Privacy Policy- Residency Match & Lira

Operated by SpeakEasy Consulting LLC · Sold by Closing Time Hub LLC

Last updated: July 10, 2026

1. Who We Are

This Privacy Policy governs personal data processed in connection with the Residency Match (AKA ResiMatch) and Lira (AKA Lira Language) brands and the websites, learning platforms, coaching, and services offered under them (collectively, the “Services”).

Two companies are involved in providing the Services, each responsible for a different part of the relationship:

  • SpeakEasy Consulting LLC (“SpeakEasy”), a Puerto Rico limited liability company, creates and operates the ResidencyMatch and Lira brands and delivers the educational, coaching, and consulting services. SpeakEasy is the data controller for personal data arising from service delivery, including learning-management-system (LMS) data, coaching records, and related operational data. Address: Urb. Alturas del Mar, calle Coral 127, Cabo Rojo, PR 00623. Email: support@speakeasy-consulting.com.
  • Closing Time Hub LLC (“Closing Time Hub”), a New Mexico limited liability company, is the merchant of record and sells access to the Services. Closing Time Hub is the data controller for checkout, order, and billing data collected at the point of sale. Address: 4502 Hamptonshire Dr, Raleigh, NC 27613. Email: contact@closingtime-hub.com.

When you purchase the Services, Closing Time Hub processes your order and payment and then transmits the information necessary to activate and deliver the Services to SpeakEasy. Each company acts as an independent controller for the data it handles, and shares data with the other only as needed to complete your purchase and deliver what you bought. “We,” “us,” and “our” refer to SpeakEasy and Closing Time Hub together where both are involved, and to the relevant company where only one is.

2. Scope

This Policy applies to individuals who visit our websites, contact us, purchase or use the Services, subscribe to our newsletter, or otherwise interact with us. The Services are offered to adults engaged in professional and educational development, including international medical graduates and the organizations that train them.

Visitors located in the European Economic Area (EEA). Our websites are informational only. We do not complete consumer sales to the EEA through our websites. Commercial relationships with organizations in the EEA are business-to-business and are established through separate written agreements and direct contact, not through online checkout. Where we nonetheless process the personal data of individuals located in the EEA, we do so in accordance with the General Data Protection Regulation (GDPR), as described in Section 13.

3. Categories of Personal Data We Collect

Depending on how you interact with us, we may collect:

General information: name; email address; phone number; billing address; account-registration details; communications and support requests; payment confirmations; technical information such as IP address, browser type, device, and logs; and newsletter subscription and engagement data.

Educational and platform information (ResidencyMatch, Lira, and related courses): course enrollment and attendance; module completion and progress; assignments and submissions; assessments, scores, and evaluations; coaching notes and instructor feedback; mock-interview results; platform usage analytics; login timestamps and IP addresses; and session or webinar recordings where applicable and agreed (see Section 6).

We collect and process personal data only to the extent necessary to provide the Services, operate our websites, communicate with you, and meet legal obligations. We do not sell or rent personal data, and we do not “share” personal data for cross-context behavioral advertising.

4. How and Why We Use Your Data, and Our Legal Bases

We process personal data for the purposes below. For individuals protected by the GDPR, the applicable legal basis is shown alongside each purpose (Purpose — Legal basis):

  • Operate and maintain our websites and platforms — Legitimate interests
  • Create and manage your account — Performance of a contract
  • Respond to inquiries and support requests — Legitimate interests; or performance of a contract
  • Schedule and deliver coaching, training, and consulting — Performance of a contract
  • Provide access to educational programs and LMS services — Performance of a contract
  • Track enrollment, attendance, progress, assignments, assessments, and feedback — Performance of a contract
  • Conduct mock interviews and coaching evaluations — Performance of a contract; consent (for recordings)
  • Issue completion records or certifications — Performance of a contract
  • Process purchases, payments, and invoices — Performance of a contract
  • Maintain billing records for tax and accounting — Legal obligation
  • Send newsletters and marketing communications — Consent
  • Analyze website usage to improve the Services — Consent (analytics cookies); otherwise legitimate interests
  • Protect system security; prevent fraud and misuse — Legitimate interests
  • Comply with legal, regulatory, and contractual obligations — Legal obligation

We do not process personal data for purposes incompatible with those listed above.

5. Payments and E-Commerce

Purchases are processed by Closing Time Hub as merchant of record through WooCommerce, using Stripe and PayPal as payment processors. We do not store full payment-card numbers. Card data is handled directly by Stripe and PayPal, which process it under the PCI-DSS standard. We retain order and billing records as required for tax and accounting purposes.

6. Educational Services, Coaching, and Recordings

When you enroll in ResidencyMatch, Lira, or any course delivered through our LMS, we process the educational and platform data needed to manage and deliver the program. This data is used only for service-related purposes and retained as described in Section 11.

Recordings. Mock interviews may be recorded for educational and quality-assurance purposes. Recording is always disclosed in advance, and participation requires the participant’s agreement to be recorded. If you prefer not to be recorded, we offer a one-to-one session instead, which is not recorded and is kept confidential. Recordings, where made, are treated as confidential and may be deleted on request unless we are legally required to retain them.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the site and improve your experience:

  • Essential cookies: required for security, the shopping cart, and LMS login. These cannot be disabled.
  • Analytics cookies: measure traffic and usage (via Google Analytics).

Non-essential cookies, including analytics, are set only after you give affirmative, prior consent through our cookie banner. Until you consent, these tags do not run. You can accept, reject, or customize your preferences at any time, and rejecting is as easy as accepting. Disabling cookies may affect some features.

Where required, we honor recognized browser-based opt-out signals, including the Global Privacy Control (GPC).

8. Marketing Communications and Newsletter

Our newsletter and promotional emails (including “Prompting Humans”) are sent only with your explicit prior consent, managed through our email platform, Encharge. We use a double opt-in process and store proof of consent. We do not use pre-checked boxes or implied consent.

When you subscribe, we may collect your email address, name (if provided), the date and time of subscription, technical metadata, and engagement data such as opens and clicks. Emails may include standard tracking (pixels or link monitoring) used solely to measure engagement and improve content.

Every message includes a clear unsubscribe link. You may withdraw consent at any time; after you unsubscribe, marketing emails stop, and we retain only minimal information needed to honor your opt-out. Our email practices are designed to comply with the CAN-SPAM Act and, where applicable, the GDPR. We do not sell or share email addresses for third-party marketing.

9. Third-Party Service Providers

We use trusted providers to operate the Services. Each processes personal data only on our behalf, under confidentiality and data-protection terms, and only as needed to perform its function (Provider — Function):

  • OVH (France) — Website and LMS hosting; primary data storage
  • LearnDash — Learning-management-system software powering our courses
  • WooCommerce — E-commerce and order management
  • Stripe; PayPal — Payment processing
  • Google Workspace (incl. Google Meet) — Email, collaboration, and video sessions or webinars
  • Encharge — Email marketing and newsletter delivery
  • Google Analytics — Website usage analytics

We may also disclose personal data when required by law or legal process, or in connection with a merger, acquisition, or business transfer.

10. International Data Transfers and Storage

Because the Services are provided online, personal data may be processed in more than one country.

  • Website, LMS, and coaching data are hosted and stored on servers located in France (OVH), within the EEA.
  • Data handled through Google Workspace — including email and Google Meet sessions or recordings — may be processed in the United States and other locations where Google operates.

For individuals in the EEA whose data is transferred to the United States (for example, via Google Workspace), those transfers rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and Google’s certification under the EU–U.S. Data Privacy Framework. For users outside the EEA, storage of data on EEA-based servers provides a high standard of protection.

We apply access controls, encrypted communications, and contractual safeguards to protect data transferred between jurisdictions.

11. Data Retention

We keep personal data only as long as necessary for the purposes described, then delete or anonymize it:

  • Client and service data: for the duration of the service relationship and up to 5 years afterward.
  • Educational and course data: for the duration of the program plus a reasonable administrative period.
  • Billing and order records: as required by tax and accounting law.
  • Support communications: up to 2 years.
  • Technical logs: up to 12 months.
  • Newsletter data: until you unsubscribe.
  • Recordings: retained only briefly for the stated purpose, or until you request deletion, unless a legal requirement applies.

12. Data Security

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration, including restricted access controls, secure hosting, encrypted databases, staff confidentiality obligations, and regular monitoring. Traffic between your browser and our sites is protected with SSL/HTTPS encryption. No system can guarantee absolute security.

13. Your Privacy Rights

We honor privacy rights based on where you live. The core rights below are available to all users as a baseline; specific frameworks add to them.

Baseline rights (all users): access your data; correct inaccurate or incomplete data; request deletion (subject to legal retention); restrict or object to processing; request portability; withdraw consent; and unsubscribe from marketing.

13.1 EEA and UK (GDPR)

If you are in the EEA, you have the rights above under the GDPR, and in addition the right to lodge a complaint with your local data protection supervisory authority. The legal bases on which we rely are listed in Section 4. Where processing is based on consent, you may withdraw it at any time without affecting processing carried out beforehand.

We are established outside the EEA. If we become required to designate a representative in the EU under Article 27 of the GDPR, that representative’s contact details will be published in this Section.

13.2 California (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it; to request deletion; to correct inaccurate information; to opt out of the “sale” or “sharing” of personal information; and to limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.

We do not sell or share personal information as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit. Where required, we recognize the Global Privacy Control (GPC) signal as a valid opt-out request.

13.3 Other US states

If you reside in another US state with a comprehensive privacy law, you have the rights that law grants — typically access, correction, deletion, portability, and opt-out of targeted advertising, sale, or certain profiling. Contact us to exercise them, and we will apply the protections required by your state.

13.4 How to exercise your rights

To exercise any right, contact us at support@speakeasy-consulting.com (service and educational data) or contact@closingtime-hub.com (checkout and billing data); either address will route your request appropriately. We verify identity before responding, using measures proportionate to the sensitivity of the data. We respond within the period required by applicable law — generally within 30 days for GDPR requests (extendable by up to 60 days for complex requests) and within 45 days for California requests (extendable by 45 days with notice). These rights apply regardless of your country of residence as a matter of our contractual commitment, and are not conditioned on any particular national law.

14. Children’s Privacy

The Services are intended for adults and are not directed to anyone under 18. We do not knowingly collect personal data from minors, and we require users to confirm they are at least 18 at registration. Because the Services are adults-only, they fall outside the scope of the U.S. Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected data from a person under 18, we will delete it.

15. Data Breach Notification

If a security breach compromises personal data, we will investigate promptly. Where the GDPR or other applicable law requires it, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights. Notifications will describe the nature of the breach, likely consequences, and recommended protective steps.

16. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. If this changes, we will update this Policy and provide the disclosures required by applicable law.

17. Third-Party Links

Our websites may link to third-party sites we do not control. We are not responsible for their content or privacy practices. Review their policies before providing personal data.

18. Changes to This Policy

We may update this Policy. Updates take effect when posted, with a revised “Last updated” date. Material changes will be communicated where required by law.

19. Governing Law and Jurisdiction

This Policy and any dispute relating to it are governed by the laws of the State of New Mexico, USA, without regard to its conflict-of-law principles, and the state and federal courts located in New Mexico will have jurisdiction. This choice of governing law does not deprive you of the protection of mandatory consumer-protection or data-protection rights available to you under the law of your country or state of residence.

20. Contact Us

Service, educational, or coaching matters — SpeakEasy Consulting LLC. Urb. Alturas del Mar, calle Coral 127, Cabo Rojo, PR 00623. Email: support@speakeasy-consulting.com.

Checkout, order, or billing matters — Closing Time Hub LLC. 4502 Hamptonshire Dr, Raleigh, NC 27613. Email: contact@closingtime-hub.com.