For tutors

Data Processing Agreement

Your students are yours. This is the art. 28 GDPR agreement that puts it in writing — you are the controller, we take instructions.

Version 2 September 2026

This Data Processing Agreement ("DPA") governs our processing of personal data on your behalf. It forms part of the Terms of Service and is accepted when you accept them, so you do not need to send us your own — it satisfies art. 28(3) GDPR.

Parties

  • Controller — you, the tutor holding a MyTutoringHome account.
  • Processor — MyTutoringHome, Fluiterlaan 536, 2903 HN Capelle aan den IJssel, The Netherlands.

If your organisation requires a countersigned copy, or a version under a different governing law, write to contact@mytutoringhome.com.


1. Roles

You are the controller of your students' personal data. You decide who to add, what to record, why, and for how long.

We are the processor. We store and process that data only to provide the Service, and only on your instructions.

For your own account data we are the controller — that is covered by the Privacy Policy, not this DPA.

Neither of us is a joint controller of the other's processing, and nothing here makes us one.


2. Scope of the processing

Subject matter. Providing the MyTutoringHome Service: student records, scheduling, availability, notifications and payment collection.

Duration. For as long as you have an account, plus the deletion periods in section 10.

Nature and purpose. Storage, organisation, retrieval, transmission, backup and erasure, carried out to run the Service.

Types of personal data and categories of data subject. Set out in Annex I.


3. Your instructions

We process personal data only on your documented instructions. Your instructions are:

  • this DPA and the Terms of Service;
  • the configuration you set in the app — availability, prices, reminders, automatic cancellation of unpaid lessons, recurring series;
  • the actions you take in the app;
  • any further written instruction we agree to.

We may also process where EU or member state law requires it, in which case we will tell you first unless that law forbids it.

We will tell you if, in our opinion, an instruction infringes the GDPR or other data protection law. We may suspend that instruction until it is resolved.

We will not process your students' data for our own purposes, will not sell or share it, and will not use it to train machine-learning models.


4. Confidentiality

Everyone we allow to process the data is bound by an appropriate obligation of confidentiality, is trained on their obligations, and gets access only where their role requires it.


5. Security

We implement the technical and organisational measures required by art. 32 GDPR, described in Annex II. We may change them, provided the level of security is not reduced.


6. Sub-processors

You give general written authorisation for us to engage sub-processors. The current list is published at /legal/sub-processors.

Before we add or replace one, we will:

  • publish the change on that page and email the address on your account, at least 30 days in advance;
  • impose on that sub-processor data protection obligations no less protective than this DPA;
  • remain fully liable to you for its performance.

You may object on reasonable data protection grounds within those 30 days, by writing to contact@mytutoringhome.com. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and export your data, and we will refund nothing because there is nothing to refund — you pay per lesson sold, not in advance.


7. International transfers

Student records are stored in the EU (Google Cloud Firestore, eur3 — Belgium and the Netherlands).

Where a sub-processor is outside the EEA, the transfer relies on an adequacy decision, the European Commission's Standard Contractual Clauses (Decision 2021/914), or the EU–US Data Privacy Framework, as stated per sub-processor in Annex III. Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference, with you as data exporter and us as data importer or as your agent for onward transfers, Module Two or Three as applicable. In case of conflict, the Clauses prevail over this DPA.


8. Assisting you

8.1 Data subject requests. You can view, correct and archive a student's record in the app yourself, which answers most access and rectification requests directly. For an export or an erasure, ask contact@mytutoringhome.com: we send an export in a structured, machine-readable format, or confirm erasure, within five business days — well inside the month art. 12(3) gives you to answer your student. If a student contacts us directly, we will not answer on your behalf; we forward the request to you promptly and tell them we have done so.

8.2 Security, breaches and impact assessments. We will assist you with your obligations under arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to us.

8.3 Personal data breaches. We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your students' data. The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose. Where we cannot give all of it at once, we will provide it in phases. Notifying the supervisory authority and the data subjects is yours as controller; we will give you what you need to do it.


9. Audit

We will make available the information needed to demonstrate compliance with art. 28, and will allow and contribute to audits, including inspections, conducted by you or an auditor you appoint.

In practice: ask contact@mytutoringhome.com and we will answer a reasonable security questionnaire and provide our sub-processors' certifications and reports. An on-site or technical audit may be requested once per year, or after a breach affecting your data, on 30 days' notice, during business hours, without disrupting the Service, subject to confidentiality, and — except where the audit finds material non-compliance — at your cost.


10. Return and deletion

When your account ends, at your choice:

  • for 30 days you may ask us for a complete export, returned in a structured, machine-readable format within five business days; then
  • we delete or irreversibly anonymise it within a further 30 days, including from backups within our normal backup rotation of 35 days.

We keep only what EU or member state law requires us to keep — principally payment records, for seven years under Dutch tax law — and that data stays subject to this DPA for as long as we hold it.

If we cease operating. Where we shut the Service down because we can no longer fund it, section 13.6 of the Terms of Service applies in place of the schedule above: at least 14 days' notice by email, export available on these same terms throughout that period, and deletion at the end of it. It is shorter than 30 days, and it is the only shortening of this section anywhere in these documents — a processor that cannot pay for storage cannot hold your data for two months after it stops. Nothing else changes: the data is still yours, the export is still free and unlimited, and whatever we must keep by law stays subject to this DPA. Deletion reaches the personal data we process for you. It does not reach your own Stripe account — the payment history there is held by Stripe under your agreement with them, not by us on your behalf, so it is neither ours to delete nor covered by this section.

You can archive an individual student in the app at any time. To have one erased outright, ask contact@mytutoringhome.com; we act within five business days and the same backup rotation applies.


11. Liability

Liability under this DPA is subject to section 17 of the Terms of Service, except where mandatory law provides otherwise — in particular art. 82 GDPR, which allocates liability towards data subjects between controller and processor, and administrative fines, which cannot be shifted by contract.


12. Governing law

Dutch law. Disputes go to the competent court in Amsterdam, as set out in section 23 of the Terms.


Annex I — Details of the processing

Categories of data subject

  • Your students, and where a student is under 16, their parent or guardian.

Types of personal data

CategoryFields
Identity and contactName, email address
PreferencesTimezone, preferred language
SchedulingLesson dates and times, lesson type, status, recurring series, attendance and no-show status, meeting links you enter
FinancialLesson price and currency, payment status, purchased lesson credits, Stripe payment identifiers. Not card numbers or bank details — those stay with Stripe
Free textThe notes you write about a student. Content is entirely yours; see section 4.5 of the Terms — special categories under art. 9 must not be entered
TechnicalPortal login credentials handled by Firebase Authentication, session cookie, security logs

Special categories of personal data. None are requested by the Service and none should be entered.

Frequency. Continuous, for the duration of your account.

Processing operations. Collection, storage, structuring, retrieval, use, transmission to the recipients in Annex III, backup, restriction, erasure.


Annex II — Technical and organisational measures

MeasureWhat we do
Encryption in transitTLS 1.2+ on every connection, HSTS on our domain
Encryption at restProvided by Google Cloud and Vercel at the storage layer
Access control — end usersFirebase Authentication; httpOnly, Secure, SameSite=Lax session cookies expiring after 14 days; password strength enforced at registration
Access control — authorisationEvery server-side request is authorised against ownership of the record before data is returned. Firestore security rules enforce the same tenant boundary independently, so a bug in one layer does not expose data
SegregationEvery record carries its owning tutor. No query returns data across tutors. Separate staging and production projects with no shared data
Payment isolationCard and bank details never reach our systems. Checkout sessions are validated against a server-recorded intent before fulfilment, so a session created elsewhere cannot credit an account
Access control — staffLeast privilege on production, individually attributed accounts, multi-factor authentication required
Availability and resilienceManaged, replicated infrastructure; Firestore in the eur3 multi-region; automated point-in-time backups
RestorationDocumented restore procedure; backup rotation of 35 days
LoggingApplication and security events logged and retained for 90 days
Third-party codeNo third-party scripts on authenticated pages; analytics only on marketing pages and only with consent; fonts self-hosted
Secure developmentTypeScript in strict mode, dependency vulnerability scanning, code review before release, automated end-to-end tests over authentication and payment flows
Vendor managementData processing agreements with every sub-processor; annual review
Incident responseDocumented procedure with a 48-hour notification commitment to controllers (section 8.3)

Annex III — Approved sub-processors

The current list, with each one's purpose, location and transfer mechanism, is maintained at /legal/sub-processors and forms part of this Annex. Changes are notified under section 6.