Privacy policy
Version 2026-08-20 · GDPR (EU 2016/679)
Who we are
Tuitzo is a multi-tenant platform for academies, parents, and students. For your login account, Tuitzo is the data controller. For student, attendance, fee, and class records that an academy stores, the academy is the controller and Tuitzo processes that data on the academy’s instructions.
Contact: privacy@tuitzo.com
What we process
Account data (name, email, password hash), family links, staff memberships, enrollments, attendance, fees, leave, invitations, notifications, and audit events. Children’s data is entered by a parent/guardian or by academy staff with a lawful academy relationship — never as an advertising profile.
Lawful bases
- Contract — providing the workspace you registered for.
- Legitimate interests — security, abuse prevention, and product reliability.
- Legal obligation — tax, fee, and audit records academies must keep.
- Consent — privacy policy acceptance at signup; parental authority for child profiles (GDPR Art. 8).
Your rights
You may access, rectify, export, restrict, object, or request erasure of personal data we control, and lodge a complaint with a supervisory authority. When signed in, open Privacy from the sidebar, or email privacy@tuitzo.com.
Erasure cannot remove fee, enrollment, or audit records an academy must retain. We anonymize your identity on those records where we can.
Children
Student profiles for minors are created by a parent/guardian or invited by an academy. We do not use child data for marketing. Platform operators see operational counts, not student dossiers.
Sharing and retention
We do not sell personal data. Hosting, email, and payment processors act as processors under contract. Account data is kept while the account is active. After erasure, anonymized operational records may remain for the academy’s legal retention period.
Security
Access is authorized server-side with academy (tenant) isolation. Passwords are hashed. Sensitive actions are rate-limited and audited.