LearnCube Training
About Us Babbel App Private Classes Group Courses
Book a Call

Privacy Policy

LearnCube Training GmbH

Effective July 2026

1. Who we are

LearnCube Training GmbH (“we”, “us”, “our”) is a corporate language training provider registered in Germany, at c/o COLLECTION Business Center Berlin, Kienberger Allee 4, 12529 Schönefeld, Germany. We deliver live online classes through the LearnCube Virtual Classroom — software developed and operated by eSplice Ltd, trading as LearnCube, and made available to us under licence — and act as an authorised reseller of the Babbel App for self-paced learning.

This Privacy Policy explains how we collect, use, share and protect personal data in connection with our website, the Virtual Classroom, and the Services we provide under an Order Form, and sets out your rights under the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the German Federal Data Protection Act (BDSG).

2. Who this policy applies to, and our role as controller or processor

This Policy applies to: (a) visitors to our website; (b) corporate Clients who sign an Order Form with us; and (c) Learners (employees or other individuals nominated by a Client) who are given access to the Services.

Where you are a Learner accessing the Services through your employer’s or organisation’s account, that organisation (the Client) is the data controller of your personal data, and we act as a data processor on the Client’s documented instructions, as set out in our Data Processing Agreement (DPA) with the Client. Questions about how your data is used should, in the first instance, be directed to your organisation.

We act as data controller in our own right for: website visitor and analytics data; data of individuals who contact us directly (for example, sales enquiries); billing and account-administration contacts; and security, audit and diagnostic logs.

3. The Babbel App

If your Services include access to the Babbel App, Babbel GmbH is an independent data controller of any personal data processed within the Babbel App itself, under Babbel’s own privacy policy, available at www.babbel.com/legal/privacy. We accept no responsibility for, and do not control, processing carried out within the Babbel App. Where a Learner redeems a Babbel voucher, Babbel GmbH may transmit a unique identifier and limited usage data to us for the purposes of programme reporting to the Client, on the Client’s documented instructions.

4. What personal data we collect

We process the following categories of personal data in connection with the Services:

  • Profile information — first name, last name and profile image, used to personalise the Services.
  • Contact information — email address, used to communicate with Learners and Teachers.
  • Location and time zone information — IP address, browser type, time zone, home country and location, used to optimise data routing, diagnose technical issues, and support class scheduling.
  • Class information — upcoming and past classes, chat, notes, teacher ratings and student feedback, used to report on attendance and teacher performance, schedule classes, validate service delivery, and improve the user experience.
  • Audio and video data — processed during live classes; see clause 6 below.
  • Aggregate reporting data — statistical and summary information about a Learner’s platform usage (session frequency, time spent, modules accessed, progress indicators), provided to the Client for programme management and workforce planning.
  • Website and cookie data — collected when you visit our website, as described in clause 12 below.

5. How and why we use your data

We use personal data for the following purposes, on the legal bases indicated:

  • To deliver the Services, including scheduling and running live classes (performance of a contract — Art. 6(1)(b) GDPR);
  • To provide programme reporting to Clients (legitimate interests of the Client and us — Art. 6(1)(f) GDPR, as documented in our DPA);
  • To maintain the security, integrity and proper functioning of our platform (legitimate interests — Art. 6(1)(f) GDPR);
  • To comply with legal and regulatory obligations, including tax and accounting requirements (legal obligation — Art. 6(1)(c) GDPR);
  • To communicate with you about your account, your classes, or in response to an enquiry (performance of a contract or legitimate interests);
  • For marketing communications, only with your consent or another valid legal basis, and always with the ability to opt out (consent — Art. 6(1)(a) GDPR, or legitimate interests where permitted).

6. Audio and video data

Audio and video data generated during live classes is processed and technically handled solely by our sub-processors, LiveKit/Twilio; we do not ourselves access or store this data. It is transmitted during live classes to facilitate live online teaching, and is not automatically recorded or transcribed. All such data is encrypted in transit (TLS/SSL), and data at rest is protected through AWS infrastructure-level security controls. If you use our optional Video Recording feature, the recording and its distribution is governed by clause 2.7 of our Terms of Service, and you are responsible for obtaining the necessary consents from anyone recorded.

7. Who we share your data with

We share personal data with:

  • Sub-processors who support the delivery of the Services, including hosting and infrastructure providers, video-conferencing infrastructure, customer support tools, teaching administration providers, and analytics providers. A current list of our sub-processors is available in our Data Processing Agreement.
  • Babbel GmbH, solely in connection with voucher redemption and programme reporting, as described in clause 3 above.
  • The Client, where you are a Learner, for programme reporting purposes as described in clause 4 above.
  • Professional advisers, regulators, or law enforcement, where required by law or to protect our legal rights.

We require every sub-processor to be bound by a written agreement imposing data protection obligations equivalent to those in our DPA, and we remain responsible for their performance.

8. International data transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure an appropriate safeguard is in place. Transfers to the United Kingdom currently rely on the European Commission’s UK adequacy decision. Transfers to sub-processors in the United States that are certified under the EU-US Data Privacy Framework rely on the European Commission’s adequacy decision of 10 July 2023. Where no adequacy decision applies, we put Standard Contractual Clauses adopted under Decision (EU) 2021/914 in place before any transfer occurs.

9. How long we keep your data

We retain personal data for as long as needed to deliver the Services. Where an Order Form ends and the Client has not requested earlier deletion, we retain personal data for 12 months following termination, to settle billing disputes, validate service delivery, and respond to complaints or regulatory enquiries, after which we pseudonymise any remaining personal data. The Client may request earlier deletion at any time, and we will action such a request within 30 days. We do not delete system logs, security logs, diagnostic information, or anonymised analytics retained for security, compliance or operational purposes; such data is retained and deleted in accordance with our standard retention schedules. Anonymised data may be retained and used for reporting, analytics or other legitimate business purposes, since it no longer constitutes personal data.

10. Security

We implement appropriate technical and organisational measures to protect personal data, in accordance with Article 32 GDPR, including:

  • Encryption — industry-standard TLS encryption in transit, encryption at rest, and password hashing using PBKDF2 with SHA-256.
  • Access control — access restricted to authorised staff on a role-based, need-to-know basis, protected by multi-factor authentication.
  • Application security — secure development practices aligned with OWASP guidelines, with periodic independent penetration testing.
  • Network security — network segmentation and Cloudflare security services, including WAF protection and DDoS mitigation.
  • Logging and monitoring — security and audit logs to detect malicious activity and monitor access.
  • Backups — encrypted daily backups stored in multiple secure locations, with business continuity procedures.
  • Incident response — in the event of a personal data breach, we will notify the affected Client without undue delay, and in any event within 48 hours of becoming aware of the breach.

Further detail on our security practices is available in our Data Processing Agreement and at our data protection and security page.

11. Your rights

Subject to applicable law, you have the right to:

  • request access to the personal data we hold about you;
  • request that we correct any inaccurate or incomplete data;
  • request erasure of your personal data;
  • request that we restrict our processing of your data;
  • object to our processing of your data, including for direct marketing;
  • receive your personal data in a portable, machine-readable format;
  • withdraw your consent at any time, where processing is based on consent; and
  • lodge a complaint with a data protection supervisory authority.

If you are a Learner whose personal data we process on behalf of a Client, please direct your request to that Client in the first instance; we will assist the Client in responding to it. Otherwise, you can exercise these rights by contacting us using the details in clause 17 below.

The supervisory authority responsible for our registered office is the Brandenburg State Commissioner for Data Protection and Freedom of Information (Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg); you may also lodge a complaint with the supervisory authority in your own EU member state of residence or place of work.

12. Cookies and website analytics

Our website uses cookies to improve your experience while visiting it. Cookies are small files saved to your device that track and store information about your interactions with our website. Where applicable, our website uses a cookie consent tool that allows you, on your first visit, to allow or disallow the use of non-essential cookies, in compliance with applicable e-privacy and data protection law.

If you wish to deny the use and saving of cookies on your device, you can do so through your browser’s security settings, or by adjusting your preferences in our cookie consent tool.

We use Google Analytics to better understand how visitors use our website; this uses cookies but does not collect personal information that identifies you. You can read Google’s privacy policy here for further information.

13. Email communications

We may use your contact details to respond to enquiries you submit to us, or to send you information about our Services, but only where you have given your consent or we otherwise have a valid legal basis to do so. Marketing emails include an unsubscribe option in the footer of every message, and you may withdraw your consent at any time. We do not pass your details on to third parties for their own marketing purposes.

14. External links and social media

We cannot guarantee or verify the contents of any externally linked website. You access external links at your own risk, and we cannot be held liable for any damages or implications arising from visiting them.

Communication and engagement through external social media platforms that we participate on are subject to the terms and conditions and privacy policies of each platform. We will never ask for personal or sensitive information through social media, and encourage you to contact us through the channels in clause 17 below for anything sensitive.

15. Children’s privacy

We do not knowingly collect personal information from children under the age of thirteen. If you are under 18, you may only access the Services with the permission of a parent or guardian, who may also act as a user on your behalf, consistent with clause 1.1 of our Terms of Service.

16. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify Clients by email or by posting a notice on our website. Continued use of the Services after such changes constitutes acceptance of the updated policy.

17. Contact us

If you have any questions about this Privacy Policy or how we handle personal data, please contact us:

Email: info@learncubetraining.com
Address: c/o COLLECTION Business Center Berlin, Kienberger Allee 4, 12529 Schönefeld, Germany

LearnCube Training
Contact Us LinkedIn Privacy Policy Terms & Conditions Switching from Babbel?
© 2026 LearnCube Training Babbel Trusted Partner · Founded 2014