Privacy Policy
Version 1.0 · Effective 26 July 2026
Applies to tutors, to parents, guardians, adult learners and students using the Client Portal, and to visitors to tutello.ae.
1. Controller and contact
HCIT DIGITAL AND AI CONSULTING, Economic Licence CN-6345766, Abu Dhabi, United Arab Emirates, operates tutello.ae. Privacy enquiries and data subject requests should be addressed to support@tutello.ae.
No Data Protection Officer has been appointed, none being required by the scale or nature of the processing.
2. Roles
In respect of tutor account data and Portal User account data, the Operator acts as controller.
In respect of personal data entered by a tutor concerning that tutor's clients, the tutor acts as controller and the Operator acts as processor. A parent, guardian, adult learner or student seeking correction or erasure of such data should contact their tutor in the first instance.
3. Categories of personal data processed
Tutor account data: name, email address and profile image obtained from federated sign-in; business name and address where provided; currency, timezone, default rate and cancellation-window settings; subscription status and payment-provider identifiers.
Client personal data entered by tutors: family and contact names; email addresses and telephone numbers; addresses where provided; student names, grade levels, subjects and applicable rates; session dates, durations, statuses and notes; invoices, amounts and payment records.
Portal User data: the email address by which an invitation was accepted, and the association between that account and the relevant tutor, family or student.
Technical data: server logs comprising network address, user agent, timestamp and requested path; short-lived rate-limiting records; authentication cookies; and records of acceptance of the Terms of Service or Portal Terms.
The Operator deploys no analytics, advertising or behavioural tracking technologies.
4. Personal data relating to minors
The Service is used to record tutoring provided to students who may be minors. The Operator does not knowingly collect personal data directly from a child. Student portal accounts exist only where created at a tutor's instruction and are limited to scheduling information and notes marked as shared.
The tutor is responsible for obtaining any parental or guardian consent required for the recording of a minor's personal data.
Client personal data is not used for product analytics, for marketing, or for the training of machine-learning or artificial-intelligence models, in any circumstances.
Where the Operator is notified that a minor's personal data is held without a lawful basis, it shall act with the relevant tutor to procure its erasure.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of the Service and the Client Portal | Performance of a contract |
| Collection of fees and prevention of fraud | Contract; legitimate interests |
| Service communications, including sign-in links, invitations and material notices | Performance of a contract |
| Security, rate limiting and abuse prevention | Legitimate interests |
| Evidence of acceptance of the applicable terms | Legitimate interests; legal obligation |
| Retention of accounting records | Legal obligation |
The Operator does not sell personal data, does not disclose personal data for advertising purposes, and does not use personal data to train artificial-intelligence models.
Any marketing communication shall be sent only with prior consent, which may be withdrawn at any time without affecting service communications.
6. Sub-processors and international transfers
| Sub-processor | Function | Processing location |
|---|---|---|
| Vercel Inc. | Application hosting and serverless execution | European Union (Frankfurt) |
| MongoDB, Inc. (Atlas) | Database hosting | European Union (Frankfurt, eu-central-1) |
| Stripe, Inc. | Payment processing | European Union / United States |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | European Union (Ireland) |
| Google LLC | Federated authentication | United States / global |
Personal data is stored within the European Union. Where a sub-processor transfers personal data outside the European Economic Area or the United Arab Emirates, that transfer is made pursuant to recognised safeguards, including the European Commission's Standard Contractual Clauses.
Changes to this list are published on this page not less than thirty (30) days before the additional sub-processor commences processing.
7. Retention
| Category | Retention period |
|---|---|
| Active account data | Duration of the account |
| Data following account deletion | Erased from production systems within 30 days; from backups within 90 days |
| Accounts in Read-Only Mode | Not less than 12 months, then deletion on 30 days' notice |
| Portal User accounts | Duration of the account; erased on request where no active membership remains |
| Server logs | Up to 90 days |
| Rate-limiting records | Automatically expired within hours |
| Records of acceptance of the applicable terms | Duration of the account plus 5 years |
| Financial records required for accounting | 5 years, as required under UAE law |
8. Rights of data subjects
Data subjects may request access to, rectification of, erasure of, restriction of or objection to the processing of their personal data, and may request its transmission in a structured, commonly used, machine-readable format.
Requests should be sent to support@tutello.ae. The Operator shall respond within thirty (30) days, extendable by a further sixty (60) days for complex requests, in which case the requester shall be notified within the initial period.
The Operator shall take reasonable steps to verify the identity of a requester proportionate to the sensitivity of the data concerned.
Tutors may exercise the right to portability at any time, without making a request, by using the export function within the Service.
Where the Operator acts as processor, requests are referred to the relevant tutor as controller, and the Operator shall assist that tutor in responding.
Data subjects in the European Union or United Kingdom may lodge a complaint with their supervisory authority. Data subjects in the United Arab Emirates may lodge a complaint with the UAE Data Office under Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data.
9. Security
Personal data is encrypted in transit using TLS and at rest by the Operator's hosting providers.
Access control is enforced at the data layer: every request is scoped to the authenticated tutor's own records or, in the case of a Portal User, to the specific family or student to which their membership relates.
Authentication is by federated sign-in or single-use email link. Account passwords are not stored.
Administrative access is limited to the owner of the Operator and is exercised only where necessary to operate the Service or to respond to a support request.
No system is entirely secure. In the event of a personal data breach the Operator shall notify affected data subjects and the competent supervisory authority without undue delay and, where required by applicable law, within seventy-two (72) hours of becoming aware of it.
10. Cookies
11. Amendments
Amendments are published on this page with a revised effective date and version number. Material amendments are notified by email not less than thirty (30) days in advance.