Lulo Solutions LLC
Privacy Policy
This Privacy Policy explains how Lulo Solutions LLC (“Lulo Solutions”, the “Company”, “we”, or “us”) collects, uses, shares, retains, and protects personal information in connection with the Exlink platform (“Exlink”), whether accessed through our website at exlink.org or through the Exlink mobile application for iOS and Android (the “Mobile Application”).
Exlink is a business-to-business platform used by exchange program sponsors and their partners (each, a “Client”) to administer international student exchange, au pair, and work & travel programs. Much of the personal information in Exlink is entered by a Client about its own participants, host families, and staff. Where we process that information on a Client’s instruction, the Client is the controller of that information and we act as processor on the Client’s documented instructions.
Relationship to the Terms of Service. The binding privacy provisions governing Exlink are set out in Section 14 of the Terms of Service. This Privacy Policy states those provisions in full and in plain form. In the event of any conflict between this Privacy Policy and Section 14 of the Terms of Service, Section 14 governs.
Information We Collect
Information collected through Exlink includes, but is not limited to: name, address, email address, telephone number, date of birth, gender, government-issued identification (such as social security number, passport, and visa), other immigration-related information, and medical, health, and insurance information.
We also collect technical and usage information automatically when users access the platform, such as IP address, browser type, and sign-in activity. This information is collected for security purposes and is subject to the retention period described under Retention below.
If you are an exchange program participant and you send an emergency alert from the Mobile Application, we also collect your device’s location, as described under Mobile Application below.
We do not collect advertising identifiers, and we do not use analytics or advertising software development kits in the Mobile Application. We do not use advertising or third-party tracking cookies.
How We Use Personal Information
We use personal information collected through Exlink for the following purposes: to provide and maintain the platform; to facilitate exchange services on behalf of Clients; to communicate with Clients and authorized users regarding platform functionality and account management; to communicate elective product and service offers to eligible users; to comply with applicable regulatory requirements; to deliver emergency alerts sent by program participants, including sharing the participant’s device location with the participant’s designated support team as described under Mobile Application below; to maintain the security of user accounts and detect and prevent unauthorized access; and to improve and enhance Exlink.
How We Share Personal Information
We may share personal information with the following categories of recipients: individuals who have provided their consent; service providers and contractors engaged by us to support platform operations, including our hosting and diagnostics providers; third-party integrations that a user chooses to connect, as described under Third-Party Calendar Integrations below; governmental authorities and legal requirement responders as required by applicable law; and parties involved in safety and fraud protection contexts where disclosure is necessary to protect the rights, property, or safety of the Company, its Clients, or others.
We do not sell personal information, and we do not share it for advertising purposes. This applies to location information as well: we do not use location for tracking across applications or websites, for advertising, or for any purpose other than delivering an emergency alert you have sent.
International Data Transfers
Each user consents to the transfer of their personal information to the United States and other countries, which may have different data protection laws than the user’s country of residence. Where personal data is transferred from the European Union to the United States, the safeguards in Section 17 of the Terms of Service apply.
Your Access and Correction Rights
Your personal information in Exlink is held on behalf of the Client or sponsoring organization through which you participate, and that organization, as controller of the information, administers requests to access, correct, update, or delete it. Direct such requests to your sponsoring organization.
Requests that reach us at privacy@exlink.org are referred to the relevant Client, and we assist the Client in responding.
Account Deletion
Your account is created and administered by the Client or sponsoring organization through which you participate; the Mobile Application does not offer account registration. Deletion works the same way: your sponsoring organization can delete records and irreversibly erase personal information directly within the platform, and decides whether and when to do so in its role as controller of that information, subject to the retention requirements of applicable law and exchange program sponsorship. If you want your account or personal information deleted, ask your sponsoring organization. Requests that reach us at privacy@exlink.org are referred to the relevant Client, and we assist the Client in responding.
Retention
We retain personal information for as long as the Client on whose behalf it is processed maintains an active account with us, and thereafter for the period required to meet our legal, regulatory, tax, and program-compliance obligations, including obligations arising from exchange program sponsorship. When a retention period ends, personal information is deleted or irreversibly anonymized.
The following categories are subject to shorter retention periods, which apply in place of the general period described above:
(a) Platform access records. The technical and usage information described under Information We Collect above — the records generated when a user signs in to or otherwise accesses the platform, such as IP address, browser type, and sign-in activity — is retained for security purposes and automatically deleted after one month.
(b) Mobile diagnostic reports. The diagnostic and crash reports described under Mobile Application below are a separate category from platform access records and are retained no longer than ninety (90) days.
(c) Push notification tokens. Push notification tokens are retained only while the associated device remains signed in, and are deleted when the user signs out of that device or that session is revoked.
(d) Calendar integration data. The OAuth tokens and related identifiers described under Third-Party Calendar Integrations below are retained only while the calendar remains connected.
(e) Emergency alert location history. Location information collected through the emergency alert feature described under Mobile Application below is retained for thirty (30) days after the alert and then deleted; it is deleted sooner where the participant’s personal information is erased within the platform.
Cookies
Exlink uses only first-party cookies that are necessary to operate the platform: (a) a session cookie that keeps you signed in; (b) a security cookie that helps us recognize the browser you signed in from, so we can detect and prevent unauthorized use of your account — it contains only a random identifier and may persist for up to five years; and (c) a token cookie that protects forms you submit. We do not use advertising or third-party tracking cookies. You may delete or block cookies in your browser settings, but the platform cannot function without the session and security cookies.
Mobile Application
This Privacy Policy applies to the Mobile Application in the same way it applies to the web platform. The Mobile Application provides access to the same personal information described under Information We Collect above; it does not collect categories of personal information beyond those described there, except as set out in this section.
Device and Session Data. When you sign in to the Mobile Application, an authentication token is stored on your device using the operating system’s secure storage. This token identifies your session and is deleted when you sign out or when the session expires. We do not collect advertising identifiers, and we do not use analytics or advertising software development kits in the Mobile Application.
Push Notifications. If you permit notifications, your device is issued a push notification token by Apple or Google, which we store and associate with your user account and the device that issued it, so that notifications reach the correct device. The token is removed when you sign out of that device. You may withdraw notification permission at any time in your device settings, which stops delivery. We do not use push notification tokens for marketing.
Diagnostics and Crash Reporting. The Mobile Application reports errors and crashes to our diagnostics provider so that we can identify and fix faults. These reports contain technical information such as the device model, operating system version, application version, and the sequence of events leading to the fault. They are configured not to include personally identifying information. We do not use this data for any purpose other than maintaining and improving the Mobile Application.
Device Permissions. The Mobile Application requests permission for notifications, and — if you are an exchange program participant — for location while the application is in use, which is used only for the emergency alert feature described below. It never requests background location, and it does not request access to your camera, microphone, contacts, or photo library.
Emergency Alerts and Location. If you are an exchange program participant, the Mobile Application includes an emergency alert feature. Sending an alert notifies your designated support team; it does not contact police, ambulance, fire, or any other public emergency service, and no response time is guaranteed — if you are in immediate danger, always call your local emergency number. When you send an alert, we collect your device’s location at that moment and share it with the support team your alert notified. If you have granted standing location permission and keep the application open, your location continues to update while the alert remains active. We do not collect your location at any other time, we never collect it in the background, and we never use it for analytics, personalization, advertising, or tracking. Sending an alert does not require location — the alert is delivered whether or not you allow it, and answering “Allow once” or “Only this time” is fully supported. Location history for an alert is deleted as described under Retention above; the record of the alert itself (who was notified and who responded) contains no location information and is retained as part of your program records.
Locally Stored Files. Documents and images you open or download within the Mobile Application are written to the application’s private storage on your device so the operating system can display or share them. Removing the application removes these files.
App Store Distribution. The Mobile Application is distributed through the Apple App Store and Google Play. Those platforms may collect information about your download and use of the application under their own privacy policies, over which we have no control.
Children and Minors
The Mobile Application is not directed to children under 13, and we do not knowingly permit them to create or use an account.
Exchange program participants are enrolled through a sponsoring organization, and personal information relating to a participant who is a minor is provided to us by that organization or by the participant’s parent or legal guardian, who obtains any consent required by the law of the participant’s own country — including any parental consent required under Article 8 of the General Data Protection Regulation where the applicable digital-consent age is above 13.
Where a minor’s personal information is processed on a Client’s instruction, that Client is the controller of that personal information and we act solely as processor on the Client’s documented instructions.
A parent or legal guardian who believes that a child under 13 has provided personal information directly to us may contact us at privacy@exlink.org, and we will delete it.
Third-Party Calendar Integrations
Exlink lets you connect your Google or Microsoft calendar so people can book meetings with you and so those meetings stay in sync. The data we access is used solely to provide this scheduling feature — we do not sell it, share it for advertising, or use it for any unrelated purpose.
Google Calendar
When you connect Google Calendar, you grant Exlink permission to:
- See and edit events on your calendars (
calendar.events) — create the meeting event (with a Google Meet link) when someone books you, update it on reschedule, delete it on cancellation, and watch for changes you make directly in Google Calendar so they sync back to Exlink. - View free/busy information (
calendar.events.freebusy) — used only to find your open times so your booking page offers genuinely available slots; we do not read the titles, attendees, or details of your other events. - View your list of calendars (
calendar.calendarlist.readonly) — so you can choose which calendar Exlink writes to and reads availability from. - Your basic Google profile (name, email) — to identify the connected account.
Limited Use. Exlink’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft / Outlook Calendar
When you connect a Microsoft (Outlook or Microsoft 365) calendar, you grant Exlink permission to:
- Read and write your calendars and events (
Calendars.ReadWrite) — create the meeting event (with a Microsoft Teams link) when someone books you, update it on reschedule, delete it on cancellation, read your availability so your booking page only offers open slots, list your calendars so you can choose which one Exlink uses, and subscribe to changes so edits you make in Outlook stay in sync with Exlink. - Sign you in and read your basic profile (
User.Read) — your name and email, to identify the connected account. - Maintain the connection (
offline_access) — so Exlink can perform the above on your behalf without asking you to sign in every time.
Exlink’s access to and use of Microsoft data complies with the Microsoft APIs Terms of Use.
Data Storage and Disconnection
We store the OAuth access and refresh tokens for your connected account (encrypted at rest) so Exlink can act on your behalf, together with the identifiers of the events we create and the calendars you select. We retain this only while your calendar is connected. You can disconnect at any time from your calendar settings in Exlink, which deletes our stored tokens. You can also revoke Exlink’s access directly through your provider — Google at myaccount.google.com/permissions, Microsoft at myaccount.microsoft.com (work/school accounts) or account.live.com/consent/Manage (personal accounts).
How We Protect Your Data
Exlink safeguards all data it accesses — including data obtained from Google APIs, such as your calendar events and free/busy information — using strong, industry-standard measures:
- Encryption in transit and at rest. All data is encrypted in transit using TLS (HTTPS) and at rest using AES-256 encryption. The OAuth access and refresh tokens for your connected Google account are stored encrypted at rest.
- Access controls. Access to data is limited on a strict need-to-know basis, and administrative access requires multi-factor authentication.
- Secure infrastructure. Data is hosted on Amazon Web Services (AWS) and encrypted using AES-256 both in transit and at rest; AWS does not have access to unencrypted data.
- Retention and deletion. We retain Google user data only while your calendar remains connected. You can disconnect at any time, which deletes the stored OAuth tokens and the associated Google data we hold.
- Incident response. If we confirm unauthorized access to your data, we notify the affected account’s designated security contact within 24 hours.
Limited Use. Exlink’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data solely to provide the calendar scheduling features you request; we do not sell or transfer this data, use it for advertising, or allow humans to read it except (a) with your consent, (b) for security purposes, (c) to comply with applicable law, or (d) as strictly necessary to operate and improve the feature.
Governing Language
This Privacy Policy is made in the English language. Any translation is provided for convenience only. In the event of any conflict or inconsistency between the English version and a translation, the English version governs.
Changes to This Policy
We may update this Privacy Policy from time to time. The version number and last-updated date at the top of this page indicate when it was last revised. Material changes will be posted at exlink.org/legal.
Contact Us
Questions about this Privacy Policy, or requests to access, correct, or delete personal information, should be directed to privacy@exlink.org.
Suspected security incidents or unauthorized access should be reported to security@exlink.org.