Articles in this section

Privacy Policy

Last updated: August 20, 2026

1. Who We Are

ImmerseMe Limited (“ImmerseMe,” “we,” “us,” or “our”) provides an immersive language-learning software-as-a-service platform for schools, higher-education institutions, teachers and learners.

This Privacy Policy explains how personal information is collected, used, disclosed, retained and protected when people use ImmerseMe 2.0, including learner, teacher and administrator web experiences and optional AI-powered conversation features.

Contact: hello@immerseme.com

2. Our Role When Schools Use ImmerseMe

When a school, district, university or other institution provides or manages user accounts, class rosters or learning data, the institution generally determines why the data is used and ImmerseMe processes that data to provide the contracted service. Depending on applicable law and contract wording, the institution may act as controller/business and ImmerseMe as processor/service provider.

Schools remain responsible for obtaining any permissions, notices or consents they are legally required to obtain from learners, parents/guardians or staff before using the service.

We do not sell student personal information. We do not use institutional or learner data for third-party advertising, data brokerage or unrelated commercial profiling.

3. Information We Process

Depending on how the service is used, we may process:

  • account and profile information, such as name, email address, username, role, language preference, locale/timezone and organization/class relationships;
  • school, roster and class information, including institutional identifiers and teacher/learner relationships;
  • authentication and security information, such as password hashes, reset-token metadata, session information, two-factor/trusted-device information, IP address, browser/user-agent information and authentication activity;
  • learning information, including activity responses, scores, pronunciation/accuracy measures, progress, XP, completion records and teacher-reporting data;
  • assignments, tasks and grades where those features are enabled;
  • streamed microphone audio used for speech recognition or AI conversation; ImmerseMe does not intentionally persist raw learner microphone audio as a stored audio file/entity;
  • AI conversation information, including conversation text, generated responses, moderation metadata and session reports/metrics;
  • limited operational, security and service-performance information necessary to operate, secure and troubleshoot the service;
  • support and feedback information, including content a user chooses to submit and, where the Usersnap feedback tool is used, potentially screenshots, screen recordings, console logs, page URL and browser/device information; and
  • operational logs, security telemetry and backup copies.

We do not intentionally collect health information, genetic information, facial-recognition templates or fingerprint data as part of normal ImmerseMe functionality. Voice is processed to provide speech and conversation functionality and is not used by ImmerseMe for biometric identification or authentication.

4. How We Use Information

We use information to:

  • provide and operate the language-learning service;
  • create and manage accounts, classes and school integrations;
  • authenticate users and protect accounts;
  • deliver learning activities, scoring, progress tracking and teacher reporting;
  • provide speech recognition, pronunciation processing and optional AI conversation features;
  • provide content-safety and moderation controls;
  • send transactional or service-related communications;
  • provide support and respond to feedback;
  • understand service performance using limited operational and support information;
  • prevent abuse, investigate security events and respond to incidents;
  • maintain backups, resilience and disaster-recovery capability; and
  • meet legal, regulatory and contractual obligations.

We do not use customer or student data to train an ImmerseMe-owned foundation model.

5. AI and Speech Features

AI conversation is an optional feature that may be enabled for an organization. When it is used, learner speech may be transported through LiveKit Cloud and processed through Microsoft Azure Speech. Conversation text/context may be sent to OpenAI to generate responses, and Azure AI Content Safety is used for safety moderation.

Conversation text, generated responses, moderation metadata and session reports may be stored in ImmerseMe's primary database in Australia East. ImmerseMe does not intentionally persist raw learner audio as a stored audio file/entity.

OpenAI model-improvement/data-sharing is disabled for the production API organization. Standard OpenAI API abuse-monitoring retention may apply for up to 30 days where applicable; ImmerseMe does not claim zero vendor retention unless that control is specifically enabled and verified.

LiveKit Agent Observability is disabled for the current production project. ImmerseMe does not use LiveKit SIP or Egress recording workflows for learner conversations.

Users should not provide unnecessary personal, confidential or sensitive information in free-form AI conversations. Safety controls reduce risk but cannot guarantee that a learner will never enter personal information.

6. Legal Bases and Customer Context

The legal basis for processing depends on the user's location, the type of account and the relationship between ImmerseMe and the customer.

Where the GDPR or similar law applies, processing may be based on:

  • performance of a contract or steps necessary to provide the service;
  • the institution's lawful authority and instructions for educational processing;
  • legitimate interests in operating, securing and improving the service, where those interests are not overridden by individual rights;
  • compliance with legal obligations; and
  • consent where consent is legally required, including for particular optional features or non-essential tracking technologies.

For school-managed student accounts, ImmerseMe generally relies on the institution's instructions and contractual authorization rather than seeking to replace the institution's own legal basis for educational processing.

7. School and Student Privacy

ImmerseMe is designed for educational use and may process education records and other student data on behalf of schools and institutions.

Where FERPA applies, schools may disclose education records to service providers acting under the school's control and for authorized educational purposes where the legal requirements are met. ImmerseMe uses school-provided data to provide, secure and support the service and not for unrelated advertising or sale.

Where state student-privacy laws apply, ImmerseMe aims to act consistently with applicable contractual and statutory requirements, including restrictions on selling student data, targeted advertising using student data and unauthorized profiling.

If a student or parent/guardian asks us to access, correct or delete school-controlled learner information, we may need to coordinate the request with the relevant school or institution.

8. Data Sharing

We disclose information only where necessary to provide, secure or support the service, comply with law, or follow a customer's authorized instructions.

Categories of recipients may include:

  • cloud hosting, infrastructure and security providers;
  • AI, speech and content-safety providers;
  • school rostering and SSO integration providers selected or enabled for the customer;
  • transactional email providers;
  • media/CDN providers; and
  • support/feedback providers.

We may also disclose information where required by valid legal process. ImmerseMe does not knowingly provide institutional data to law enforcement without valid legal authority. Where legally permitted and contractually appropriate, we may notify the affected customer before disclosure.

9. Cookies and Essential Technologies

ImmerseMe uses essential authentication/session technologies required to operate the service.

We also maintain limited operational, security, audit, application-error and infrastructure logging necessary to operate, secure and troubleshoot the service.

If we introduce non-essential tracking technologies in future, they will be reviewed through our privacy-impact and change-management processes and appropriate notice or consent controls will be implemented where required.

10. Data Retention and Deletion

We retain information only as long as reasonably necessary for the purposes described in this Policy, the applicable customer agreement, legal obligations and our approved retention standard.

Customer-controlled production personal data is normally deleted or approved-anonymized within 30 calendar days after a confirmed contract-termination or approved deletion trigger, unless a different period is required by law or contract.

Database backup copies are retained for up to 30 days in Azure Blob Storage, with temporary local backup copies retained for up to 3 days. Deleted production data may therefore remain in backup copies until the relevant backup expires.

Some production records and application/security logs still require additional technical automation to fully enforce approved retention periods. Those items are tracked through ImmerseMe's GRC and risk-management program.

11. Security

We use administrative, technical and organizational measures designed to protect personal information, including role-based access controls, encryption in transit, cloud-provider encryption at rest, privileged-access controls, secure secrets management, network and web-application protections, security logging, vulnerability management, incident response, employee security/privacy training requirements, and backup/recovery controls.

No system is completely secure, and we cannot guarantee absolute security.

12. International Data Transfers

ImmerseMe's core production architecture is Australia-centered, not Australia-only. Primary application/database infrastructure, Azure Blob Storage, Azure Speech and Azure AI Content Safety are configured in Australia East (Sydney).

Other providers use global networks or may process data in other countries. Where international-transfer laws apply, we rely on applicable contractual or legal safeguards, including Standard Contractual Clauses or equivalent transfer mechanisms where appropriate.

13. Subprocessors

We use trusted subprocessors to operate and support ImmerseMe. The current material subprocessors are listed below. We require subprocessors that process personal data on our behalf to be subject to appropriate data-protection and security obligations.

 

Subprocessor Purpose Categories of Personal Data Location of Processing
Microsoft Azure Core hosting/storage, speech, translation and content safety. Account, institutional, authentication, learning, transcript, media/backup data and live audio/text required for managed services. Australia East (Sydney) for primary hosting/storage and confirmed Azure Speech / AI Content Safety; Microsoft support/subprocessors may operate globally.
Cloudflare DNS, CDN, TLS, WAF and API protection. IP address, request/response metadata, authentication/session/API traffic in transit and security logs. Global edge / nearest-location processing.
Vercel React web application hosting and delivery. IP/device/browser/request information required to deliver the web application. Functions configured to Sydney; distributed edge delivery may occur outside Australia.
OpenAI Optional generative AI conversation. Educational context, learner conversation text/prompts, generated outputs and user-provided information entered into conversations. United States and other locations used by OpenAI affiliates/subprocessors under applicable transfer safeguards.
LiveKit Cloud Real-time media transport and voice-agent infrastructure. Live audio/media, room/session identifiers, technical metadata and inference data required for AI conversation. Global dynamic mesh and nearest-edge routing; inference-region restriction enabled.
SendGrid / Twilio Transactional and service email. Recipient name/email where included, message content and delivery metadata. Vendor-hosted; international processing may occur.
Edlink Customer-enabled rostering and SSO integration. Roster identity/profile, organization/class membership, SSO identifiers and tokens. Customer-selected region: United States (Iowa), Canada (Toronto), Germany (Frankfurt), or Australia (Sydney). Edlink states all personally identifiable information is stored within the selected region; additional non-personally identifiable metadata may be stored in the United States.
ClassLink Customer-enabled rostering and SSO integration. Roster identity/profile, organization/class membership, SSO identifiers and tokens. Depends on the customer's ClassLink deployment and configuration.
Bunny.net Video and media delivery. IP address and request/device/network metadata associated with media delivery. Global CDN edge processing based on user location.
Usersnap Support and feedback. User-initiated feedback, screenshots/screen recordings, console logs, page URL, browser/device data, optional name/email. EU-based support/feedback infrastructure; production processing described by Usersnap as AWS in Frankfurt, with related EU locations.

14. Your Privacy Rights

Depending on applicable law, individuals may have rights to request access, correction, deletion, portability, restriction or objection to certain processing, or to complain to a privacy regulator.

To exercise a right, contact hello@immerseme.com. We may need to verify identity before acting. For school-managed learner records, we may refer or coordinate the request with the relevant school or institution.

Our internal target is to respond to valid privacy-rights requests within 30 days unless applicable law or contract requires a different period.

15. Children and School-Managed Accounts

ImmerseMe is used in educational settings and may be used by children or minors through school-managed accounts. We process school-managed learner information only for authorized educational/service purposes and in accordance with the applicable customer agreement and law.

Where parental consent is legally required for a particular use, the school/customer is responsible for obtaining that consent unless the parties expressly agree otherwise.

16. Government and Law-Enforcement Requests

Requests from courts, regulators, governments or law enforcement are reviewed for valid legal authority, jurisdiction, scope and proportionality. We disclose only information legally required and, where permitted, seek to notify the affected customer or institution before disclosure.

17. Business Transfers and Service Retirement

If ImmerseMe is involved in a merger, acquisition, restructuring or sale of assets, customer and user information may transfer as part of that transaction subject to applicable law and contractual protections.

Customer/institution ownership rights in customer-provided data and service data remain with the customer/institution as set out in the applicable agreement. If the service is intentionally retired or the business closes, ImmerseMe aims to provide at least 90 days' notice/opportunity for customers to export or migrate available customer data where practicable, subject to legal, security, insolvency and technical constraints.

18. Changes to This Policy

We may update this Privacy Policy when our services, subprocessors, legal requirements or privacy practices change. We will update the “Last updated” date and provide additional notice where required by law or contract.

 

Questions about privacy, security, or compliance?

We are always happy to help. Contact our team at hello@immerseme.com

 

Was this article helpful?
0 out of 0 found this helpful