Compliance commitment
Langa Library intends to process personal data in accordance with applicable privacy, personal data protection, cybersecurity, consumer protection, child protection, and electronic communications laws in the jurisdictions where the service is made available.
Where applicable, this may include Vietnamese personal data protection law, the European Union General Data Protection Regulation, the United Kingdom data protection framework, California privacy law, children's privacy rules, and other local privacy or consumer protection requirements.
If a local law, platform rule, browser-store requirement, school requirement, payment-provider requirement, or child-protection requirement is stricter than this policy, Langa Library should apply the stricter safeguard where reasonably practicable.
International privacy and data protection compliance
Langa Library may be accessed by readers, contributors, rights holders, customers, supporters, students, and researchers from different jurisdictions. For that reason, Langa Library should not treat privacy compliance as a single-country matter.
Langa Library intends to comply with the personal data protection laws that apply to the relevant user, service, processing activity, server location, payment provider, school arrangement, browser extension platform, or legal request.
Where several legal frameworks may apply at the same time, Langa Library should apply the more protective requirement where reasonably practicable, especially for children, sensitive personal data, cross-border transfer, breach notification, user rights, consent, and account deletion.
- Vietnam: Langa Library should comply with Vietnam's personal data protection framework, including the Law on Personal Data Protection and implementing decrees where applicable.
- European Union and European Economic Area: where the GDPR applies, Langa Library should maintain a lawful basis for processing, provide transparent notice, support data subject rights, protect international transfers, maintain appropriate processor controls, and notify personal data breaches where required.
- United Kingdom: where UK data protection law applies, Langa Library should observe UK GDPR and Data Protection Act requirements, including individual rights, processor controls, security, transfer safeguards, and breach procedures.
- California and other United States privacy laws: where applicable, Langa Library should provide rights to know, access, correct, delete, opt out of sale or sharing, limit certain sensitive personal information uses, and avoid discrimination for exercising privacy rights.
- Children's privacy: where COPPA or similar children's privacy laws apply, Langa Library should not knowingly collect unnecessary personal information from children below the applicable age threshold without the required parental or guardian consent.
- Canada, Australia, Singapore, and similar privacy regimes: where applicable, Langa Library should respect principles of notice, consent or permitted basis, purpose limitation, access, correction, security safeguards, retention limits, and accountable processing.
- International privacy principles: Langa Library should treat collection limitation, purpose specification, use limitation, data quality, security safeguards, openness, individual participation, and accountability as baseline operating principles.
Who controls personal data
For ordinary website, account, reading, search, translation, support, contributor, and customer functions, Langa Library acts as the organization responsible for deciding why and how personal data is processed, except where a third-party service acts under its own independent terms.
Langa Library may use processors or service providers for hosting, authentication, email delivery, analytics, security, translation, payment, customer support, backup, or other operational purposes. Such providers should be selected and configured to protect personal data and to process it only for authorized purposes.
Personal data Langa Library may collect
- Account data, such as email address, display name, account identifier, login provider, role, account status, and authentication metadata.
- OAuth sign-in data received from providers such as Google, Facebook, or another authentication provider, depending on the user's authorization and the provider's settings.
- Contact and support data, such as messages sent to Langa Library, email correspondence, takedown requests, privacy requests, security reports, and contributor communications.
- Reader data, such as reading preferences, interface language, font size, theme, saved shelves, bookmarks, reading progress, notes, or saved workspace state where the user enables or uses those features.
- Search and discovery data, such as search queries, clicked results, filters, language preferences, and metadata interactions where needed to provide or improve the service.
- Translation data, such as selected text, chapter text, source language, target language, translation provider choice, translation preview, correction history, and saved translation drafts where the user requests or saves translation assistance.
- Contributor data, such as submitted metadata corrections, original cover submissions, OCR reports, author identity corrections, contributor credit names, and moderation history.
- Customer, supporter, or payment-related data if paid membership, donation, supporter, certificate, or marketplace features are introduced.
- Technical and security data, such as IP address, device and browser information, session identifiers, cookies, error logs, access logs, rate-limit logs, security events, and audit records.
- Age-related or eligibility signals where needed for minors protection, mature content restriction, school access, family access, or legally required consent.
Data Langa Library should not collect unnecessarily
Langa Library should not collect government identity documents, precise geolocation, payment card numbers, sensitive personal information, children's personal information, or private communications unless a specific feature, legal duty, safety requirement, or payment provider requires it.
If a user signs in with Google, Facebook, or another provider, Langa Library should not receive or store the user's password for that provider. Authentication should be handled through the provider's sign-in system.
If Langa Library later offers direct password-based login, passwords must not be stored in plain text. They should be protected using appropriate password hashing and security controls.
Why personal data is processed
- To create, maintain, secure, and administer user accounts.
- To provide reading, search, library discovery, translation assistance, saved shelves, bookmarks, notes, and workspace features.
- To send account, security, support, service, privacy, takedown, contributor, and administrative communications.
- To process support requests, privacy requests, copyright requests, takedown notices, security reports, contributor submissions, and customer inquiries.
- To operate paid, supporter, donation, certificate, or customer features if such features are introduced.
- To prevent spam, fraud, abuse, scraping, account misuse, unauthorized access, rights violations, and security incidents.
- To comply with legal obligations, enforce policies, maintain audit records, and respond to lawful requests.
- To improve metadata quality, reader experience, search relevance, accessibility, translation workflow, and library governance.
Lawful basis and consent
Langa Library should process personal data only where it has an appropriate legal basis or permitted ground under applicable law. Depending on the feature and jurisdiction, this may include user consent, performance of a service requested by the user, legitimate operation and security of the service, legal obligation, protection of rights, or another lawful basis recognized by applicable law.
Where consent is required, Langa Library should request consent clearly, keep records where required, and allow the user to withdraw consent where the law gives that right.
Where parental or guardian consent is required for a child or young reader, Langa Library should not enable the relevant feature until an appropriate consent process is available and completed.
Email registration and communications
An email address may be used to create an account, verify account ownership, send sign-in or security messages, respond to support requests, deliver service notices, and manage user-requested features.
Administrative and security emails may be necessary to operate the account and service. Marketing, newsletter, supporter, or promotional emails should be sent only where permitted and should provide an unsubscribe or preference mechanism where required.
Langa Library should not sell registered email addresses. Email addresses should not be published publicly unless the user explicitly provides a public contact address for a specific contributor, rights, or institutional purpose.
Google, Facebook, and third-party sign-in
If a user registers or signs in through Google, Facebook, or another provider, Langa Library may receive limited account information such as email address, name, profile image, provider identifier, and authentication status, depending on provider settings and user authorization.
Langa Library uses such information to authenticate the user, link the account, prevent duplicate accounts, protect account security, and provide the requested service.
Third-party sign-in does not remove Langa Library's responsibility to protect the personal data stored in Langa Library systems. Users should also review the privacy policies and account settings of the third-party provider.
Customer, supporter, and payment data
If Langa Library later offers paid memberships, donations, supporter recognition, certificates, marketplace features, or other paid services, personal data connected with those services may include transaction identifiers, billing email, payment status, invoice data, supporter tier, customer support records, and tax or accounting records where required.
Payment card numbers should be handled by a qualified payment provider and should not be stored directly by Langa Library unless Langa Library has implemented the required payment security and compliance controls.
Customer and supporter data should be used only for the transaction, account administration, legal accounting, fraud prevention, customer support, and user-requested recognition features.
Storage, hosting, and backups
Personal data may be stored in Langa Library databases, application storage, server logs, encrypted backups, email systems, support systems, authentication systems, and operational records.
Backups are maintained for continuity, security, recovery, and legal accountability. Deleted data may remain in backups for a limited backup-retention period before being overwritten or removed through normal backup rotation.
Langa Library should maintain an internal data inventory identifying what personal data is stored, where it is stored, who may access it, why it is stored, how long it is retained, and which processors or service providers may process it.
Security safeguards
- Use HTTPS/TLS for transmission of personal data.
- Protect production databases, backups, and server credentials with access control.
- Use role-based access so only authorized personnel can access personal data needed for their work.
- Hash passwords securely if direct password login is introduced.
- Use secure, HttpOnly, SameSite, and Secure cookie settings where applicable.
- Limit admin access and record sensitive administrative actions where practical.
- Keep dependencies, servers, frameworks, and extension packages updated.
- Use secrets management and do not expose private API keys in client-side code or browser extension packages.
- Monitor security events, suspicious access, account abuse, scraping, and abnormal traffic.
- Maintain backup, recovery, and incident response procedures.
Internal compliance records and processor controls
Langa Library should maintain internal records of personal data processing, including categories of personal data, purposes, systems, processors, retention periods, access roles, transfer locations, and security controls.
For higher-risk processing, such as large-scale personal data processing, children's data, sensitive data, behavioral profiling, paid customer data, cross-border transfer, or automated content classification, Langa Library should conduct an internal risk assessment or data protection impact assessment where required.
Service providers that process personal data for Langa Library should be governed by appropriate contractual, technical, and organizational controls.
- Maintain a personal data inventory.
- Maintain a processor and service-provider register.
- Maintain retention and deletion rules.
- Maintain incident and breach response records.
- Maintain records of user rights requests and responses.
- Maintain cross-border transfer review records where applicable.
- Review privacy risks before launching new account, payment, school, family, child, translation, contributor, or analytics features.
Access by staff, contractors, and service providers
Personal data should be accessible only to people or service providers who need it for account administration, support, security, legal compliance, rights review, payment administration, system maintenance, or another authorized purpose.
Where Langa Library uses contractors or service providers, access should be limited to the work being performed and subject to appropriate confidentiality, security, and data processing obligations.
Langa Library should not allow casual internal browsing of reader accounts, private reading activity, private notes, private translation drafts, customer records, or support messages.
International data transfer
Langa Library may use hosting, cloud, authentication, email, payment, translation, analytics, security, or support providers located in different countries.
Where personal data is transferred across borders, Langa Library should use appropriate legal, contractual, organizational, and technical safeguards required by applicable law.
For Vietnamese personal data, Langa Library should evaluate cross-border processing and storage obligations under applicable Vietnamese personal data protection law. For users in the European Economic Area, United Kingdom, or other regulated jurisdictions, Langa Library should evaluate the transfer mechanisms required by the applicable data protection framework.
Regulators, legal requests, and jurisdiction-specific obligations
Langa Library may receive requests from courts, regulators, law enforcement authorities, data protection authorities, payment providers, browser extension stores, schools, parents, guardians, or rights holders.
Langa Library should review legal and regulatory requests carefully before disclosure. Where legally permitted, Langa Library should seek to disclose only the minimum personal data necessary for the specific lawful purpose.
If a request is unclear, excessive, informal, or outside the requesting party's authority, Langa Library may ask for clarification, formal legal process, or additional verification before acting.
- Regulatory requests should be documented with date, authority, scope, legal basis, response, and responsible reviewer.
- Law-enforcement or court requests should be assessed for validity, jurisdiction, scope, and necessity before disclosure.
- Cross-border legal requests should receive additional review because one jurisdiction's request may affect users or data protected in another jurisdiction.
- Requests involving children, sensitive personal data, reading history, private notes, private translations, payment information, or identity data should receive heightened review.
- Where notification to the affected user is legally permitted and appropriate, Langa Library should consider notifying the user before or after disclosure.
Data retention
Langa Library should retain personal data only for as long as needed for the purpose for which it was collected, unless a longer period is required for legal, accounting, security, rights, dispute, audit, backup, or legitimate operational reasons.
Account data may be retained while the account remains active. Support, takedown, copyright, security, privacy, contributor, customer, and payment records may be retained for a longer period where needed for accountability, legal defense, accounting, or rights review.
When personal data is no longer needed, Langa Library should delete, anonymize, aggregate, or otherwise restrict it according to the applicable retention rule.
User rights
Depending on the user's jurisdiction, users may have rights to request access to personal data, correction of inaccurate data, deletion, restriction, objection, portability, withdrawal of consent, opt-out of certain sharing, limitation of sensitive personal information, and information about how personal data is used.
Langa Library should provide a reasonable process for users to exercise applicable rights and may need to verify identity before acting on a request.
Langa Library may refuse or limit a request where the law permits or requires refusal, such as where retention is needed for security, legal compliance, accounting, rights review, dispute resolution, fraud prevention, or protection of other users.
Deletion and account closure
Users may request deletion or closure of their account where applicable. Langa Library should delete or de-identify personal data that is no longer needed, subject to legal, security, backup, accounting, rights, and dispute-retention limits.
Deleting an account may not immediately remove data from encrypted backups, audit logs, legal records, payment records, takedown records, security records, or records that must be retained for legitimate or legal reasons.
Where public contributions have been accepted into Langa Library, Langa Library may need to retain a record of the contribution, rights status, moderation decision, or attribution history, while limiting unnecessary personal identifiers where appropriate.
Personal data breach response
If Langa Library becomes aware of a suspected personal data breach, it should investigate, contain the incident, preserve necessary evidence, assess the scope and risk, take corrective action, and document the response.
Where legally required, Langa Library should notify the appropriate authority, affected users, service providers, or other parties within the time required by applicable law.
Breach response should consider confidentiality, integrity, and availability risks, including unauthorized access, unauthorized disclosure, alteration, loss, destruction, ransomware, credential compromise, or exposure of backups or logs.
Children and young readers
Personal data involving children and young readers requires additional safeguards. Langa Library's Children & Young Readers Protection Policy explains age-aware access, under-13 restrictions, under-18 feature limits, parental or guardian contact, and content classification.
If Langa Library learns that it has collected personal data from a child in a way that requires parental consent or additional legal safeguards, it should review the account, restrict relevant features where appropriate, and respond to parent or guardian requests.
Automated processing and profiling
Langa Library may use automated systems for search ranking, recommendations, spam prevention, security monitoring, metadata quality, content classification, translation assistance, and abuse prevention.
Automated systems should not be used to make significant decisions about a user without appropriate safeguards, human review where required, and an available contact route.
Changes to this policy
Langa Library may update this policy as the service, account system, translation workflow, payment system, legal obligations, or security practices develop.
Material changes should be posted on this page. Where required by law, Langa Library should provide additional notice or obtain renewed consent.
Privacy contact
Privacy questions, data access requests, correction requests, deletion requests, consent withdrawal requests, and concerns involving personal data may be sent to langalibrary.team@gmail.com.
General support may be sent to langalibrary.team@gmail.com. Security reports may be sent to langalibrary.team@gmail.com. Copyright and takedown concerns may be sent to langalibrary.team@gmail.com.