GDPR Compliance | Weekly Cross - Data Protection & Privacy Rights

🛡️ GDPR Compliance

Your data protection rights and our commitment to privacy under European law

✅ GDPR Compliant Since May 2018

Weekly Cross is fully compliant with the General Data Protection Regulation (GDPR) and committed to protecting your privacy rights.

🛡️ GDPR Compliance Statement

Last updated: August 2025 | Regulation (EU) 2016/679

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of EU residents, regardless of where the organization is located.

Our Commitment to You

At Weekly Cross, we are committed to:

  • Protecting your personal data with appropriate technical and organizational measures
  • Being transparent about how we collect, use, and share your information
  • Respecting your rights and providing easy ways to exercise them
  • Only processing data that is necessary for providing our educational services
  • Ensuring data accuracy and keeping information up to date

Your Data Protection Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

Request access to your personal data and receive a copy of the information we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data under certain circumstances ("right to be forgotten").

Right to Restrict Processing

Request limitation of how we process your personal data in specific situations.

Right to Data Portability

Receive your personal data in a structured, machine-readable format or transfer it to another service.

Right to Object

Object to processing of your personal data based on legitimate interests or for direct marketing.

Personal Data We Process

We only collect and process personal data that is necessary for providing our English learning services:

Data Category Examples Legal Basis Retention
Account Information Email, username, profile preferences Contract performance Until account deletion
Learning Progress Exercise completion, scores, time spent Legitimate interest 2 years after last activity
Usage Analytics Page views, click patterns, device info Legitimate interest 26 months (Google Analytics)
Communication Support messages, feedback Contract performance 3 years
Technical Data IP address, browser, cookies Legitimate interest Session or as specified

Legal Basis for Processing

We process your personal data under the following legal bases:

Contract Performance

Processing necessary to provide our educational services, manage your account, and fulfill our obligations to you as a user.

Legitimate Interest

Processing for website analytics, improving our services, security monitoring, and marketing communications (with opt-out options).

Consent

When you explicitly agree to specific processing activities, such as marketing emails or optional analytics cookies.

Legal Obligation

When we're required by law to process your data, such as for tax records or responding to legal requests.

How We Protect Your Data

We implement comprehensive security measures to protect your personal data:

  • Encryption: All data transmissions use SSL/TLS encryption
  • Access Controls: Role-based access with multi-factor authentication
  • Data Minimization: We only collect data necessary for our services
  • Regular Audits: Security assessments and vulnerability testing
  • Staff Training: Regular privacy and security training for all team members
  • Incident Response: Procedures for handling potential data breaches
  • Vendor Management: Due diligence for third-party service providers

International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). When we transfer your data internationally, we ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
  • Standard Contractual Clauses: EU-approved contracts for data protection
  • Certification Schemes: Providers certified under recognized privacy frameworks
  • Data Processing Agreements: Contractual obligations for data protection

Current Transfer Locations

  • United States: Google Analytics (Privacy Shield certified), AWS (Standard Contractual Clauses)
  • Canada: Some hosting services (adequacy decision)
  • United Kingdom: Analytics services (adequacy decision)

Our GDPR Compliance Journey

May 2018 - GDPR Implementation

Updated privacy policies, implemented data subject rights, and established data protection procedures.

Ongoing - Regular Audits

Quarterly privacy impact assessments and annual data protection compliance reviews.

2024 - Enhanced Controls

Implemented automated data retention policies and improved consent management systems.

2025 - Continuous Improvement

Updated procedures based on regulatory guidance and implemented additional security measures.

Exercise Your Rights & Contact Us

To exercise any of your data protection rights or if you have questions about our GDPR compliance:

Data Protection Contact

  • Email: privacy@weeklycross.com
  • Response Time: Within 30 days (as required by GDPR)
  • Subject Line: Include "GDPR Request" for faster processing
  • Identity Verification: May be required for security purposes

Right to Lodge a Complaint: If you're not satisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority. For EU residents, you can find your local authority at ec.europa.eu/justice/data-protection.

Privacy Policy Contact DPO
Scroll to Top