Personal data protection

Privacy Policy

Effective 29 August 2026. This Policy describes actual processing on the website, calendar and public booking, Author Account, Student Account, Classroom, reviews, and the optional Telegram bot.

01

Controller and scope

Controller: sole proprietor Pokulytyi Maksym Volodymyrovych, Ukrainian tax number 3323110774, 11 Vysokohirna Street, Dnipro, Dnipropetrovsk Region, 49048, Ukraine. Data requests: support@tutora.com.ua. This Policy covers website visitors, Authors, Students, persons lawfully added by an Author, support contacts, and future payers. External sites have their own policies. Tutora does not sell personal data.

02

Data categories and sources

Tutora may process account identifiers and password hashes; optional public-profile data; courses, lessons, files, answers, scores, comments, progress, schedule, attendance, Classroom data and recordings. Public booking adds guest name and email, optional comment, selected time and timezone, status, email verification, consent revision/time, IP and user agent, and after approval a Student Account and Classroom link. A Tutora review may include rating, optional text, a Student name-display choice, moderation status/note, public name, Tutora reply, and the prior approved version until deletion. Voluntarily connected Telegram adds user/chat ID, username, name, notification settings, support communications, and attachments. Tutora also processes plan and payment records without full card data, IP address, user agent, security logs, cookies, and localStorage. Sources are the User, a lawfully acting Author, Google OAuth, browser/device, bank or future payment provider, and platform operation. Users should not upload sensitive categories unless necessary and lawfully authorised.

03

Purposes and legal bases

Data is used for registration and contract performance; availability display, email verification, booking approval and creation of a Student Account and Classroom; teaching, review, progress and Backup; submission, manual moderation, publication and deletion of Tutora reviews; service notifications and support; payments and statutory accounting; abuse prevention, legal protection, compliance, and aggregated reliability improvement. Bases are contract or pre-contract steps, legal obligations, consent where required (including optional publication, communications, and recording), and legitimate interests in security, support, service improvement, and legal claims where individual rights do not prevail. Marketing requires a separate lawful basis and opt-out; Tutora currently uses no behavioural advertising.

04

Authors, Students, and minors

Tutora controls account and platform-operation data. Where an Author determines teaching purposes and adds Student data, answers, or recordings for their own practice, the Author is also responsible for lawful basis, minimisation, notice, retention, and rights; Tutora technically processes the data to provide the service. Authors must not add Students without authority or expose them to other Students. A minor’s learning is organised by an adult Author or lawful representative; audio/video recording, publication, and report sharing require separate authority and consent where law requires.

05

Public data and Author-supplied recipients

Learning materials, answers, Classroom, and private booking details are not public by default. An Author separately chooses publication of profile, contacts, course, or template; a booking page shows only available time, not titles or details of busy events. A Tutora review becomes public only after manual moderation: an Author Account displays the Author’s public name, while a Student Account holder may choose a name or anonymous label. Third parties and search engines may copy public data outside Tutora’s control. Anyone supplying a third party’s email, phone, or other details for an invitation, report, or support confirms authority and must inform the recipient. Tutora does not send learning results to an arbitrary Telegram number; the recipient must first opt in and link it.

06

Providers and recipients

Where necessary, recipients may include OVHcloud for server infrastructure; Cloudflare for DNS, email routing, and private R2 storage; Brevo for transactional email; and Telegram through the Bot API only after the User voluntarily starts the bot, for optional service notifications and support. Every category available to the role is enabled by default after connection and may be disabled individually, or Telegram may be disconnected; email remains primary. Telegram receives only the particular message data and technical identifiers needed for delivery. Other recipients may include Google for selected OAuth and visible enabled reCAPTCHA, self-hosted LiveKit, Daily.co only when fallback is used, YouTube privacy-enhanced embeds, UNIVERSAL BANK, and a future payment provider only after a separate launch and Policy update. Vetted support contractors, accountants, lawyers, auditors, banks, and authorities receive only necessary data under contract, lawful demand, or legal-protection grounds.

07

Processing location and international transfer

Tutora’s main server is in Germany and self-hosted LiveKit is in Poland. Public and private R2 storage has an Eastern Europe location without a separate jurisdiction restriction; the R2 bucket for LiveKit recordings has EU jurisdiction. Brevo states that its main databases are stored in France, Germany, and Belgium. Google may process data in countries worldwide. Daily performs its primary processing in the United States and uses global AWS call regions; data is transferred to Daily only when the configured fallback is actually used. Transfer occurs only where needed for a feature or contract, with consent where required, or on another lawful basis. Before adding a provider, Tutora reviews data categories, location, terms, access, and deletion. Details are available on request.

08

Retention and deletion

Account and learning data remain while active or needed and are deleted or anonymised after a verified request except records required for accounting/tax, acceptance evidence, disputes, security, or law. An unverified booking holds a slot for 15 minutes; an email-verified request awaits the Author for up to 12 hours or until the class starts. Booking name, email, comment, IP and user agent not linked to a Student Account are anonymised 180 days after completion or cancellation, while technical status and time remain. A review and its prior approved version remain while the review exists and are removed from the active database when deleted. Other current periods: application logs up to 14 days; password reset links 60 minutes; Tutora Backup and import source up to 24 hours; completed Pro Classroom recording 180 days; Free board/chat/attachments deleted after the session. Rotation targets up to 3 deployment and 7 daily database copies, but Object Lock may extend retention; active-system deletion reaches backups after actual rotation.

09

Security and incidents

Tutora uses role separation, private access routes, TLS, password hashing, administrative MFA, upload scanning, private file storage, logging, backups, and login throttling. No system is perfectly secure; Users should use unique passwords and protect email and sessions. A confirmed incident is contained, evidenced, recovered, and notified to affected users and authorities to the extent and within the time required by applicable law or needed to reduce real risk. Vulnerabilities should be reported privately to support@tutora.com.ua without accessing others’ data.

10

Rights and request procedure

Users have the rights provided by Article 8 of Ukraine’s Personal Data Protection Law, including information, access, correction or destruction of unlawfully processed or inaccurate data, objection, consent withdrawal without retroactive effect, information about automated processing, protection from legally consequential automated decisions, and complaint to the Commissioner or court. Requests go to support@tutora.com.ua or the Controller’s postal address with enough information to verify identity and the requested action. Tutora may verify the person and representative. Responses follow statutory time limits; another person’s data is not disclosed. Account deletion may end the service but does not override mandatory record retention.

11

Cookies, changes, and complaints

Tutora uses necessary session/XSRF cookies, locale, and theme localStorage. It currently uses no behavioural analytics or advertising cookies. Google OAuth and YouTube may use their own technical storage only when the relevant function is used; reCAPTCHA only if it is enabled and shown in a form. See the Cookie Policy. Material changes are announced before application in the account or by email and the revision date changes. Questions go to support@tutora.com.ua; complaints may also be made to the Ukrainian Parliament Commissioner for Human Rights or a court. Where translations differ, the Ukrainian text governs relations with the Ukrainian Controller to the extent permitted by law.