← BACK TO HOME

Privacy Policy

Effective date: 28 May 2026  · Last updated: 30 May 2026

This Privacy Policy explains what personal data UP2U collects from you, why we collect it, who we share it with, how we protect it, and what rights you have over it. It applies to up2uagency.info and to every UP2U sales, training, and placement service delivered from that website, our Instagram accounts (@up2u.go, @up2u.company), WhatsApp, email, our CRM, and our payment pages.

If anything in this policy is unclear, write to us at privacy@up2uagency.info before you submit personal data to us.

1. Who we are (the data controller)

The data controller of your personal data is:

  • Legal name: TABACU TUDOR-LUCREȚIU P.F.A. (a Romanian sole-trader entity — Persoană Fizică Autorizată, governed by Romanian Government Emergency Ordinance 44/2008)
  • Registered address: 136 Bucureștii Noi Blvd., apt. 5, Sector 1, Bucharest 012366, Romania, European Union
  • Unique registration code (CUI): 52423615
  • Trading name: UP2U ("UP2U", "we", "us", "our")
  • Privacy contact: privacy@up2uagency.info

If you are in the European Economic Area, the United Kingdom, or Switzerland, this Policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, and equivalent data protection laws.

2. The data we collect

We collect personal data in three ways: (a) you give it to us directly, (b) we receive it automatically when you visit our website or interact with our ads, and (c) we receive it from third parties such as payment processors and social platforms.

2.1 Data you give us directly

Depending on which of our services you engage with — the free content, Tier 1 ("Not Native Still Hired" DIY course, $199), Tier 2 (Review, $349), Tier 3 (Full Mentorship, $750, including the China Program variant), or our TEFL add-on — we collect different categories of data. The table below tracks what we ask for, at what point, and why.

CategoryExamplesWhen collected
Identification dataFull name, country of residence, nationality, age range, gender (when relevant for visa/legal eligibility), photograph or video appearanceAt enquiry, application, qualification video, course signup, and at payment
Contact dataEmail address, phone number, Instagram handle, WhatsApp number, Telegram handleAt first contact and throughout the sales conversation
Professional and educational dataCV/resume, employment history, academic qualifications (including degree status — relevant to Vietnamese work-permit eligibility), English proficiency level, TEFL/TESOL certifications, prior teaching experienceTier 2 and Tier 3 onboarding
Audio-visual dataQualification video (typically 3-minute self-recording), pronunciation samples you submit, intro-video drafts and revisionsTier 2 (one-shot video feedback), Tier 3 (iterative coaching)
Immigration and legal documentsPassport scan/details, visa documents, criminal-record (police) check, health-check results, legalised diploma, signed school contractTier 3 only, during the 12-step placement procedure
Financial dataPayment method type, billing name, billing country, the last four digits of the card or wallet reference, payment timestamps. We do NOT receive or store full card numbers or CVV — those are handled by Stripe and other processors directly.At checkout and at the second installment of Tier 3
Sales-conversation dataEvery message you send us on Instagram DM, WhatsApp, Telegram, email, or the Kommo chat widget, plus internal sales notes and lead tags we create about that conversationThroughout the funnel and after purchase
Marketing-preference dataWhether you have opted in to ad-targeting, newsletters, retargetingWhere applicable
Post-arrival support dataMessages and updates inside the dedicated Tier 3 WhatsApp Working Group during the 6 months after you land in VietnamTier 3 post-arrival period

Some of the above categories — passport scans, photos, video recordings of your face, and (in some places) criminal-record checks — are "special category" or otherwise sensitive personal data. You provide them voluntarily and only because they are necessary to apply for a Vietnamese teaching position and the associated work permit. You can refuse, but we cannot deliver Tier 3 without them.

2.2 Data collected automatically

When you visit up2uagency.info or engage with our ads, we (or our service providers) automatically collect:

  • Device and connection data: IP address, browser type and version, operating system, device identifiers, screen size, time zone, referring URL, the pages you visit on our site, and the timestamps of those visits.
  • Cookie and similar-technology data: see Section 8 ("Cookies and tracking").
  • Ad-engagement data: which ad you clicked, the placement, the creative variant, and any conversion event you triggered. This is provided to us by Meta (Instagram/Facebook). We do not currently run paid campaigns on Google Ads, TikTok Ads, or any other ad network.

2.3 Data we receive from third parties

  • From Stripe when you pay: name, billing address, payment-method type, transaction status, and risk signals.
  • From Meta (Instagram/Facebook): your public profile, your interactions with our ads and posts, and aggregated audience statistics (we cannot see your private profile contents).
  • From your referrer, if a current or former UP2U client introduced you: your name, contact, and the context in which they referred you.
  • From email-provider deliverability tools: bounce/spam/engagement signals on emails we send you.

3. Why we process your data and on what legal basis

Under GDPR we are required to declare a lawful basis for every processing activity. The table below pairs each purpose with its basis.

PurposeLegal basis (GDPR Art. 6)
Reply to your enquiry, send you a sales conversation, qualify you for a tierPre-contractual steps at your request (Art. 6(1)(b))
Deliver Tier 1, Tier 2, Tier 3, the TEFL add-on, and any post-arrival support you boughtPerformance of a contract (Art. 6(1)(b))
Process your payment and prevent fraudPerformance of a contract and our legitimate interest in fraud prevention (Art. 6(1)(b) and (f))
Comply with tax, accounting, anti-money-laundering, and other legal dutiesLegal obligation (Art. 6(1)(c))
Run our website, secure it, debug it, and keep audit logsOur legitimate interest in operating the site (Art. 6(1)(f))
Send marketing emails or messages about UP2U services to existing customers about similar servicesOur legitimate interest (Art. 6(1)(f)) — you can opt out at any time
Run paid advertising and lookalike-audience modelling on Meta, set marketing cookiesYour consent (Art. 6(1)(a))
Use sales-conversation data to improve our sales playbooks and to train internal AI sales-assistance promptsOur legitimate interest in improving our service (Art. 6(1)(f)). The training data is held internally and is not sold or used to train any third-party model.
Process special-category data (passport, photo of face on a passport, criminal-record check, health check) for the visa/work-permit step of Tier 3Your explicit consent (Art. 9(2)(a)). You may withdraw consent at any time, but Tier 3 cannot complete without those documents — withdrawal will end the contract.

4. Who we share your data with

We do not sell your personal data. We share it only with the categories of recipient listed below, and only to the extent necessary for the purpose.

4.1 Internal access

UP2U is a Romanian sole-trader business (Persoană Fizică Autorizată). Access to your personal data inside UP2U is limited to the controller identified in Section 1. Any further processing carried out on UP2U's behalf is performed by the external service providers listed in Section 4.2, each of which is bound by its own contractual and statutory data-protection obligations.

4.2 Service providers ("data processors")

Each of these acts on our instructions under a contract (a Data Processing Agreement) that obliges them to protect your data:

  • Stripe, Inc. — payment processing. Stripe is a PCI-DSS Level 1 service provider. stripe.com/privacy
  • Kommo (amoCRM / Kommo LLC) — our customer relationship management (CRM) system. All sales conversations and lead notes are stored there. kommo.com/privacy
  • Meta Platforms, Inc. — Instagram and Facebook DM, Instagram Direct, Meta business tools, the Meta Pixel on our website, and Meta ads delivery. facebook.com/privacy/policy
  • WhatsApp / Meta — primary messaging channel for customer conversations and the Tier 3 post-arrival Working Group. whatsapp.com/legal/privacy-policy
  • Wise, Revolut, and (where you choose them) cryptocurrency exchanges such as Binance — alternative payment routes for Tier 3 and for buyers without international cards. Each operates under its own privacy policy.
  • Email provider: Google LLC — our privacy-contact inbox privacy@up2uagency.info is hosted on Gmail, and email sent to addresses on @up2uagency.info is routed through Google Workspace (MX records point to Google's mail servers). policies.google.com/privacy
  • Website hosting and content delivery: Vercel Inc. (San Francisco, USA) — hosts up2uagency.info and serves it from a global edge network. Vercel processes connection metadata (IP address, request headers, response status) for operational and security purposes under its own privacy policy and Data Processing Addendum. vercel.com/legal/privacy-policy · vercel.com/legal/dpa
  • AI tooling for internal sales assistance: Anthropic, PBC (Claude) and Google LLC (NotebookLM) — used by UP2U to draft replies, summarise lead history, and run sales analytics on conversations we already have. Conversations are not sold and are not used by these providers to train their public models when processed via our paid API integrations.
  • Visa, work-permit, and legalisation agents in Vietnam (Tier 3 only): we share the minimum identity, education, and immigration documents required to apply for your work permit and residency.
  • Vietnamese school partners (Tier 3 only): we forward your CV, video intro, and contact details to schools we believe are a fit. We disclose only what is needed to obtain an interview and a contract offer.

Note on TEFL providers. Vietnamese law requires every teacher to hold a legalised 120-hour TEFL/TESOL certificate to obtain a work permit. We do not resell, host, or operate any TEFL course. Where useful, we recommend third-party 120-hour accredited TEFL/TESOL providers. If you choose to enrol with one of them, you transact with that provider directly under their privacy policy and terms; UP2U does not share your personal data with the TEFL provider on your behalf and the provider is not our data processor.

4.3 Other recipients

  • Tax, accounting, and legal advisors under professional duties of confidentiality.
  • Public authorities when we are legally required to disclose data — for example in response to a tax investigation, a court order, or a law-enforcement request that meets the legal standard in our jurisdiction.
  • Buyers in a sale of the business, if we ever sell UP2U or merge with another entity. You will be notified before such a transfer takes effect.

We do not rent, sell, or trade your personal data to advertisers or list brokers.

5. International transfers

UP2U is operated from Romania (European Union), delivers a service whose end destination is Vietnam, and uses service providers based in the United States (Stripe, Meta, Anthropic, Google, Vercel), in various EU countries, and in Vietnam. Your personal data will therefore be transferred outside your country of residence.

Where data is transferred outside the EEA/UK to a country that the European Commission has not declared to provide an adequate level of protection, we rely on the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or — for Vietnam-based recipients such as schools and visa agents — your explicit, informed consent to the transfer as necessary to perform our contract with you (GDPR Art. 49(1)(a) and (b)).

You can ask us for a copy of the safeguards in place at privacy@up2uagency.info.

6. How long we keep your data

Data categoryRetention period
Enquiry / lead data where no purchase occurred24 months from last contact, then deleted or anonymised
Sales conversations (Instagram DM, WhatsApp, Kommo) for customersDuration of the customer relationship plus 5 years, then archived in restricted form for limitation-period and tax purposes
Tier 1, 2, 3 course-access recordsDuration of access plus 3 years
Payment / invoicing records10 years from the end of the financial year in which they were issued, as required by Romanian Law 82/1991 on accounting (Legea contabilității), art. 25
Passport scans, visa documents, criminal-record checks (Tier 3)Until 12 months after your Vietnamese work permit and residency are granted, then deleted, unless a longer period is required to defend a legal claim
Qualification videosUntil the end of the active sales cycle plus 6 months, then deleted
Marketing-cookie dataPer the cookie's own lifetime — see Section 8
Backups and request logsVercel retains operational request logs for a short period under its own retention policy (typically 1–7 days depending on plan). Kommo, Google Workspace, and Stripe retain backups under their own privacy policies. We do not maintain an independent backup of personal data beyond what these providers keep.

When the retention period ends, we delete the data or anonymise it so that it can no longer be linked back to you.

7. How we protect your data (security)

We take the following technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, and loss:

  • Encryption in transit: all traffic between your browser and up2uagency.info is encrypted using HTTPS/TLS. WhatsApp messages are end-to-end encrypted by Meta. Email traffic is encrypted in transit (TLS) between supporting servers.
  • Encryption at rest: sensitive documents (passport scans, signed contracts) are stored in access-controlled cloud storage that encrypts data at rest.
  • Access control: access to your personal data is restricted to the controller identified in Section 1 and to the data processors named in Section 4.2. Multi-factor authentication is enforced on admin accounts of Kommo, Stripe, Google Workspace, and Meta Business Manager.
  • Payment-card data isolation: we never receive your full card number. Stripe handles all card data on PCI-DSS Level 1 infrastructure.
  • Vendor due diligence: we select processors that are themselves accountable under GDPR or equivalent regimes and that publish their own security documentation.
  • Internal AI use: the AI tools we use to help draft replies and analyse our own sales conversations (Claude, NotebookLM) operate on API and account configurations that, to our knowledge, do not feed your data into the providers' public training sets.
  • Incident response: if we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, we will notify you directly.

No system is perfectly secure. We do not, and cannot, guarantee absolute security — but we commit to handling your data with the standard of care our profession requires.

8. Cookies and tracking

Our website uses the following cookies and tracking technologies:

  • Strictly necessary cookies and storage — required to load the site, route you to checkout, and remember your language. These do not require consent under ePrivacy law and cannot be disabled. Our hosting provider (Vercel) also sets a small number of operational cookies and HTTP headers necessary to route requests and serve content from its edge network.
  • Referral cookie — if you reach our site through a referral link shared by one of our partners or past clients (a link containing a ?ref= code), we store that referral code in a first-party cookie named ref (and an equivalent entry in your browser's local storage) for up to 12 months. Its only purpose is to remember which partner introduced you, so that we can credit them correctly if you make a purchase. This information stays on our own systems — it is not shared with Meta, advertisers, or any third party, and it is not used to track you across other websites. If you do not arrive via a referral link, this cookie is never set.
  • Analytics — we use Vercel Web Analytics, the privacy-preserving analytics tool built into our hosting provider. It records aggregated page-view counts without setting any cookie in your browser and without storing personally identifying information; visitor IP addresses are hashed in memory to derive an approximate country and are then discarded. We do not run Google Analytics, Google Tag Manager, Hotjar, Microsoft Clarity, Plausible, Fathom, or any other third-party analytics tool. See vercel.com/docs/analytics for details on Vercel's analytics privacy posture.
  • Advertising cookies and pixels — we run paid advertising on Meta (Instagram and Facebook). The Meta Pixel is installed on up2uagency.info and tracks which pages you visit so that Meta can attribute conversions to our ads and so that we can show UP2U content to you and to similar audiences on Instagram and Facebook. The Meta Pixel sets cookies in your browser and sends an HTTP request to facebook.com/tr on each page load, subject to the consent rules described at the end of this Section. See Meta's Cookies Policy: facebook.com/policies/cookies.
  • Static-asset content delivery networks (CDNs) — to load pages, our website fetches typefaces from Google Fonts (fonts.googleapis.com / fonts.gstatic.com), interface icons from Icons8 (img.icons8.com), and the Tailwind CSS library from Tailwind's CDN (cdn.tailwindcss.com). Each of these CDNs receives your IP address and the URL of the resource you request — this is technically necessary to deliver the visual layer of the page. They do not set tracking cookies on our pages. Our payment library Stripe.js (js.stripe.com) also loads on every page so that the checkout form is ready when you reach it; Stripe is already named as a data processor in Section 4.2.
  • Embedded third-party content — some of our pages embed YouTube testimonial videos. When you view a page with a YouTube embed, the video loads from Google's servers and is subject to YouTube's own privacy policy and cookies. We are progressively migrating these embeds to the youtube-nocookie.com privacy-enhanced domain.

We do not currently run advertising on Google, TikTok, or any other ad network, and no other advertising pixels are installed.

How we obtain consent (cookie banner): we operate a consent mechanism that applies the rules of the law in force where you are located:

  • European Economic Area, United Kingdom, and Switzerland — the Meta Pixel and any non-essential tracking are blocked until you give consent. When you first visit, a banner lets you Accept or Decline with equal ease; nothing non-essential loads, and no Meta request is sent, unless and until you click Accept. Declining does not restrict your access to the site.
  • United States — the Meta Pixel loads by default, but we honour the Global Privacy Control (GPC) browser signal as a valid opt-out of "sale"/"sharing" under the CCPA/CPRA and similar state laws: if your browser sends GPC, the Pixel is suppressed for you automatically.
  • Rest of the world — the Meta Pixel loads by default, as permitted by local law.

Your choice is stored on your device for up to 6 months, after which we ask again. You can change or withdraw your choice at any time using the button below, which re-opens the consent banner. Withdrawing consent is as easy as giving it (GDPR Art. 7(3)).

You can also, at any time and in any region: block third-party cookies in your browser, use a tracker-blocking extension (e.g. uBlock Origin, Privacy Badger), adjust personalised-ad settings in your Meta account, or write to privacy@up2uagency.info to ask us to suppress retargeting against your identifiers — we will action this within 30 days.

9. Automated decision-making and AI

We use AI tools, including Anthropic's Claude and Google's NotebookLM, to help draft replies, summarise long lead conversations, and analyse aggregated sales data. These tools are decision-support for the controller — they do not make binding decisions about you, they do not by themselves decide whether you are accepted into Tier 3, and they do not set your price. A human (the controller identified in Section 1) always reviews and is responsible for any decision that affects you, including Tier 3 acceptance, which is decided personally and never by an automated system.

You have the right to ask for human review of any decision you believe was made about you by automated means alone — write to privacy@up2uagency.info.

10. Your rights

If you are in the EEA, UK, or Switzerland — and, by our policy, regardless of where you live — you have the following rights over your personal data:

  • Access — get a copy of the personal data we hold about you and information about how we process it.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — ask us to delete data we no longer have a lawful basis to keep.
  • Restriction — pause our processing while you contest accuracy or our lawful basis.
  • Portability — receive a machine-readable copy of data you gave us, or have us send it to another provider, where technically feasible.
  • Object — object to processing based on legitimate interest (including marketing); for direct marketing this is absolute and we will stop.
  • Withdraw consent — where we rely on consent (cookies, special-category data, marketing). Withdrawal does not affect prior lawful processing.
  • Lodge a complaint with your local supervisory authority. In Romania this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)dataprotection.ro. You can also complain to the authority in the EU/EEA country where you live or where the alleged infringement happened.

To exercise any of these rights, write to privacy@up2uagency.info with enough information for us to identify you securely. We will reply within 30 days (extendable by two further months for complex requests, in which case we will tell you why). We will not charge you for the first request; manifestly unfounded or excessive repeated requests may be charged a reasonable fee or refused.

We do not use the California Consumer Privacy Act (CCPA) "sale" mechanism — we do not sell your personal data. California residents nonetheless have rights to access, deletion, correction, and non-discrimination, exercisable via the same contact above.

11. Children

UP2U's services are not directed at children. We do not knowingly process personal data of anyone under 16 for marketing purposes. Tier 1 (the DIY course) is open to adult learners only; Tier 2 and Tier 3 require legal capacity to sign an international work contract, which in practice means 18+. If we discover we have collected data from a child below the age threshold without verified parental consent, we will delete it.

12. Changes to this policy

We will update this Policy when our practices change or when the law requires. The "Last updated" date at the top will always show the current version. Material changes will be announced on up2uagency.info and, where reasonable, by direct message to active customers. Continued use of our services after a material change indicates acceptance.

13. Contact

For any privacy question, request, or complaint:

  • Email: privacy@up2uagency.info
  • Postal address: 136 Bucureștii Noi Blvd., apt. 5, Sector 1, Bucharest 012366, Romania, European Union
  • Controller: TABACU TUDOR-LUCREȚIU P.F.A., CUI 52423615