We run a tutoring platform. Most of our users are in the EU; our company is in Canada. Canada holds an EU adequacy decision for data handled under PIPEDA, and we additionally apply the GDPR standards described here to everyone.
Draft — pending review. This document has not been approved and is not binding. It describes how the platform works today and is published here so you can read it; the final version will replace it.
Controller: Differentiate Tutoring Inc., 3398 McKinley Beach Ln. 101, Kelowna BC V1V 0C5, Canada · contact@differentiatetutoring.com
EU representative (Art. 27 GDPR): Gabriel Piñón, Calle Alfredo Marquerie 20, 7b Madrid, M, Spain, 28034
Last updated: 2026-08-15.
We do not sell personal data and we do not run third-party advertising tracking.
Processors bound by data-processing agreements: our hosting and storage (Google Cloud, EU region; Neon Postgres, EU region), payment providers (independent controllers for their own compliance), and email delivery.
Your tutor sees what they need to teach you: your name, school programme and level, your bookings with them, your messages to them, and the homework and recap history you share.
Your linked parent sees your sessions, progress, homework status and balance.
Tax authorities receive tutor data where the law requires (§5).
We are a Canadian company: account operations involve transfer to Canada, covered by the EU adequacy decision for Canadian commercial organizations.
Content and database storage stays in EU regions. Where a processor is in the US, transfers rely on the EU–US Data Privacy Framework or standard contractual clauses.
EU law (DAC7) and Canadian law require platforms like ours to report, annually, each tutor's identity, tax identification number, and the fees they earned through the platform, to the relevant tax authority.
This is a legal obligation under Art. 6(1)(c) GDPR. We collect exactly the data the law lists, and no more.
Account data: while your account exists, then deleted or anonymised within 90 days of closure — except records we must keep. Invoices and accounting records are kept for 10 years under German commercial and tax law where applicable, and 6 years under Canadian tax law. DAC7 reports are kept for their statutory periods.
Messages and session files: while your account exists. Server logs: 90 days.
Access, rectification, erasure, restriction, portability, and objection — from your account, where self-service export and deletion are built in, or by email.
Erasure anonymises records we must keep for tax law rather than breaking them.
You can withdraw any consent with effect for the future.
You may complain to your local data-protection authority; for Germany that is the authority of your state. Under PIPEDA you may complain to the Office of the Privacy Commissioner of Canada.
Passwords are hashed with scrypt; access is role-gated; admin actions are logged; uploads live in access-controlled storage with signed, expiring links; backups are encrypted.
If a breach ever creates a risk to you, we will notify you and the authorities within the statutory deadlines.
We use no analytics, advertising or tracking cookies, and no third-party scripts. What the site stores in your browser is only what it needs to work: the sign-in session and its security token; a preference cookie remembering the timezone you chose while booking (one year); and local storage holding your theme choice, your cart while you book, and whether you have seen the introduction. None of this is used to identify you across other sites, so no consent banner is needed under Art. 5(3) ePrivacy and §25 TDDDG. If that ever changes, we will ask first.
We will announce material changes by email at least 14 days ahead. The current version always lives at /legal/privacy, with its version number at the foot of the page.