Eiffel — Your English Connection
Effective date: 18 August 2026 · Version 1.0 · Last updated: 18 August 2026
1. Introduction
This Privacy Policy explains what personal information we collect when you use eiffelyourenglishconnection.com or book a lesson with us, why we collect it, what we do with it, and what rights you have over it.
We take this seriously. We are a small practice, we collect very little, and we do not sell information about you to anyone.
This Policy should be read together with our Terms and Conditions and, if you are booking for a child, our Child Protection and Safeguarding Statement.
2. Who is responsible for your information
The responsible party (POPIA) and data controller (GDPR) for your personal information is Pieter H C Reyneke, a sole proprietor trading as Eiffel — Your English Connection, of 29 Carvahlo Street, Meyerton, 1961, Gauteng, Republic of South Africa.
Information Officer: Pieter H C Reyneke
Email: pieterhcreyneke@gmail.com
Telephone: +82 (010) 4445 0421
Registered with the Information Regulator (South Africa), registration number 2026-064646.
3. The laws that apply
We aim to meet the standard of whichever law gives you the strongest protection. Depending on where you live, that will be:
- the Protection of Personal Information Act 4 of 2013 (POPIA) of the Republic of South Africa;
- the General Data Protection Regulation (EU) 2016/679 (GDPR), and the UK GDPR, if you are in the European Economic Area or the United Kingdom;
- the Personal Information Protection Act (PIPA) of the Republic of Korea, if you are in Korea.
4. What we collect
4.1 Information you give us when you book
- Full name — to identify you and address you correctly
- Email address — to confirm bookings, send Zoom links, and communicate with you
- Telephone or messaging handle (KakaoTalk, WhatsApp) — to reach you if a lesson is disrupted, where you have given it
- Time zone — to schedule the lesson at the correct local time
- Course and lesson length selected — to deliver the correct service
- Any information you volunteer about your goals or level — to tailor the lesson to you
4.2 Information about a child, where you book a children’s course
- Child’s first name (or preferred name) — to address the child during the lesson
- Child’s age or school year — to select age-appropriate material and lesson length
- Child’s approximate English level — to pitch the lesson correctly
- Any learning need, allergy, or sensitivity you choose to disclose — to teach the child appropriately and safely
We do not ask for a child’s surname, home address, school name, date of birth, photograph, or any identity or government number. Please do not send us these. If you send them to us unprompted, we will delete them.
4.3 Payment information
Payments are processed by PayPal. We receive confirmation that a payment succeeded, the amount, and the payer’s name and email address. We never receive or store your card number, CVV, or bank account details.
4.4 Information collected automatically on the Website
Our website is hosted on WordPress.com. Standard server logs and analytics may record your IP address, browser type, device type, pages viewed, and the site you arrived from. This information is used to keep the site running and secure, and to understand roughly how the site is used.
4.5 Lesson content
We may keep brief teaching notes — for example, vocabulary covered, progress observations, and what to work on next. These notes are kept to the minimum necessary and are treated as confidential.
We do not record lessons. See clause 8 below.
5. Why we process your information, and on what legal basis
- Delivering the lessons you booked — performance of a contract (GDPR); necessary to perform a contract (POPIA)
- Taking payment and keeping financial records — contract and legal obligation
- Communicating with you about your bookings — performance of a contract
- Keeping teaching notes to improve your lessons — legitimate interests in delivering an effective service
- Keeping the website secure and functioning — legitimate interests
- Processing a child’s information — consent of the parent or guardian (GDPR); consent of a competent person, section 35 POPIA
- Sending you optional updates or newsletters, if you ask for them — consent
- Establishing, exercising, or defending a legal claim — legitimate interests
We do not send marketing email unless you have specifically asked to receive it. If you do, you can unsubscribe at any time, and every message will carry a way to do so.
6. Children’s information
We treat information about children with particular care.
- We only process a child’s personal information with the express consent of a parent or legal guardian, which is given when the parent books the lesson.
- We collect the minimum described in clause 4.2 and nothing more.
- We do not use children’s information for marketing, profiling, or automated decision-making of any kind.
- We do not communicate directly and privately with a child. All scheduling, progress, and account communication goes to the parent.
- A parent may at any time ask to see what we hold about their child, ask us to correct it, or ask us to delete it. We will comply promptly, subject only to any record we are legally required to keep.
- A child’s information is deleted within 12 months of the last lesson, unless the parent asks us to keep it for continuity of teaching.
7. Who we share your information with
We share your information only with the service providers we need to run the practice, and only to the extent necessary:
- WordPress.com / Automattic — website hosting and contact form (United States, EU)
- FluentBooking — booking and scheduling (hosted on our own site)
- Zoom — delivering lessons (United States and global)
- PayPal — payment processing (United States, EU, global)
- Google (Gmail) — email correspondence (United States and global)
Each of these providers has its own privacy policy governing what it does with information it holds.
We do not sell, rent, or trade your personal information to anyone, for any purpose, ever.
We may disclose your information where we are legally required to do so, where it is necessary to protect a person from harm (see our Child Protection and Safeguarding Statement), or where it is necessary to establish or defend a legal claim.
8. Recordings
- We do not record lessons.
- We do not record lessons with children under any circumstances unless a parent specifically requests it in writing in advance, in which case the recording is provided to the parent for private use and is deleted from our own systems once delivered.
- You may not record a lesson without our prior written consent.
9. International transfers of information
We are established in the Republic of South Africa and teach primarily from the Republic of Korea. Our service providers operate principally from the United States and the European Union.
This means your personal information will cross borders. Where we transfer information out of the EEA or the UK, we rely on the transfer mechanisms our providers have in place, which are typically the European Commission’s Standard Contractual Clauses, an adequacy decision, or an equivalent safeguard. The Republic of Korea holds an EU adequacy decision.
Where POPIA applies, transfers are made on the bases permitted by section 72 — principally your consent, the necessity of the transfer to perform our contract with you, and the binding obligations our providers are subject to.
10. How long we keep information
- Booking and contact details — 3 years after your last lesson
- Teaching notes — 12 months after your last lesson
- A child’s information — 12 months after the last lesson
- Payment and invoice records — as required by applicable tax law, typically 5 years
- Email correspondence — 3 years
- Website server logs — as retained by our hosting provider
We delete or anonymise information once it is no longer needed for the purpose it was collected for, unless we are legally required to keep it.
11. How we protect your information
We take reasonable and appropriate technical and organisational measures to protect your information, including:
- password protection and two-factor authentication on the accounts that hold your information;
- encrypted connections (HTTPS) on our website;
- limiting access to your information to the people who need it — in practice, only Pieter;
- keeping the amount of information we hold to a minimum, which is the most effective protection of all.
No system is perfectly secure. If a breach occurs that is likely to compromise your personal information, we will notify you and the relevant regulator as required by POPIA (section 22) and the GDPR (articles 33–34).
12. Your rights
Whatever law applies to you, you have the right to:
- be told what personal information we hold about you;
- access a copy of it;
- have it corrected if it is inaccurate or incomplete;
- have it deleted, where we no longer need it or where you withdraw consent;
- object to our processing it, including for direct marketing;
- restrict our processing of it in certain circumstances;
- withdraw consent at any time, where consent is the basis we rely on;
- complain to a regulator.
If the GDPR applies to you, you additionally have the right to data portability — to receive your information in a structured, commonly used, machine-readable format.
To exercise any of these rights, email pieterhcreyneke@gmail.com. We will respond within 30 days. We do not charge for this. We may need to confirm your identity before acting on a request, to make sure we are not disclosing your information to somebody else.
You will never be treated less favourably for exercising a right under this Policy.
13. Complaints
If you are unhappy with how we have handled your personal information, please tell us first — we would rather fix it directly. If you are not satisfied with our response, you may complain to:
- South Africa — Information Regulator: complaints.IR@justice.gov.za · inforegulator.org.za
- European Union — the data protection supervisory authority of the country where you live
- United Kingdom — Information Commissioner’s Office: ico.org.uk
- Republic of Korea — Personal Information Protection Commission: pipc.go.kr
14. Cookies
Our website uses cookies that are necessary for it to function, and may use analytics cookies to understand how the site is used. You can control or delete cookies through your browser settings. Blocking necessary cookies may stop parts of the site from working.
15. Changes to this Policy
We may update this Policy from time to time. The current version is always published on our website, with the date it took effect. If we make a material change, we will tell you by email or by a notice on the site.
16. Contact us
Pieter H C Reyneke
t/a Eiffel — Your English Connection
Information Officer: Pieter H C Reyneke
29 Carvahlo Street, Meyerton, 1961, Gauteng, Republic of South Africa
Email: pieterhcreyneke@gmail.com
Telephone: +82 (010) 4445 0421
Website: eiffelyourenglishconnection.com