
- General enquiries: contact@langly.uk
- Privacy-related requests: privacy@langly.uk
- Legal notices, child safety reports and regulatory communications: legal@langly.uk
Where required by applicable law, we may verify the identity of individuals submitting requests before responding. Failure to provide sufficient information may delay or prevent fulfilment of the request where verification is legally required.
5. No Data Protection Officer
At the date of publication, Langly UK has not designated a formal Data Protection Officer ("DPO") because such appointment is not currently required under applicable law based on the nature and scale of the Service.
Privacy requests should instead be directed to the Privacy Contact listed above. Should appointment of a Data Protection Officer become legally required, this Privacy Policy will be updated accordingly.
6. Definitions
Unless otherwise required by applicable law, the following definitions apply throughout this Privacy Policy.
- Account means a registered user profile.
- User means any natural person using the Service.
- Personal Data means any information relating to an identified or identifiable individual.
- Processing means any operation performed on Personal Data.
- Controller means the entity determining the purposes and means of processing.
- Processor means a third party processing data on behalf of the Controller.
- Service means all Langly websites, applications, APIs and related services.
- Content means any information submitted by users, including vocabulary items, descriptions, feedback and reports.
- OAuth Provider means third-party authentication providers such as Apple or Google.
- Subscription means any paid premium access purchased through Stripe.
- Applicable Law means all mandatory legislation governing the processing of Personal Data.
7. Interpretation
Headings are provided solely for convenience and do not affect interpretation.
References to legislation include amendments, replacements and successor legislation.
If any provision of this Privacy Policy is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.
Nothing in this Privacy Policy shall be interpreted as limiting any mandatory legal rights that individuals may have under applicable law.
8. Children's Privacy Overview
The Service may be accessed by individuals of various ages. However, the Service is not specifically designed as a children's service.
At present, the Service does not implement age verification, parental consent workflows, or age estimation technologies. Accordingly, where applicable law requires parental or guardian consent, the responsibility for ensuring that such consent exists rests with the individual using the Service and, where applicable, their parent or legal guardian.
Where we become aware that Personal Data has been collected in violation of applicable children's privacy legislation, we reserve the right to suspend access, restrict processing, request additional verification, or delete the relevant information where legally appropriate.
A dedicated Children's Privacy Notice and Parent Information Notice form part of this Privacy Policy.
9. Changes to this Privacy Policy
We reserve the right to amend, modify, supplement or replace this Privacy Policy at any time to reflect legal, technical, operational, commercial, or regulatory developments.
Where required by applicable law, material changes will require renewed acceptance before continued use of certain Service functionality.
Previous internal versions of this Privacy Policy may be retained for legal, regulatory, audit, security, or evidential purposes, but historical versions are not necessarily published.
10. Categories of Personal Data We Process
Depending on how you interact with the Service, we may process different categories of Personal Data. We only process information that is reasonably necessary for the operation, security, maintenance, improvement, legal compliance or protection of the Service and our legitimate interests, unless a different legal basis applies.
10.1 Account Registration Information
When you register an account, we may collect:
- Full name;
- Username;
- Email address;
- Password (stored only as a cryptographic hash);
- Preferred language (locale);
- Accepted legal document version;
- Email verification status;
- Account creation and update timestamps.
These data are necessary to establish and maintain your account, authenticate your identity, protect the Service against unauthorized access, comply with legal obligations, and provide the requested functionality.
10.2 Authentication Data
Whenever you sign in, access protected areas or maintain an authenticated session, we may process authentication-related information including:
- Session identifiers;
- Authentication tokens;
- Remember-me tokens;
- Session timestamps;
- IP address associated with the session;
- Browser user agent string;
- Session activity metadata.
Authentication data is processed solely for security, fraud prevention, session management and protection of user accounts.
10.3 OAuth Login Information
If you choose to authenticate using a third-party identity provider, we may receive information from that provider, including:
- Provider identifier;
- Provider account identifier;
- Name;
- Email address;
- Access token;
- Refresh token (where supplied by the provider).
The categories of information actually shared depend entirely upon the permissions granted by you and the policies of the relevant OAuth provider.
At present, the supported OAuth Providers for sign-in are Apple and Google. When you start Apple or Google sign-in, your browser is redirected to the selected provider. That provider may receive information necessary to process the authentication request, including the fact that you are attempting to authenticate to Langly, Langly's client or application identifier, redirect URL, requested scopes or permissions, state or similar security parameters, and ordinary network, browser, device, cookie and session information processed by that provider. We do not send your Langly password, vocabulary content, reports, subscription status or billing details to Apple or Google for sign-in.
After successful authentication, Apple or Google may return an authorization code, identity token or similar authentication response and may provide, or allow us to obtain, your provider account identifier, name, email address, email verification status, access token and refresh token where supplied. Google sign-in may provide information permitted by the openid, profile and email scopes. Apple sign-in may provide your name and verified email address, and may provide a private relay email address where you choose that option. Apple may provide name information only when you first authorize the Service.
We do not control what information is made available by third-party identity providers.
10.4 User Generated Content
Users may voluntarily submit content including:
- Vocabulary titles;
- Vocabulary descriptions;
- Vocabulary visibility settings;
- Vocabulary language selections;
- Words and translations;
- Word categories;
- Word classifications;
- Feedback messages;
- Reports regarding other content.
Users remain solely responsible for the content they submit. Users should avoid uploading Personal Data belonging to third parties unless they have an appropriate legal basis for doing so.
Some words, translations or study content may be marked as requiring a Subscription and may be blurred, hidden or otherwise unavailable to users who do not have the required Subscription or permissions. We may process subscription-required flags, Subscription status, account identifiers and authorship information to determine whether particular word content should be displayed.
10.5 Technical Information
When the Service is used, technical information may be processed automatically, including:
- IP address;
- Browser type;
- Browser version;
- Operating system information available through the user agent;
- Session identifiers;
- Requested URLs;
- Locale preferences;
- HTTP request metadata;
- Security logs;
- Rate limiting information.
This information is processed exclusively for technical operation, availability, security, fraud detection, capacity planning, diagnostics, and legal compliance.
10.6 Subscription and Billing Information
Where Premium Services are purchased, we may process:
- Stripe Customer ID;
- Subscription identifier;
- Subscription status;
- Subscription plan;
- Subscription renewal information;
- Payment method type;
- Last four digits of the payment method where provided by Stripe;
- Billing-related metadata.
Full payment card information is not processed or stored by Langly UK. Payment card details are processed directly by Stripe in accordance with Stripe's own privacy documentation and PCI DSS requirements.
10.7 Communications
Where you contact us, submit feedback, or send legal enquiries, we may process:
- Your email address;
- Your account identifier;
- Your communication;
- Attachments you voluntarily provide;
- Support history.
10.8 Reports and Moderation Records
When content is reported, we may store:
- Reporter identifier;
- Reported content identifier;
- Snapshot of the reported content;
- Date of submission;
- Moderation-related metadata.
Report records may continue to exist after the original content or user account has been removed where retention is reasonably necessary for legal compliance, security, fraud prevention, defence of legal claims, audit purposes, or enforcement of our Terms of Service.
11. Sources of Personal Data
We obtain Personal Data from one or more of the following sources:
- Directly from you;
- Your browser or device;
- Your authenticated session;
- OAuth providers;
- Stripe;
- Cookies and similar technologies;
- Security systems;
- Reports submitted by other users;
- Feedback submitted by you;
- Legal requests and regulatory authorities where applicable.
We do not intentionally collect Personal Data from publicly available sources, commercial data brokers, or third-party marketing databases.
12. Purposes of Processing
Personal Data may be processed for one or more of the following purposes:
- Creating and maintaining user accounts;
- Authenticating users;
- Providing collaborative vocabulary management;
- Displaying user-generated content;
- Providing Premium Services;
- Processing subscriptions;
- Providing customer support;
- Generating requested data exports;
- Operating account recovery procedures;
- Verifying email addresses;
- Detecting abuse, fraud and security incidents;
- Preventing unauthorised access;
- Protecting the integrity of the Service;
- Investigating reports;
- Maintaining system security;
- Complying with legal obligations;
- Establishing, exercising or defending legal claims;
- Enforcing our Terms of Service;
- Operating backups, disaster recovery and business continuity processes;
- Improving the stability, reliability and security of the Service.
We do not currently process Personal Data for behavioural advertising, cross-context behavioural advertising, automated profiling producing legal or similarly significant effects, or automated decision-making within the meaning of Article 22 GDPR. Should this change in the future, we will update this Privacy Policy before such processing begins where required by applicable law.
13. Legal Bases for Processing (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies, we rely upon one or more of the following legal bases:
- Performance of a contract or steps prior to entering into a contract;
- Compliance with legal obligations;
- Our legitimate interests, provided such interests are not overridden by your rights and freedoms;
- Your consent where consent is legally required;
- The establishment, exercise or defence of legal claims;
- Protection of vital interests where applicable.
Where consent is relied upon, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal became effective.
Where multiple legal bases apply to a particular processing activity, we may rely on any applicable legal basis permitted under the relevant legislation.
14. Disclosure of Personal Data
We do not sell Personal Data in the ordinary meaning of that term. Except where expressly described in this Privacy Policy or required by applicable law, Personal Data is not disclosed to unrelated third parties.
Personal Data may be disclosed where reasonably necessary for the operation, security, maintenance or lawful provision of the Service.
Recipients may include:
- Infrastructure providers;
- Cloud hosting providers;
- Payment processors;
- Identity providers;
- Email delivery providers;
- Professional advisers;
- Regulators;
- Courts;
- Law enforcement authorities;
- Other recipients where disclosure is required by law.
We disclose only the minimum amount of information reasonably necessary for the relevant purpose unless applicable law requires otherwise.
15. Service Providers and Processors
In order to operate the Service we may engage carefully selected service providers acting as processors or independent controllers depending on the nature of the service provided.
Current categories include:
- Laravel Cloud (hosting and infrastructure);
- Stripe (payments, subscriptions and billing);
- Sign in with Apple;
- Sign in with Google;
- Email delivery providers configured by the Service;
- Content filtering technologies;
- Security providers;
- Professional advisers where legally necessary.
Service providers receive only the information reasonably required for the services they perform and are expected to process Personal Data only in accordance with applicable contractual obligations and applicable law.
The identity of individual providers may change from time to time without prior notice where such replacement does not materially affect your rights.
16. International Transfers
Because the Service may utilise globally distributed infrastructure, Personal Data may be processed in countries outside your country of residence, including countries outside the European Economic Area or the United Kingdom.
Whenever Personal Data is transferred internationally, we seek to implement one or more appropriate safeguards where required by applicable law, including where appropriate:
- European Commission Adequacy Decisions;
- UK adequacy regulations;
- Standard Contractual Clauses (SCCs);
- International Data Transfer Addendum;
- Binding contractual obligations;
- Other legally recognised transfer mechanisms.
Certain providers may themselves engage authorised subprocessors in multiple jurisdictions. Such providers remain responsible for ensuring compliance with their contractual and legal obligations.
The countries in which infrastructure or subprocessors operate may change over time without prior notice where legally permissible.
17. Data Storage Locations
The Service currently operates using infrastructure provided through Laravel Cloud.
The physical location of particular servers, backups, redundant infrastructure, disaster recovery environments, logging systems, or temporary processing environments may change over time according to operational, availability, security, performance, or regulatory requirements.
For resilience purposes, Personal Data may be replicated across multiple secure environments operated by our service providers.
We do not guarantee that all processing will always occur within a single country or jurisdiction.
18. Data Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
18.1 Registered Accounts
Account information is generally retained while an account remains active.
After deletion, certain information may continue to be retained where necessary for:
- legal obligations;
- fraud prevention;
- security investigations;
- dispute resolution;
- enforcement of contractual rights;
- tax compliance;
- accounting requirements;
- defence of legal claims.
18.2 Unverified Accounts
Accounts that remain unverified may be automatically removed after an appropriate verification period in accordance with the operational policies of the Service.
18.3 Session Information
Authentication sessions are retained only as long as necessary for security, authentication, technical operation, or fraud prevention. Inactive sessions may be automatically removed.
18.4 Reports
Reports, moderation evidence, and snapshots of reported content may continue to be retained after the original content or user account has been deleted where reasonably necessary to protect users, investigate abuse, or defend legal claims.
18.5 Billing Records
Financial records may be retained for periods required by applicable accounting, taxation, financial reporting, anti-fraud, or regulatory legislation.
18.6 Technical Logs
Security logs, diagnostic information, system events, and operational logs may be retained for periods reasonably necessary to maintain system security, detect abuse, respond to incidents, or satisfy legal obligations.
Retention periods may differ between categories of information.
19. Backups
The Service may maintain encrypted backups, redundant storage, or disaster recovery copies for operational resilience.
Deletion of Personal Data from active systems does not necessarily result in immediate removal from backup media. Backup copies may remain until they are securely overwritten, rotated, or destroyed according to operational backup schedules.
Where restoration of backups becomes necessary, reasonable efforts will be made to ensure that restored Personal Data remains subject to this Privacy Policy.
20. Security Measures
We implement administrative, technical, and organisational measures that are reasonably designed to protect Personal Data against accidental, unlawful, or unauthorised destruction, loss, alteration, disclosure, or access.
Security measures may include:
- password hashing;
- encrypted communications;
- authenticated sessions;
- email verification;
- rate limiting;
- CSRF protection;
- role-based access controls;
- logging and monitoring;
- secure development practices;
- access restrictions;
- regular software updates;
- incident response procedures.
No method of electronic transmission, storage, or processing is completely secure. Accordingly, we cannot guarantee that the Service will always be free from security incidents, cyberattacks, or unauthorised access.
Users are responsible for maintaining the confidentiality of their passwords, authentication credentials, devices, and account access.
21. Data Accuracy
Users are responsible for ensuring that information submitted to the Service is accurate, complete, and kept reasonably up to date.
We are not responsible for inaccuracies arising from information voluntarily submitted by users or third parties.
22. Automated Decision-Making
The Service does not currently perform automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.
Certain automated technical processes, including authentication, spam prevention, content validation, rate limiting, security controls, or system integrity mechanisms, may operate automatically as necessary for the technical operation of the Service. Such automated processes are not intended to produce legally significant decisions about individuals.
23. Cookies and Similar Technologies
The Service uses cookies and similar technologies that are necessary for the secure operation, authentication, localisation and functionality of the Service.
At the time of publication, the Service does not intentionally deploy advertising, behavioural profiling or cross-site tracking technologies. Should additional categories of cookies be introduced in the future, this Privacy Policy and any legally required consent mechanisms will be updated accordingly.
23.1 Strictly Necessary Cookies
These cookies are essential for the operation of the Service and cannot normally be disabled without affecting functionality.
- Session authentication;
- CSRF protection;
- Security controls;
- Load balancing where applicable;
- User authentication status;
- Remember-me authentication where selected by the user.
23.2 Preference Cookies
Preference cookies may store user interface settings such as language selection in order to improve usability.
23.3 Authentication Cookies
Where a user selects a persistent login option, an authentication cookie may remain on the user's device in accordance with the authentication mechanisms implemented by the Service. Users may invalidate persistent authentication by signing out, changing their password or using available account security controls.
23.4 Third-Party Cookies
Certain third-party providers, including payment providers or identity providers, may set their own cookies while providing their services. Such cookies are governed solely by the privacy policies of those third parties.
23.5 Browser Controls
Most browsers permit users to refuse, delete or restrict cookies. Disabling essential cookies may prevent some or all functionality of the Service from operating correctly.
24. Children's Privacy
The Service may be accessed by individuals of various ages. However, the Service is designed as a general-purpose educational platform and is not specifically directed toward children.
At present, the Service does not implement age verification, age estimation, parental consent workflows or parental account linking. Accordingly, we do not intentionally distinguish between adult and minor users during registration.
Parents and legal guardians remain responsible for supervising the online activities of children under their care and determining whether use of the Service is appropriate under applicable law.
Where applicable legislation requires parental authorisation before Personal Data may lawfully be processed, responsibility for ensuring that such authorisation has been obtained rests with the individual using the Service and, where appropriate, their parent or legal guardian.
If we reasonably believe that Personal Data has been collected in violation of applicable children's privacy legislation, we reserve the right to request additional information, suspend processing, restrict access, disable accounts or delete relevant information where appropriate.
Nothing in this Privacy Policy shall be interpreted as encouraging children to provide more information than is reasonably necessary for use of the Service.
25. Notice to Parents and Legal Guardians
Parents or legal guardians who believe that a child has submitted Personal Data without appropriate authority may contact us using the contact details provided in this Privacy Policy.
Where reasonably necessary, we may request information sufficient to verify the identity and authority of the requesting parent or legal guardian before taking any action regarding the relevant account.
Subject to applicable law and appropriate verification, we may:
- provide information regarding Personal Data associated with the account;
- correct inaccurate information;
- restrict processing;
- delete Personal Data where legally appropriate;
- suspend or permanently close the relevant account.
We reserve the right to decline requests where identity or legal authority cannot reasonably be verified or where disclosure would infringe the rights and freedoms of another individual.
26. Your Privacy Rights
Depending on your country of residence and applicable legislation, you may have one or more of the following rights.
- Right of access;
- Right to rectification;
- Right to erasure;
- Right to restriction of processing;
- Right to data portability;
- Right to object;
- Right to withdraw consent;
- Right to lodge a complaint with a supervisory authority;
- Rights relating to automated decision-making where applicable;
- Additional rights granted by local legislation.
The availability of particular rights depends upon the legislation applicable to the relevant processing activity. Certain rights may be limited where exceptions permitted by law apply.
27. Exercising Your Rights
Requests concerning Personal Data should be submitted to the privacy contact identified in this Privacy Policy.
To protect the security of Personal Data, we may require reasonable identity verification before responding to requests.
Requests that are manifestly unfounded, excessive, repetitive or abusive may be refused or subject to reasonable limitations where permitted by applicable law.
Where legally permitted, we may refuse to disclose information that would adversely affect the rights, freedoms, confidentiality, security or legitimate interests of other individuals or the Service.
Responses will normally be provided within the period required by applicable law, subject to any lawful extensions.
28. California Privacy Rights
Residents of California may possess additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including rights relating to access, deletion, correction and portability of certain Personal Information.
At the time of publication, Langly UK does not knowingly sell Personal Information or share Personal Information for cross-context behavioural advertising as those terms are defined under applicable California legislation.
Where California law requires additional disclosures in the future, this Privacy Policy may be supplemented by a dedicated California Privacy Notice.
29. Canadian Privacy Rights
Where PIPEDA or substantially similar provincial legislation applies, individuals may request access to Personal Information, correction of inaccuracies and information concerning the processing of Personal Information, subject to lawful limitations.
30. Australian Privacy Rights
Where the Australian Privacy Act applies, individuals may request access to and correction of Personal Information, subject to applicable legal exceptions. Complaints concerning privacy matters may be directed to us in the first instance.
31. United Kingdom Privacy Rights
Individuals located within the United Kingdom benefit from the rights provided by the UK GDPR and the Data Protection Act 2018 in the same manner as described throughout this Privacy Policy, subject to applicable statutory exceptions.
32. User Responsibilities
Users are solely responsible for all information, content and materials that they choose to submit to the Service.
Users should ensure that any Personal Data uploaded to the Service is accurate, lawfully obtained and may legally be processed or shared through the Service.
Users must not upload Personal Data belonging to third parties unless they possess an appropriate legal basis or authorisation under applicable law.
Users remain solely responsible for complying with any legal obligations arising from the content they submit.
33. User-Generated Content
The Service allows users to create vocabulary collections and other textual content. Such content is created entirely by users and does not necessarily reflect the views or opinions of Langly UK.
We do not routinely review, verify, endorse or guarantee the accuracy, legality, completeness or reliability of user-generated content before publication.
Where content is reported or otherwise comes to our attention, we reserve the right, but are under no obligation except where required by applicable law, to investigate, restrict, remove or preserve such content.
Users remain solely responsible for all consequences arising from content they submit.
34. Sensitive Personal Data
The Service is not intended for the storage or processing of special categories of Personal Data or other highly sensitive information unless expressly required for a specific lawful purpose.
Users are strongly encouraged not to include information concerning health, biometric data, political opinions, religious beliefs, trade union membership, criminal convictions, sexual orientation or other sensitive information within free text fields.
Where users voluntarily submit such information, they do so at their own initiative and responsibility, subject to applicable law.
35. Third-Party Services
The Service may integrate with or provide links to third-party services including, without limitation, payment providers, authentication providers and other external services.
We do not control the privacy practices, security measures or content of such third parties.
Each third-party provider remains independently responsible for its own processing activities. Users should review the applicable privacy policies before using those services.
36. Legal Requests and Law Enforcement
We may preserve, disclose or otherwise process Personal Data where we reasonably believe such action is necessary to:
- comply with applicable law;
- respond to legally valid governmental requests;
- protect the rights or safety of individuals;
- investigate fraud or abuse;
- protect the integrity of the Service;
- establish, exercise or defend legal claims;
- enforce our Terms of Service.
Nothing in this Privacy Policy limits our ability to comply with mandatory legal obligations imposed by competent authorities.
37. Business Changes
If Langly UK undergoes a merger, acquisition, corporate restructuring, investment, asset sale, financing transaction, insolvency proceeding or other business reorganisation, Personal Data may be transferred as part of that transaction where permitted by applicable law.
Any successor entity shall continue processing Personal Data in accordance with this Privacy Policy or another legally compliant privacy notice.
38. Availability of the Service
The Service is provided on an ongoing basis but may be modified, suspended, restricted or discontinued, in whole or in part, at any time for operational, technical, security, commercial or legal reasons.
Nothing in this Privacy Policy shall be interpreted as guaranteeing uninterrupted availability of the Service.
39. Data Security Incidents
Although appropriate technical and organisational measures are implemented, no electronic service can be guaranteed to remain completely secure.
Should a Personal Data Breach occur, we will take such measures as are required by applicable law, including notification of competent supervisory authorities and affected individuals where legally required.
40. Limitation of Privacy-Related Liability
Nothing in this Privacy Policy excludes or limits liability where such exclusion or limitation would be prohibited by applicable law.
Subject to mandatory legal requirements, Langly UK shall not be responsible for:
- information voluntarily disclosed by users;
- content submitted by users;
- actions of third-party service providers acting independently;
- temporary interruptions of the Service;
- unauthorised access resulting from circumstances beyond our reasonable control;
- losses arising from users' failure to maintain appropriate account security;
- acts or omissions of other users.
Users acknowledge that the Internet and electronic communications inherently involve certain security risks that cannot be completely eliminated.
41. Complaints
Individuals who believe that their Personal Data has been processed unlawfully are encouraged to contact us first so that we may attempt to resolve the matter.
Nothing in this Privacy Policy restricts the right of any individual to lodge a complaint with a competent supervisory authority where permitted by applicable law.
42. Supervisory Authorities
Individuals located within jurisdictions recognising independent data protection authorities may submit complaints directly to the competent supervisory authority in their country of residence, place of work or place of the alleged infringement, subject to applicable law.
43. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy at any time. Changes may result from legal developments, technical improvements, operational requirements, regulatory guidance, security considerations or changes to the Service.
Where required by applicable law, users may be requested to acknowledge updated versions before continuing to use certain functionality.
The most recent version published by Langly UK supersedes all previous publicly available versions unless expressly stated otherwise.
44. Contact Us
- For general enquiries: contact@langly.uk
- For privacy requests: privacy@langly.uk
- For legal notices and child safety matters: legal@langly.uk
45. Governing Version
This Privacy Policy is published in English. Translations may be provided solely for convenience. In the event of any inconsistency or conflict between a translated version and the English version, the English version shall prevail to the maximum extent permitted by applicable law.
46. Final Provisions
If any provision of this Privacy Policy is found to be unlawful, invalid or unenforceable, the remaining provisions shall remain in full force and effect.
The failure of Langly UK to enforce any provision of this Privacy Policy shall not constitute a waiver of any right or provision.
This Privacy Policy shall be interpreted in a manner that gives maximum effect to applicable data protection legislation while preserving the lawful operation of the Service.
© Langly. All rights reserved.