🎵The Global ConservatorySign in →

Legal

Terms of ServicePrivacy PolicyIndependent Contractor AgreementRefund PolicyAcceptable Use PolicyCookie Policy

Questions? info@theglobalconservatory.com

Legal documents
Terms of ServicePrivacy PolicyIndependent Contractor AgreementRefund PolicyAcceptable Use PolicyCookie Policy

Questions? info@theglobalconservatory.com

v3.0Effective May 2, 2026Questions? info@theglobalconservatory.com

Privacy Policy

How Kalinklo Limited (trading as The Global Conservatory, "TGC", "we", "us") collects, uses, stores, and shares information when you use our website, portal, or related services. We're a Hong Kong company subject to Hong Kong's Personal Data (Privacy) Ordinance ("PDPO"); we also comply with GDPR (EU/UK), CCPA (California), and applicable child-protection laws.

Plain English summary

What we do with your data

  • We collect the information needed to deliver lessons (name, email, bookings, lesson notes), process payments (via Shopify), and pay faculty (via Airwallex or PayPal).
  • We do not sell your data. We do not share with advertisers. We do not run cross-context behavioural ad pixels.
  • We use sub-processors for hosting (Vercel), email (Resend), payments (Shopify), payouts (Airwallex / PayPal), storefront (Shopify), and lesson video (Zoom).
  • Children under 13 use the Platform via a parent-managed account only. The parent is the contracting party.
  • You have rights to access, correct, delete, port, or restrict your personal data — exercise them by emailing info@theglobalconservatory.com.
  • We retain account data while your account is active plus 90 days. Order data: 7 years (tax/audit). Lesson notes: while the account exists.
  • We notify you of breaches without undue delay if your data is affected.
Table of contents
  1. 1. Information we collect
  2. 2. How we use your information
  3. 3. Who we share information with (sub-processors)
  4. 4. International data transfers
  5. 5. Data retention
  6. 6. Your rights (GDPR, CCPA, PDPO)
  7. 7. Children under 13 — parent-managed accounts
  8. 8. Marketing communications
  9. 9. Cookies and tracking
  10. 10. Security
  11. 11. Data breach notification
  12. 12. Changes to this Policy
  13. 13. Contact
1

Information we collect

In plain English

Account info, lesson info, payment info — only what we need to operate the platform.

From all users

  • Email address (used as your sign-in identity)
  • IP address and basic device data, for security and abuse prevention
  • Cookies and similar technologies — see our Cookie Policy
  • Communications you send us (support emails, contact form submissions)

From Faculty applicants and Faculty

  • Name, phone, country, time zone
  • Primary subject (instrument, voice, dance, drama, etc.), other subjects you teach, styles, languages
  • Bio, headshot, portfolio link, sample video URL, social-media URLs
  • Teaching style, levels you teach, age ranges, qualifications, years of experience
  • Zoom Personal Meeting Room URL (used to deliver lessons)
  • Banking and tax info via your chosen payout provider (Airwallex or PayPal account ID; we do not store full bank details — those live with the payout provider)
  • Independent Contractor Agreement consent timestamp
  • Application disclosures (background checks consent, prior disciplinary history if disclosed)

From Students (and parents booking for students)

  • Name and email (collected by Shopify at checkout)
  • Order history (lessons, masterclasses, studio classes purchased)
  • Lesson date and time preferences (when you book)
  • Messages you exchange with faculty through the in-portal messaging system

From bookings and lessons

  • Lesson notes, homework, and next-focus content created by Faculty
  • Recording links (when both parties consent)
  • Cancellation, no-show, and reschedule events
  • Faculty earnings ledger
2

How we use your information

In plain English

Run the platform. Process bookings and payments. Email reminders. Pay faculty. Detect abuse.

  • To deliver the Platform and process bookings, lessons, and masterclasses
  • To match Students with Faculty
  • To send transactional emails (sign-in codes, booking confirmations, lesson reminders, post-purchase guidance)
  • To process payments (via Shopify) and Faculty payouts (via Airwallex or PayPal)
  • To improve the Platform — performance monitoring, error logging, aggregate usage analytics
  • To detect and prevent abuse, fraud, and security threats
  • To enforce our Terms, Acceptable Use Policy, and IC Agreement
  • To comply with legal obligations (tax reporting, audit, sanctions screening, lawful requests from authorities)
  • To respond to support requests and resolve disputes

Legal bases (for users in the EU/UK under GDPR): contract (to deliver the Platform); legitimate interest (to operate, improve, and secure); consent (for any optional marketing emails, which we do not currently send); legal obligation (for tax/audit/regulatory compliance).

3

Who we share information with (sub-processors)

In plain English

The vendors we use to actually run the platform. We never sell data.

  • Shopify Inc. (Canada) — payment processing, order management, customer accounts. The storefront at theglobalconservatory.com runs on Shopify.
  • Vercel Inc. (United States) — hosting of portal.theglobalconservatory.com (this site).
  • Airwallex Hong Kong Limited (Hong Kong) — recommended payout rail for faculty. Faculty have a direct relationship with Airwallex; we share payout instructions only.
  • PayPal Pte. Ltd. (Singapore) — alternative payout rail for faculty. Same model as Airwallex.
  • Resend Inc. (United States) — transactional email delivery (sign-in codes, booking confirmations, reminders).
  • Zoom Communications — video platform for lessons. Zoom processes audio/video; we do not access lesson recordings unless both parties explicitly grant access.
  • Appointo (Shopify app) — calendar / booking widget.
  • Faculty ↔ Student visibility — Faculty can see basic info (name, email, instrument, lesson notes) about Students who book with them. Students can see Faculty bios and the Faculty's contact information after a booking.
  • Legal compliance — when required by valid legal process or to protect rights, safety, and property.

We never sell personal information. We do not share for cross-context behavioural advertising. We do not run third-party advertising pixels (no Google Ads, no Meta Pixel, no TikTok Pixel) on the portal.

4

International data transfers

In plain English

Our infrastructure spans HK, US, EU, Singapore, etc. We use industry-standard safeguards.

TGC is operated from Hong Kong. Our infrastructure providers may host or process data in the United States, the European Union, Hong Kong, Singapore, and other regions. By using the Platform you consent to such transfers.

For transfers from the EU/UK we rely on the European Commission's Standard Contractual Clauses (or the UK equivalent) and on our sub-processors' own GDPR-compliant safeguards. We perform vendor due-diligence on every sub-processor we engage.

5

Data retention

In plain English

Account data: while your account is active + 90 days. Orders: 7 years (tax). Lesson notes: while account exists.

  • Account data: kept while your account is active, plus 90 days after deletion to handle late refunds, chargebacks, and audit trails.
  • Order data: kept for 7 years to satisfy tax and audit obligations.
  • Lesson notes: kept while either the Faculty or the Student has an active account.
  • Email logs (delivery status): kept for 90 days for deliverability diagnostics.
  • Application materials (for Faculty applicants who weren't accepted): kept for 12 months in case you reapply, then deleted.
  • Server access logs: kept for 30 days for security investigations.
6

Your rights (GDPR, CCPA, HK PDPO)

In plain English

You can ask us for a copy of your data, fix it, delete it, or restrict our use of it. Email us.

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten" under GDPR)
  • Restrict or object to certain processing
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent (where processing is consent-based)
  • Lodge a complaint with your local data-protection authority (e.g. UK ICO, Irish DPC, Hong Kong PCPD, California Attorney General)

To exercise any of these rights, email info@theglobalconservatory.com. We respond within 30 days (or sooner where required by your local law).

Hong Kong PDPO (our home jurisdiction): Hong Kong residents can exercise data-access and correction requests under the Personal Data (Privacy) Ordinance through the same email channel.

For California residents (CCPA/CPRA): you may make CCPA requests via the same email. We do not sell or "share" (as defined by CCPA) personal information.

7

Children under 13 — parent-managed accounts

In plain English

If the student is under 13, the parent holds the account. The parent provides verifiable consent and is responsible for all activity.

We market lessons for children of all ages including under-13s (e.g. our Young Musicians (3–14) program and Suzuki tracks for ages 3+). We treat under-13 protection seriously and have built our system around it.

How it works:

  • For any student under 13, the parent or legal guardian is the account holder. The parent registers, signs in, accepts these terms, makes the bookings, communicates with the faculty, and receives all email correspondence.
  • The parent provides verifiable consent by completing checkout (a financial transaction at a verified address with a verified payment instrument).
  • The under-13 student does not have their own account, sign-in credentials, or independent ability to make bookings.
  • The faculty member sees only what the parent has shared (the child's first name, age, level, any practice notes the parent provides).
  • Recordings of lessons involving under-13 students require explicit parent consent for each session.
  • We do not knowingly collect any personal information directly from a child under 13. If you believe we have inadvertently done so, contact us at info@theglobalconservatory.com and we will delete it promptly.

This model complies with the US Children's Online Privacy Protection Act ("COPPA"), the EU GDPR's child-protection provisions (Article 8), and the UK Age-Appropriate Design Code.

8

Marketing communications

In plain English

We don't send marketing emails. If we ever do, you'll opt in.

We currently send only transactional emails (sign-in codes, booking confirmations, lesson reminders, application status updates) — not marketing emails. If we begin sending marketing communications in the future, we will:

  • Make them optional (opt-in for new users; opt-out for existing users with at least 30 days' notice)
  • Include an unsubscribe link in every message
  • Respect opt-out preferences within 7 days
9

Cookies and tracking

In plain English

Just the session cookie that keeps you signed in. The storefront has Shopify's cookies. No ad pixels.

See our Cookie Policy for the full list. Summary:

  • Portal (portal.theglobalconservatory.com): a single session cookie (tgc_portal_session) for sign-in. Strictly necessary; no consent required.
  • Storefront (theglobalconservatory.com): Shopify sets its own cookies for cart, checkout, and Shopify-native analytics (anonymised). See Shopify's Cookie Policy.
  • No third-party advertising tracking on either domain. No Google Ads pixel, no Meta Pixel, no TikTok pixel, no LinkedIn Insight tag.
10

Security

In plain English

HTTPS everywhere. Encrypted at rest. Scoped tokens. Webhook HMAC signing. Rate limits. Least-privilege access.

Industry-standard security in place across the Platform:

  • TLS 1.2+ everywhere (HTTPS only); HSTS enforced
  • Encrypted data at rest in our hosting providers
  • Scoped access tokens for all third-party APIs (Shopify, Resend, Zoom)
  • HMAC webhook signature verification (rotating secrets)
  • Per-IP and per-account rate limits to prevent enumeration and credential stuffing
  • Least-privilege admin access (role-based access control inside the portal)
  • Idempotency keys on payment webhooks to prevent duplicate charges
  • Magic-link OTP authentication (no passwords stored)
  • Session cookies are HttpOnly, Secure, SameSite=Lax, and rotate on sign-in

No system is perfectly secure. If we discover a breach affecting you, we will notify you per Section 11.

11

Data breach notification

In plain English

If your data is exposed in a breach, we'll tell you ASAP and tell you what to do.

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware (GDPR-aligned standard)
  • Notify affected users without undue delay, by email to your account address
  • Describe the nature of the breach, what data was affected, what we are doing about it, and what you should do
12

Changes to this Policy

In plain English

We can update this Policy. Material changes get 30 days' notice.

We may update this Privacy Policy from time to time. The "Effective" date at the top reflects the most recent version. We will give at least 30 days' advance notice of material changes by email and/or by prominent notice on the Platform. Continued use after the effective date constitutes acceptance.

13

Contact

In plain English

Any privacy question or rights request: info@theglobalconservatory.com.

Kalinklo Limited
Hong Kong SAR
info@theglobalconservatory.com

Questions or notices

For any question about this document, write to us at info@theglobalconservatory.com. This is the only official email channel for The Global Conservatory; messages sent to any other address are not legally binding notice.

📧 Email usAll legal docsTermsPrivacyRefundsIC AgreementAcceptable UseCode of Conduct

Version 3.0 · Effective May 2, 2026 · Kalinklo Limited (Hong Kong) · info@theglobalconservatory.com

© 2026 The Global Conservatory · Kalinklo Limited (Hong Kong)