- LEGAL DOCUMENT
Privacy Policy
Effective Date: 24th January 2026

Your Data Protection
We implement
comprehensive security
measures to safeguard
your information

FERPA & COPPA Compliant
Full compliance with
education privacy laws
across multiple
jurisdictions

Your Rights
Access, correct, or
delete your personal
data at any time
TutorCloud India Private Limited is a company incorporated under the Companies Act, 2013, having its registered office at #31, 4th Floor, Above A2B Restaurant, Hebbal Outer Ring Road, Bengaluru, Karnataka 560094. TutorCloud is a “Data Fiduciary” within the meaning of Section 2(i) of the DPDPA in respect of personal data processed under this Policy.
This Policy applies to:
- Students (of all ages, including K-12 learners and adult learners aged 18 years and above) who use the Services directly or through a School, District, or Institution;
- Parents and legal guardians of Students under the age of 18 who provide verifiable consent under Section 9 of the DPDPA;
- Teachers, tutors, and administrators using the Services for educational delivery;
- Schools, districts, coaching institutes, colleges, universities, and other educational institutions (collectively, “Institutions”) that license the Services under our institutional (B2B2C) offering;
- Visitors to our website and any prospective users, donors, applicants, or business contacts.
This Policy does not apply to personal data processed by third parties whose services or websites you may access through the Services. Please review their respective privacy policies.
Certain Approved Equivalent: A category of data-processing activity approved by the Government of India where standard consent requirements may be modified.
Child: An individual who has not completed eighteen (18) years of age, as defined under Section 2(f) of the DPDPA.
Consent: Free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s wishes, signified by clear affirmative action, as required under Section 6 of the DPDPA.
Consent Manager: A person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent.
Data Fiduciary: TutorCloud India Private Limited, being the person who alone or in conjunction with others determines the purpose and means of processing personal data.
Data Principal: The individual to whom the personal data relates; where the individual is a Child or a person with a disability, this includes their Parent or lawful guardian.
Data Processor: Any person who processes personal data on behalf of a Data Fiduciary.
Institution / School User: A school, district, coaching centre, college, university, or other educational entity that licenses the Services and its authorised users (administrators, teachers, students associated with the Institution).
Parent: A parent or lawful guardian of a Child.
Personal Data: Any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDPA.
Personal Data Breach: Any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction of or loss of access to personal data, that compromises the confidentiality, integrity, or availability of personal data.
Sensitive Personal Data or Information (SPDI): Categories of information defined under Rule 3 of the SPDI Rules, including password, financial information, physical/physiological/mental health condition, sexual orientation, medical records, and biometric information.
Significant Data Fiduciary (SDF): A Data Fiduciary or class of Data Fiduciaries notified as such by the Central Government under Section 10 of the DPDPA.
Services: The TutorCloud.AI website, mobile applications, AI tutor, adaptive learning engine, generative learning content, proctoring features, and all related products, features, and offerings.
We collect the following categories of personal data, subject always to the consent obligations set out in Section 5 below.
3.1 Information you provide directly
- Identity and contact data — full name, username/handle, email address, mobile number, date of birth, gender (optional), country/state, and preferred language.
- Account credentials — password (stored in hashed form), security questions, two-factor authentication tokens.
- Profile data — grade/class, board of education, subjects of interest, learning goals, profile photograph (optional), and biographical details you choose to share.
- Parental/guardian data — for Students under 18, the Parent’s name, relationship to the Student, contact details, and government-issued ID reference (where required for verification of parental consent).
- Learning content and submissions — assignments, essays, code, drawings, quiz answers, voice recordings, and any content you generate or upload.
- Communications — messages sent through in-app chat, support tickets, feedback surveys, and correspondence with our team.
- Payment data — for paid subscriptions, billing name, billing address, GSTIN (if applicable), and last four digits of payment card / masked payment identifiers. Full payment card numbers are collected and processed by our PCI-DSS compliant payment processors and are not stored on our servers.
3.2 Information collected automatically
- Device and technical data — IP address, device type, operating system, browser type and version, unique device identifiers, mobile network information, and time zone.
- Usage data — pages viewed, features used, time spent, clickstream data, session duration, learning progress and performance metrics, error logs, and crash reports.
- Location data — approximate location derived from IP address (city/region level). We do not collect precise GPS location without your explicit consent.
- Cookies and similar technologies — see our Cookie Policy in Part III.
3.3 Information from third parties
- From Institutions — when you access the Services through your school, district, or institution, we may receive rostering data (name, grade, class, teacher assignments, student ID) from your Institution or through single sign-on (SSO), Learning Management System (LMS), Student Information System (SIS), or one-roster integration providers.
- From SSO providers — if you sign in using a third-party identity provider, we receive the profile information you authorise them to share (name, email, profile photo, and unique identifier).
- From payment processors — transaction confirmation, subscription status, and refund status.
- From your Parent or teacher — if a Parent or teacher creates an account on your behalf, they may provide the information listed in Section 3.1.
3.4 AI-generated interaction data
When you interact with our AI tutor, voice-based features, adaptive learning engine, generative content tools, or webcam-enabled engagement/proctoring features, we process the inputs you provide (text prompts, voice recordings, webcam frames where applicable) and the outputs the system returns, along with associated metadata (timestamps, model version, session identifier). See Section 7 for further detail on how AI features process your data.
- Directly from you — when you register, complete your profile, submit content, communicate with us, make a payment, or otherwise interact with the Services.
- Automatically — through cookies, log files, analytics tools, and similar technologies as you navigate and use the Services.
- From your Parent or Institution — where a Parent, teacher, or Institution creates your account, enrols you into a class, or provides supplementary data (e.g., grade, roster).
- From third-party integrations — SSO providers, LMS/SIS/rostering providers, and payment processors, subject to your (or your Institution’s) authorisation.
- From publicly available sources — for verification, fraud prevention, or business development purposes.
In accordance with Sections 4, 5, 6, and 7 of the DPDPA, we process personal data only for the lawful purposes stated below and either on the basis of your consent or, where permitted, on the basis of certain legitimate uses recognised under Section 7 of the DPDPA.
5.1 Purposes of processing
- Providing the Services — Creating and managing your account; delivering learning content; personalising your experience; enabling AI-powered tutoring, adaptive learning, and generative content features.
- Institutional service delivery — Rostering, class management, teacher-student communication, progress reporting to Institutions, gradebook synchronisation, and administrative analytics for Institutions.
- Parental oversight — Facilitating Parent access to a Child’s account, progress, and safety controls.
- Communication — Responding to your queries; sending service notices, security alerts, transactional confirmations, and (where you have opted in) marketing or newsletter communications.
- Safety, security, and abuse prevention — Detecting, investigating and preventing fraud, cheating, harassment, abusive content, security incidents, and breaches of our Terms of Use.
- Payments and billing — Processing subscription payments, invoicing, taxation, refunds, and financial reconciliation.
- Legal and regulatory compliance — Complying with applicable law, court orders, regulator directions, and lawful requests from public authorities.
- Product research and improvement — Analysing aggregated and de-identified usage data to improve the Services, develop new features, and conduct educational research.
- Business operations — Corporate audits, risk management, internal reporting, and (in the event of a merger, acquisition, or reorganisation) transfer of your data to a successor entity subject to equivalent protections.
5.2 Lawful basis
We process personal data under the DPDPA on one or more of the following bases:
- Consent (Section 6, DPDPA) — for most processing activities, we rely on your free, specific, informed, unconditional, and unambiguous consent, obtained through clear affirmative action.
- Verifiable parental consent (Section 9, DPDPA) — for processing personal data of a Child (under 18), we obtain verifiable consent from the Parent before processing.
- Legitimate uses (Section 7, DPDPA) — including where the Data Principal has voluntarily provided personal data for a specific purpose without indicating objection, for compliance with judgment/decree/order of a court or authority, for medical emergency, or for employment-related purposes (as applicable).
- Contractual necessity — where processing is necessary for the performance of a contract to which you are a party (e.g., a paid subscription).
5.3 Consent Notice and Withdrawal
Where processing is based on consent, we present a plain-language notice at or before the point of collection, containing the information required under Section 5 of the DPDPA and Rule 3 of the DPDP Rules 2025. You may withdraw your consent at any time by writing to us at dpo@tutorcloud.in or using the in-app consent-management dashboard. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal, and may impact your ability to use certain parts of the Services.
We also support consent management through Consent Managers registered with the Data Protection Board of India, once such a facility is operational under the DPDP Rules
We adopt the reasonable security practices set out in the SPDI Rules for any Sensitive Personal Data or Information we may collect (for example, financial information for subscription payments). We do not collect biometric data, health information, sexual orientation data, caste, religion, or political opinions of Data Principals as part of the Services, and you should not upload such data to your account or into our AI features.
Where we use webcam-based engagement or proctoring, we process video imagery strictly on an opt-in basis, only during authorised sessions, and only for the disclosed purpose. Recordings, where required by an Institution, are retained under the Institution’s data-processing instructions and are not used to train any AI model.
Our Services include AI-powered features. This section describes how those features work and the protections we apply.
7.1 AI features
- AI tutor / chatbot — text-based conversational tutoring, hint generation, explanation, and Q&A.
- Voice/speech recognition — spoken answers and voice-based practice.
- Adaptive learning and personalisation — recommending content, difficulty, and next-best-action based on your learning trajectory.
- Generative content — producing essays, images, code, feedback and worked solutions as learning aids.
- Video/webcam analysis — proctoring and engagement analytics (opt-in and disclosed at the point of collection).
7.2 Use of third-party Large Language Models (LLMs) and AI APIs
We use third-party AI service providers (including large language model APIs and speech-processing APIs) to power certain AI features. In doing so, we apply the following privacy-by-design safeguards:
- No PII in prompts — we do not transmit your name, email, mobile number, date of birth, account identifier, Institution identifier, physical address, payment details, or other directly identifying personal data to third-party LLM/AI providers. Inputs are stripped, tokenised, or pseudonymised before transmission.
- No training on user data — our contractual arrangements with third-party AI providers expressly prohibit them from using inputs or outputs generated through the Services to train, fine-tune, or improve their generally-available models.
- Zero-retention or short-retention modes — wherever available, we enable zero-retention or short-retention configurations offered by AI providers.
- Contractual protections — all third-party AI providers are engaged under written agreements imposing confidentiality, security, and purpose-limitation obligations equivalent to those required under Section 8 of the DPDPA.
- Human oversight and safety filters — we deploy safety filters, content moderation, and human review mechanisms to reduce hallucination, bias, and harmful output.
7.3 AI limitations and your acknowledgement
AI-generated output is provided as a learning aid and may contain errors, omissions, or outdated information. You should independently verify any factual, mathematical, or citation-related content. AI features are not a substitute for professional advice (medical, legal, financial, psychological, etc.). Do not include personal data, sensitive information, or the personal data of others in your inputs to AI features.
TutorCloud is committed to protecting the personal data of Children. Under Section 9 of the DPDPA, a Child is any individual who has not completed 18 years of age.
8.1 Verifiable Parental Consent
Before processing the personal data of a Child, we obtain verifiable consent from the Child’s Parent or lawful guardian in the manner prescribed under the DPDP Rules. Verifiable consent may be obtained through methods such as government-issued digital identity verification (e.g., DigiLocker), a signed consent form, a Parent-linked email confirmation, a small payment verification, or another Government-recognised method.
8.2 Restrictions on processing Children’s data
- We do not undertake behavioural monitoring or targeted advertising directed at Children.
- We do not process Children’s data in any manner likely to cause detrimental effect on the well-being of the Child.
- We restrict public-facing features (e.g., open profiles, public forums) for Child accounts by default.
- We do not knowingly sell, rent, or trade Children’s personal data.
8.3 School-mediated consent
Where a Child accesses the Services through an Institution as part of the Institution’s educational programme, the Institution acts as the Child’s authorised representative for the purpose of providing certain consents necessary to deliver the educational service, subject to the Institution first obtaining the Parent’s consent as required under applicable education and privacy laws.
When TutorCloud is licensed by an Institution for educational purposes (“Institutional Services”):
- The Institution is the Data Fiduciary in respect of Students enrolled by the Institution; TutorCloud acts as a Data Processor under written instructions from the Institution.
- The processing is governed by our Data Processing Agreement (DPA) with the Institution, in addition to this Policy.
- Rostering, class assignment, progress reports, and administrator dashboards are provided to the Institution and its authorised users (teachers, administrators) only.
- Student personal data collected under the Institutional Services is not used for marketing purposes or for the development of unrelated features.
- Institutional Services are delivered in a manner designed to comply with applicable education laws in India, including the National Education Policy, 2020 and CBSE/State Board rostering guidance where applicable.
10.1 Parental rights
- Access — to view the categories of personal data collected from the Child.
- Correction — to correct or update inaccurate or outdated data.
- Deletion — to request deletion of the Child’s account and personal data (subject to retention obligations under law).
- Withdrawal of consent — to withdraw consent for further processing at any time.
- Complaint — to file a complaint with the Data Protection Board of India.
10.2 Parental responsibilities
- Provide accurate information at the time of granting consent.
- Supervise the Child’s use of the Services in accordance with the Terms of Use.
- Educate the Child about safe online conduct, appropriate use of AI features, and confidentiality of account credentials.
- Notify us promptly if you believe the Child’s account has been compromised or is being used inappropriately.
- Ensure that the Child does not submit personal data (their own or of others), sensitive personal information, or objectionable content into any AI feature.
We do not sell your personal data. We disclose personal data only in the circumstances described below:
- Service providers and processors — cloud hosting, database and storage providers, analytics platforms, communication tools (email, SMS, video), payment processors, customer support tools, and AI/LLM API providers. All such processors are engaged under written contracts imposing confidentiality, security, and purpose-limitation obligations equivalent to those required under Section 8 of the DPDPA.
- Institutions — where you use the Services through your Institution, your personal data is shared with the Institution and its authorised users for the educational purposes described in Section 9.
- Parents/guardians — for Child accounts, we share the Child’s account information, learning activity, and safety-related data with the linked Parent.
- Third-party integrations — SSO, LMS, SIS, rostering, communication, or payment integrations that you or your Institution authorise. Such third parties process your data under their own privacy policies.
- Legal requests — to law enforcement agencies, courts, regulators, or other public authorities where required by law, court order, or regulatory direction, or where necessary to protect the rights, property, or safety of TutorCloud, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, reorganisation, sale of assets, or insolvency, subject to the acquiring party undertaking to honour equivalent privacy protections.
- Aggregated or de-identified data — statistical, aggregated, or de-identified data that cannot reasonably be used to identify you may be shared for research, benchmarking, marketing, or product development.
We host personal data of Indian Data Principals within India. Primary data storage and processing infrastructure for the India Services is located within the territory of India.
In limited circumstances — such as when your data is processed by a third-party AI/LLM provider whose service is delivered from outside India, or for global business support functions — personal data (in pseudonymised form where practicable) may be transferred to jurisdictions outside India. Any such transfer will:
- Comply with Section 16 of the DPDPA and any restrictions notified by the Central Government from time to time (including any list of restricted jurisdictions);
- Be effected under written contracts imposing equivalent protection;
- Exclude, wherever possible, directly identifying personal data.
If the Central Government notifies any jurisdiction as restricted, we will cease transfers to that jurisdiction within the timeframes prescribed.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention criteria are set out below.
| Category | Retention Period |
|---|---|
| Account data (name, email, credentials) | For the duration of your active account plus 90 days after account closure, unless a longer period is required by law. |
| Learning content and progress | For the duration of the account; upon account closure, retained in de-identified/aggregated form for research and product improvement. |
| Payment and tax records | 8 years from the end of the relevant financial year, as required under the Companies Act, 2013 and Income Tax Act, 1961. |
| Institutional data | In accordance with the retention period specified in the DPA with the Institution; typically for the duration of the licence plus 12 months, subject to Institutional deletion instructions. |
| Support tickets and communications | 36 months from the date of resolution. |
| Cookies and analytics logs | As specified in the Cookie Policy (Part III). |
| AI interaction logs | 90 days for operational logs; longer retention (up to 12 months) for safety and abuse investigations. |
| Video/webcam recordings (proctoring) | As instructed by the requesting Institution; typically deleted within 90 days of session completion unless required for dispute resolution. |
Upon expiry of the retention period, we securely delete or irreversibly anonymise the personal data. You may request deletion at any earlier point in accordance with Section 15.
In accordance with Section 8(5) of the DPDPA, Rule 8 of the DPDP Rules, and Rule 8 of the SPDI Rules, we implement reasonable technical, physical, and organisational security measures, including:
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Role-based access control (RBAC), least-privilege access, and multi-factor authentication for administrative access.
- Network segregation, firewalls, intrusion-detection systems, and continuous security monitoring.
- Regular vulnerability assessments, penetration testing, and code reviews.
- Security awareness training for all personnel with access to personal data.
- Documented incident response and breach notification procedures.
- Alignment with ISO/IEC 27001 (ISMS) and ISO/IEC 27701 (PIMS) frameworks.
No system is completely secure. If you believe your account has been compromised, please notify us immediately at dpo@tutorcloud.in.
Sections 11 to 14 of the DPDPA grant you the following rights in respect of your personal data:
- Right to information — obtain a summary of the personal data being processed and processing activities.
- Right to correction and erasure — request correction of inaccurate/misleading data, completion of incomplete data, updating of outdated data, and erasure of personal data no longer necessary for the disclosed purpose.
- Right to grievance redressal — approach our Grievance Officer (see Section 17) with any concern.
- Right to nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent — at any time, with prospective effect.
- Right to file a complaint with the Data Protection Board of India (see Section 17).
15.1 How to exercise your rights
You may exercise your rights by:
- Using the in-app privacy dashboard under Settings > Privacy;
- Writing to our Grievance Officer at the address in Section 17;
- Engaging a registered Consent Manager (once available).
We will respond to your request within thirty (30) days of receipt (or such shorter period as prescribed under the DPDP Rules). We may verify your identity and, in the case of a Child, may require verification of the Parent’s identity before acting on the request.
Our use of cookies, pixels, web beacons, local storage, and similar technologies is described in the Cookie Policy set out in Part III of this document. Where consent is required, we will present a cookie consent interface at your first visit and allow you to update your preferences at any time.
17.1 Grievance Officer
In accordance with Rule 3(11) of the Intermediary Rules and Section 8(9) of the DPDPA, we have appointed a Grievance Officer:
- Name: Nishil Deepak
- Designation: Grievance Officer, TutorCloud India Private Limited
- Email: grievance@tutorcloud.in
- Postal address: #31, 4th Floor, Above A2B Restaurant, Hebbal Outer Ring Road, Bengaluru, Karnataka 560094
- Response commitment: We will acknowledge receipt of your grievance within 48 hours and aim to resolve it within 45 days from the date of receipt.
17.2 Data Protection Officer (DPO)
If we are notified as a Significant Data Fiduciary under Section 10 of the DPDPA, we will appoint a Data Protection Officer whose contact details will be published on the Services. Interim contact: dpo@tutorcloud.in
17.3 Data Protection Board of India
If you are dissatisfied with our response, you may lodge a complaint with the Data Protection Board of India constituted under Section 18 of the DPDPA, once operational, or with the Ministry of Electronics and Information Technology (MeitY) in the interim.
Changes to this Policy and Contact
TutorCloud India Private Limited
#31, 4th Floor, Above A2B Restaurant, Hebbal Outer Ring Road,
Bengaluru, Karnataka 560094
Email: dpo@tutorcloud.in
- LEGAL DOCUMENT
Privacy Policy
Effective Date: 24th January 2026

Your Data Protection
We implement
comprehensive security
measures to safeguard
your information

FERPA & COPPA Compliant
Full compliance with
education privacy laws
across multiple
jurisdictions

Your Rights
Access, correct, or
delete your personal
data at any time
This Privacy Policy (“Policy”) explains how TutorCloud Technology Limited, a free zone entity incorporated in the United Arab Emirates (“UAE”) with trade licence number CL13327, having its registered office at GA-00-SZ-L1-RT-208, Level 1, Gate Avenue, South Zone, DIFC, Dubai. (hereinafter “TutorCloud”, “we”, “us” or “our”), collects, uses, discloses, transfers, retains and otherwise processes Personal Data of individuals who access or use the TutorCloud.AI platform, including the website http://www.tutorcloud.in, our mobile applications, learner and educator dashboards, AI-enabled tutoring tools, institutional consoles and any related digital services (collectively, the “Service”).
This Policy applies to Personal Data processed in the context of Users based in, or accessing the Service from, the United Arab Emirates, including the mainland UAE, the Dubai Internationlal Financial Centre (DIFC) free zone and the Abu Dhabi Global Market (ADGM) free zone, and to institutional customers regulated by the Knowledge and Human Development Authority (KHDA), the Abu Dhabi Department of Education and Knowledge (ADEK), the Sharjah Private Education Authority (SPEA) or any other UAE education regulator.
We process Personal Data as a Controller under Article 1 of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) in respect of Users who register directly with us, and as a Processor when we process Student Personal Data under written instructions from an Institutional Customer (a school, training institute, university, tuition centre or educational agency). Where TutorCloud provides Services to Data Subjects located in the DIFC or ADGM, this Policy is read together with the DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 respectively.
1.1 Legal Framework Applicable to This Policy
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its Executive Regulations.
- Federal Decree-Law No. 44 of 2021 establishing the UAE Data Office.
- Federal Decree-Law No. 34 of 2021 concerning the Combating of Rumours and Cybercrime.
- Federal Law No. 3 of 1987 (Penal Code) and Federal Law No. 15 of 2020 on Consumer Protection.
- Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services.
- Wadeema’s Law (Federal Law No. 3 of 2016) concerning Child Rights.
- Cabinet Resolution No. 21 of 2013 concerning Executive Regulations of Federal Law No. 6 of 2010 on Credit Information (as applicable).
- DIFC Data Protection Law No. 5 of 2020 and DIFC Regulations, where TutorCloud engages Users or Institutional Customers established in the DIFC.
- ADGM Data Protection Regulations 2021, where TutorCloud engages Users or Institutional Customers established in the ADGM.
- KHDA guidance for training institutes and private schools in the Emirate of Dubai; ADEK, SPEA and Ministry of Education (MoE) circulars concerning student data and safeguarding.
- Where TutorCloud transfers Personal Data to or from the European Economic Area or the United Kingdom, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the UK GDPR are applied on a supplementary basis.
1.2 What This Policy Does Not Cover
This Policy does not apply to (i) third-party services, websites or applications accessed through the Service; (ii) offline interactions unrelated to the Service; or (iii) Personal Data processed by an Institutional Customer under its own privacy notice where TutorCloud acts merely as a Processor and the Institutional Customer is the Controller.
In this Policy, capitalised terms have the following meanings unless the context requires otherwise:
| Term | Meaning |
|---|---|
| Personal Data | Any data relating to an identified or identifiable natural person, whether directly or indirectly, in accordance with Article 1 of the UAE PDPL. |
| Sensitive Personal Data | Personal Data revealing a person’s family origins, racial or ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, health data or genetic data, as defined in the UAE PDPL. |
| Data Subject | The natural person to whom the Personal Data relates. |
| User | Any natural person who uses or interacts with the Service, including Learners, Parents, Educators, Institutional Administrators and visitors. |
| Learner | A User who consumes educational content via the Service, whether a Child, minor, or adult learner. |
| Child | For the purposes of this Policy in the UAE, a natural person under the age of 18 years, in line with Wadeema’s Law and relevant education regulator guidance. |
| Parent | A parent, legal guardian or person having parental responsibility for a Child under UAE law. |
| Institutional Customer | A school, training institute, university, KHDA-approved centre, tuition centre or educational agency that licenses the Service. |
| Student Personal Data | Personal Data relating to a Learner processed by TutorCloud on behalf of an Institutional Customer under a data processing agreement. |
| Controller | The natural or legal person who determines the purposes and means of the Processing of Personal Data. |
| Processor | The natural or legal person who processes Personal Data on behalf of the Controller. |
| Processing | Any operation performed on Personal Data, whether automated or otherwise, including collection, storage, use, disclosure, transfer, deletion and destruction. |
| AI-Enabled Features | Features of the Service that use artificial intelligence, machine learning models or large language models to generate, adapt or analyse educational content. |
| Service Providers | Third parties engaged by TutorCloud to provide part of the Service on our behalf, such as hosting, communications, payments, analytics and AI infrastructure. |
We collect Personal Data through the categories set out below. The specific data elements we collect depend on your role (Learner, Parent, Educator, Institutional Administrator, visitor), the features you use and whether your account is provided by an Institutional Customer.
3.1 Account Registration Data
- Full name (or preferred/display name).
- Email address; for Learners under 18, a Parent email address is required.
- Date of birth or age band (to apply age-appropriate settings and consent flows).
- Password (stored in salted, hashed form; never in plain text).
- Country and Emirate of residence; preferred language (English/Arabic).
- Role indicator (Learner, Parent, Educator, Institutional Administrator).
- Where you sign in via a Single Sign-On (“SSO”) provider, the basic profile fields released by that SSO provider (name, email, unique identifier).
3.2 Institutional / School Rostering Data
- Class or grade level, section, subject enrolment.
- Institution-issued Learner identifier or student ID.
- Educator assignments and class rosters, provided by the Institutional Customer or through supported rostering / SSO / interoperability standards.
- Institutional demographic fields (only where the Institutional Customer elects to share these and where lawful).
3.3 Learning Activity and Content Data
- Lessons, assessments and modules accessed; time spent; completion status.
- Answers, essays, projects and other submissions created by the Learner.
- AI tutor chat transcripts and prompts submitted to AI-Enabled Features.
- Voice recordings, transcripts and speech-to-text outputs where you use spoken-answer features.
- Webcam feeds and derived engagement/attention analytics when you use proctoring or engagement features (with prior notice and consent).
- Generated content produced on your behalf by AI-Enabled Features (essays, code, images and study aids).
3.4 Communications and Support Data
- Messages you send to us through in-product chat, email, or support forms.
- Feedback, survey responses and user research participation.
- Recordings or transcripts of scheduled video/voice sessions initiated within the Service, where a session is recorded with prior notice.
3.5 Device, Log and Diagnostic Data
- IP address, general (city/region-level) geolocation, device type, operating system, browser, language settings.
- Session identifiers, referring URLs, timestamps, feature usage events and error logs.
- Approximate location derived from IP for regionalisation and security (we do not collect precise GPS coordinates without additional consent).
3.6 Payment and Subscription Data (Freemium / Institutional Licensing)
- Billing name, billing address and VAT registration number of the paying Institutional Customer.
- Subscription tier, licence quantity, invoicing details and payment status.
- For direct subscribers, payment card metadata handled by our PCI-DSS certified payment processor(s); full card numbers are not stored on TutorCloud systems.
3.7 Cookies and Similar Technologies
We use a limited set of cookies and similar technologies as further described in our Cookie Policy set out in Document 3 of this Legal Pack.
4.1 Directly From You
When you create an account, provide information in your profile, submit content, contact us for support, respond to a survey, or attend an event we organise.
4.2 From an Institutional Customer
When your school, training institute, university or educational agency licenses the Service and provisions accounts on your behalf, they may provide us with rostering data, class information and Institution-issued identifiers through supported rostering standards and single sign-on integrations.
4.3 From a Parent
Where a Parent creates or manages a Child account, they may provide their own Personal Data (as the Parent) and the Child’s Personal Data. The Parent is responsible for ensuring the accuracy of that data.
4.4 Automatically
When you interact with the Service, we automatically collect log, device and usage data via cookies, SDKs and server-side logging as described in Sections 3.5 and 3.7 and the Cookie Policy.
4.5 From Third-Party Service Providers
We may receive limited information from our Service Providers, including SSO providers (verified identity), payment processors (payment status), rostering / interoperability providers (class rosters) and communication tools (message delivery status). We do not receive advertising profiles or third-party marketing data about you.
We use Personal Data only for the purposes described below and only to the extent necessary for those purposes:
- To create, maintain and secure your account and to authenticate you.
- To deliver the Service, personalise learning content and generate adaptive learning pathways.
- To operate AI-Enabled Features, including AI tutor conversations, speech recognition, engagement analytics and content generation (subject to the safeguards described in Section 7).
- To provide reports, analytics and dashboards to Learners, Parents, Educators and Institutional Administrators.
- To communicate with you about your account, subscriptions, service updates, security alerts and support requests.
- To operate billing and payment functions, prevent fraud and collect fees legitimately due.
- To ensure the safety, integrity and security of the Service, including detection and prevention of misuse, abuse, cheating and cyber-security threats.
- To comply with legal, regulatory and educational regulator obligations, including responding to lawful requests from UAE regulators, courts and law enforcement authorities.
- To perform anonymised research and analytics, and to improve the quality and effectiveness of the Service (using de-identified or aggregated data).
- With separate and specific consent, to send you optional marketing communications about new features or educational offerings; you may withdraw consent at any time.
5.1 We Do Not
- Sell your Personal Data to any third party.
- Use Learner data or Student Personal Data to serve behaviourally targeted advertising.
- Build advertising profiles of Learners or Children.
- Share Student Personal Data with third-party advertising or marketing networks.
- Permit our AI/LLM providers to use your inputs, prompts or outputs to train, retrain or fine-tune their foundation models (see Section 7).
Under Articles 4 and 5 of the UAE PDPL (and Article 10 of the DIFC Data Protection Law and Article 6 of the ADGM Data Protection Regulations where applicable), we process Personal Data only where a valid legal basis exists. The relevant legal basis depends on the purpose of Processing:
| Legal Basis | Typical Use Case |
|---|---|
| Consent (PDPL Art. 6) | For optional features (e.g. voice/webcam features, marketing emails, non-essential cookies), Parent consent for Child accounts, and where required by law. |
| Performance of a contract (PDPL Art. 4) | To provide the Service you or your Institutional Customer has requested, including account creation, tuition delivery, dashboards, payments and support. |
| Compliance with a legal obligation (PDPL Art. 4) | To comply with UAE PDPL, tax and accounting laws, KHDA/ADEK/SPEA/MoE regulatory obligations, cyber-security laws and lawful requests from authorities. |
| Protection of the Data Subject’s interests (PDPL Art. 4) | In emergencies affecting the life, health or safety of a Child or User. |
| Public interest / performance of a task carried out in the public interest | When we support Institutional Customers in delivering educational activities of public interest. |
| Legitimate interests (PDPL Art. 4) | For securing the Service, preventing fraud, network integrity and product analytics, where such interests are not overridden by the rights of the Data Subject; for Children, we do not rely on legitimate interests as the sole basis. |
Where TutorCloud acts as a Processor for an Institutional Customer, the Institutional Customer is responsible for identifying the legal basis on which it collects and shares Student Personal Data with TutorCloud, and we process such data strictly under written instructions.
TutorCloud uses AI-Enabled Features to deliver personalised, adaptive and generative learning experiences. Some AI-Enabled Features are powered by third-party large language model (“LLM”) and machine learning APIs (collectively, “LLM Providers”). This Section explains how we protect your Personal Data when AI-Enabled Features are used.
7.1 Our Core Commitments
- We do not send Personal Data or directly identifying information (such as your full name, email, phone number, national ID, Emirates ID, home address or payment details) to LLM Providers in the content of prompts or model inputs.
- Where Learner content must be sent to an LLM Provider (for example, an essay draft submitted for feedback), we strip, redact or pseudonymise directly identifying fields prior to transmission where technically feasible.
- Our contractual agreements with LLM Providers expressly prohibit those providers from using our inputs, outputs, prompts or completions to train, retrain, fine-tune or otherwise improve their foundation or proprietary models.
- LLM Providers are contractually bound to zero-retention, short-retention or abuse-monitoring-only retention configurations, and must comply with confidentiality, security and data protection obligations no less stringent than those in this Policy.
- We assess each LLM Provider through a documented vendor risk assessment before onboarding, and we periodically review that assessment.
7.2 What You Should Not Enter Into AI-Enabled Features
Users must not include sensitive, identifying or confidential information in prompts to AI-Enabled Features, including national identifiers, Emirates ID, passport numbers, credit-card data, home addresses, health information, or any other Sensitive Personal Data relating to themselves or others. We display in-product notices reminding you of this obligation.
7.3 Voice, Speech and Webcam Features
Voice-recognition and webcam-based engagement/proctoring features are always opt-in for Learners aged 18 and over, and require verified Parent consent for Learners under 18. We provide clear notice before recording begins, do not retain raw audio or video beyond the period necessary to generate the derived transcript or analytic, and do not use these inputs for model training.
7.4 Human Oversight and Explainability
Any decision made using AI-Enabled Features that materially affects a Learner (for example, an automated grade, a placement recommendation or a proctoring flag) is subject to human review by an Educator or authorised member of the Institutional Customer’s staff before it is applied. Learners and Parents may request human review under Article 9 of the UAE PDPL (Automated Processing).
TutorCloud is designed for use by Learners across the K-12 spectrum and by adult learners. We take special care in respect of Children (persons under the age of 18 in the UAE).
8.1 Age Bands and Consent Model
- Under 13 years — Only Institutional Accounts (provisioned by a school or KHDA-approved training institute) or accounts created by a verified Parent are permitted. We do not knowingly collect Personal Data directly from a Child under 13 without prior verified Parent or institutional consent.
- 13 to 17 years — Accounts may be created with verified Parent consent or by an Institutional Customer. Additional privacy defaults apply automatically (see Section 8.3).
- 18 years and above — Adult learners may register directly, subject to the Terms of Use.
8.2 How We Verify Parent Consent
Where a Child account is created, we obtain Parent consent through one or more of the following methods before activating the account or enabling optional features: (i) a signed consent form (paper or electronic); (ii) a verified email loop with the Parent; (iii) a payment card transaction or micro-transaction using the Parent’s card; (iv) a video-verified consent step where required; or (v) via the Institutional Customer, which represents that it has obtained the necessary Parent consent under UAE law.
8.3 Default Privacy Protections for Child Accounts
- Public profiles, community posts, direct messaging and social features are disabled by default.
- Behavioural or interest-based advertising is not shown; no advertising cookies are placed.
- Voice, webcam, engagement analytics and geolocation features are disabled by default and require explicit Parent opt-in.
- Chat/AI tutor conversations are automatically monitored for safeguarding signals (self-harm, abuse, bullying) using safety filters, in line with UAE child-protection obligations.
- Learner display names cannot include real names, contact details or personally identifying information; we prompt for pseudonymous display names.
8.4 Parent Rights
Parents may at any time review, correct, download or request deletion of their Child’s Personal Data, refuse further collection, or withdraw consent by contacting dpo.uae@tutorcloud.in. Where the Child account is provisioned by an Institutional Customer, the Parent should contact the Institutional Customer in the first instance; TutorCloud will assist the Institutional Customer in responding.
8.5 Wadeema’s Law Alignment
We align our practices with Federal Law No. 3 of 2016 (Wadeema’s Law) concerning the rights of the child, including duties to protect Children from harmful content, exploitation and abuse. We report suspected abuse or safeguarding concerns to the appropriate UAE authorities where required by law.
When TutorCloud is licensed by an Institutional Customer (a school, training institute, KHDA-approved centre, ADEK/SPEA-regulated school, university, or educational agency), the Institutional Customer is the Controller (or joint Controller) in respect of Student Personal Data, and TutorCloud acts as Processor under a data processing agreement (“DPA”).
9.1 Roles and Responsibilities
- The Institutional Customer determines the purpose and means of processing Student Personal Data and provides written instructions to TutorCloud.
- The Institutional Customer is responsible for obtaining any consents required from Learners, Parents or educators under UAE law and applicable regulator guidance (KHDA, ADEK, SPEA, MoE, DIFC or ADGM authorities).
- TutorCloud processes Student Personal Data solely for the purposes described in the DPA and this Policy, and does not use it for its own commercial purposes, targeted advertising or model training.
9.2 KHDA and Other Regulator Considerations
Where an Institutional Customer is a KHDA-approved training institute in Dubai, a school regulated by ADEK in Abu Dhabi, a school regulated by SPEA in Sharjah, or a private school regulated by the Ministry of Education, TutorCloud will process Student Personal Data in a manner consistent with the applicable regulator’s data-protection, safeguarding and record-keeping expectations, and will support the Institutional Customer’s own compliance obligations upon reasonable request.
9.3 Rostering, SSO and Interoperability
TutorCloud supports industry-standard rostering, single sign-on and learning interoperability protocols to enable Institutional Customers to provision, deprovision and manage accounts. We use these integrations solely to synchronise the minimum data required and we do not use the underlying credentials for any other purpose.
9.4 Educator Access
Educators appointed by the Institutional Customer may access Learner progress data, submissions and analytics limited to their assigned classes. Access is role-based and logged for audit purposes.
Parents play a central role in protecting the privacy and safety of their Children. This Section sets out both the rights that Parents may exercise and the responsibilities that we ask Parents to accept when their Child uses the Service.
10.1 Parental Rights
- Right to be informed about what Personal Data we collect from the Child and how we use it.
- Right to review, correct or update the Child’s Personal Data.
- Right to request deletion, restriction or return of the Child’s Personal Data.
- Right to withdraw consent previously given for optional or enhanced features, at any time.
- Right to receive a copy of the Child’s Personal Data in a structured, commonly used and machine-readable format, where technically feasible.
- Right to lodge a complaint with the UAE Data Office or another competent supervisory authority.
10.2 Parental Responsibilities
- Provide accurate information when creating or approving a Child’s account, and update that information when it changes.
- Supervise the Child’s use of the Service and educate the Child on safe online behaviour, in line with UAE cyber-safety guidance.
- Keep account credentials confidential and not permit unauthorised persons to use the Child’s account.
- Review the Child’s submissions and AI-generated content where appropriate.
- Enable or disable optional features (voice, webcam, engagement analytics, communications) in line with the Parent’s own assessment of appropriateness.
- Report to us any content or interaction that appears to breach UAE laws, this Policy or safeguarding expectations.
10.3 Parent Consent Withdrawal
A Parent may withdraw consent at any time by writing to dpo.uae@tutorcloud.in or using in-product controls. Withdrawal of consent does not affect the lawfulness of Processing carried out prior to withdrawal, and may result in the closure of the Child’s account or the disabling of the affected optional feature.
We disclose Personal Data only in the limited circumstances set out below, and only to recipients who are contractually bound to protect it. We do not sell, rent or trade your Personal Data.
11.1 Categories of Recipients
- Institutional Customers — Learner progress, submissions and analytics are shared with the school, training institute or educational agency that provisioned the Learner account.
- Parents — Learner progress and account information for Learners under 18 are made available to the linked Parent.
- Service Providers — Cloud hosting, storage, database, security, communications, payments, analytics, AI/LLM inference, customer support and email delivery providers.
- Single Sign-On, rostering and learning interoperability providers — Solely to authenticate Users and synchronise class rosters, in the minimum data set required.
- Payment processors — For processing subscription fees and invoicing, where you or your Institutional Customer purchases a paid tier.
- Professional advisors — External auditors, legal counsel, tax advisors and insurers, bound by confidentiality.
- Regulators, courts and law enforcement — When required by UAE law, a court order, a lawful investigation, or where necessary to protect the vital interests, safety or property of any person.
- Business transfers — In connection with a proposed or actual merger, acquisition, reorganisation, financing or sale of assets, subject to appropriate confidentiality and continuity of protection.
11.2 Processor Safeguards
Every Service Provider that processes Personal Data on our behalf is required to (i) sign a written data processing agreement compliant with the UAE PDPL Executive Regulations and, where applicable, GDPR Article 28; (ii) implement appropriate technical and organisational security measures; (iii) process Personal Data only under our documented instructions; (iv) assist us with Data Subject rights requests and breach notifications; and (v) delete or return Personal Data at the end of the engagement.
11.3 Categories, Not Named Third Parties
We publish categories of Service Providers rather than named vendors, because our vendor stack evolves over time. Institutional Customers may request our current sub-processor register under a DPA. Individual Users may request the list of categories of Service Providers that hold their Personal Data by contacting dpo.uae@tutorcloud.in.
TutorCloud operates a data-localisation-by-region posture. This means that Personal Data of UAE Users is primarily hosted on infrastructure located inside the UAE where such infrastructure is available and operationally appropriate, and otherwise in a jurisdiction that offers an adequate level of protection under the UAE PDPL.
- Transfer to a jurisdiction determined by the UAE Data Office to provide an adequate level of protection.
- Transfer subject to Standard Contractual Clauses or equivalent contractual safeguards approved for the purpose.
- Explicit and informed consent of the Data Subject, where legally permitted.
- Transfer necessary for the performance of a contract with the Data Subject, or in the vital interests of the Data Subject where consent cannot be obtained in time.
- Transfer necessary for the establishment, exercise or defence of legal claims, or for the operation of a legal or judicial process.
12.2 DIFC / ADGM Transfers
Where data is transferred from a DIFC or ADGM establishment, we apply the transfer mechanisms set out in the DIFC Data Protection Law No. 5 of 2020 (Articles 26 to 28) or the ADGM Data Protection Regulations 2021 (Section 41), including the use of Standard Contractual Clauses issued by the DIFC Commissioner of Data Protection or the ADGM Office of Data Protection as applicable.
12.3 Transfer Impact Assessments
For material onward transfers, we conduct a transfer impact assessment that considers the legal regime of the destination jurisdiction, the sensitivity of the data, the volume of transfer, the security posture of the recipient, and any supplementary technical or organisational measures (such as end-to-end encryption or pseudonymisation) that we apply.
We retain Personal Data only for as long as necessary to fulfil the purposes described in this Policy, comply with our legal, tax and regulatory obligations, defend legal claims, and support the legitimate operations of the Service.
13.1 Retention Principles
- Account data — Retained while the account is active, and for a reasonable period after closure to allow account restoration and to resolve disputes.
- Learning activity and submissions — Retained while linked to an active Learner account; may be retained longer if required by the Institutional Customer or by law.
- AI-tutor transcripts and prompt/response pairs — Retained for a limited operational period (typically no longer than 12 months), and then deleted or de-identified unless a longer period is required to investigate safety, abuse or legal matters.
- Payment and invoicing records — Retained for the minimum period required under UAE Federal Decree-Law No. 47 of 2022 on the Taxation of Corporations and Businesses and applicable tax and accounting laws (generally 7 years).
- Security, audit and access logs — Retained for a reasonable rolling window (typically 12 months) to support security investigations.
- Marketing preferences — Retained until you withdraw consent or the underlying record is deleted.
13.2 Deletion Requests
You may request deletion of your Personal Data at any time under Article 15 of the UAE PDPL. We will action verified deletion requests without undue delay, subject to lawful grounds for retention. Where the account is provisioned by an Institutional Customer, we will route the request to the Institutional Customer and support their response.
13.3 De-identified and Aggregated Data
We may retain and use de-identified, anonymised or aggregated data indefinitely for research, product improvement and impact measurement, provided such data cannot reasonably be used to re-identify any individual.
We implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in line with Article 20 of the UAE PDPL and international good practice (including ISO/IEC 27001, ISO/IEC 27701 and SOC 2 Type II control frameworks).
14.1 Technical Measures
- Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Role-based access control, least-privilege principles and multi-factor authentication for administrators.
- Network segmentation, web application firewalls and DDoS protection.
- Continuous vulnerability scanning, penetration testing and secure development lifecycle practices.
- Endpoint security, mobile device management and hardened production images.
- Secure key management and regular rotation of cryptographic keys.
- Logging, monitoring and security event detection with 24/7 alerting.
14.2 Organisational Measures
- Written information security policies, reviewed annually.
- Mandatory security and privacy training for all personnel, with role-based training for engineers, educators and support staff.
- Background checks for personnel with access to Personal Data, where lawful.
- Vendor risk management including due diligence, data processing agreements and periodic re-assessment.
- Incident response plan and business continuity / disaster recovery plans, tested at least annually.
- Data protection impact assessments for high-risk Processing activities.
14.3 Personal Data Breach Notification
If a Personal Data breach occurs that is likely to result in a risk to the rights and freedoms of Data Subjects, we will notify the UAE Data Office (and any other competent supervisory authority) without undue delay and, where feasible, within the timeframe specified by the UAE PDPL Executive Regulations. Where the breach is likely to result in a high risk, we will also notify affected Data Subjects and, where applicable, Institutional Customers, providing information necessary to help them mitigate potential harm.
Subject to the UAE PDPL and other applicable data-protection laws, you have the following rights in relation to your Personal Data:
| Right | Description |
|---|---|
| Right to information | To receive clear information about how we process your Personal Data (fulfilled by this Policy). |
| Right of access | To obtain confirmation of whether we process your Personal Data and to receive a copy of that data. |
| Right of rectification | To correct inaccurate Personal Data and complete incomplete Personal Data. |
| Right of erasure | To request deletion of your Personal Data where the legal grounds set out in the UAE PDPL apply. |
| Right to restrict Processing | To restrict Processing in defined circumstances (for example, while accuracy is being verified). |
| Right to data portability | To receive your Personal Data in a structured, commonly used, machine-readable format, and to transmit it to another Controller, where technically feasible. |
| Right to object | To object to Processing based on legitimate interests or for direct marketing purposes. |
| Right not to be subject to solely automated decisions | To request human intervention in respect of decisions produced solely by automated Processing, including profiling, that materially affect you. |
| Right to withdraw consent | To withdraw any consent you have given, without affecting the lawfulness of prior Processing. |
| Right to lodge a complaint | To lodge a complaint with the UAE Data Office or (as applicable) the DIFC Commissioner of Data Protection or the ADGM Office of Data Protection. |
15.1 How to Exercise Your Rights
To exercise any of these rights, please write to dpo.uae@tutorcloud.in. We may need to verify your identity before actioning your request. Where your account was provisioned by an Institutional Customer, we may direct your request to that Institutional Customer and support their response. We will respond within the timeframe required by the UAE PDPL (generally without undue delay and no later than 30 days, extendable in complex cases).
15.2 No Discrimination
We will not discriminate against you for exercising any of your data-protection rights. Exercising a right will not affect the price or quality of the Service you receive.
We use a minimal set of cookies and similar technologies for essential functionality, security, preferences and limited analytics. Please refer to the Cookie Policy in Document 3 of this Legal Pack for full details.
If you believe your rights under this Policy or under applicable data-protection law have been infringed, please contact us first at dpo@tutorcloud.in so that we can attempt to resolve the matter promptly.
If you remain dissatisfied, you may lodge a complaint with the competent supervisory authority:
- UAE Data Office (Federal): https://www.tdra.gov.ae / https://u.ae — for complaints under the UAE PDPL.
- DIFC Commissioner of Data Protection: https://www.difc.ae/business/operating/data-protection — for Personal Data processed in the DIFC.
- ADGM Office of Data Protection: https://www.adgm.com/operating-in-adgm/office-of-data-protection — for Personal Data processed in the ADGM.
- Telecommunications and Digital Government Regulatory Authority (TDRA) — for concerns relating to electronic communications and cyber-safety.
- Where you are a Learner or Parent of a KHDA-, ADEK-, SPEA- or MoE-regulated institution, you may also raise a complaint with the applicable education regulator.
We may update this Policy from time to time to reflect changes in law, regulatory guidance, our services or best practices. Any updated version will be posted on the Service with a new effective date. Where the changes are material — in particular, if they broaden the categories of Personal Data collected or the purposes of Processing — we will notify you in advance through in-product notice, email or Institutional Customer notification, and where required by law we will seek renewed consent.
We will not make material changes to our handling of Student Personal Data or Child Personal Data without providing prior notice to the applicable Institutional Customer or Parent and, where required by law, obtaining fresh consent.
Changes to this Policy and Contact
TutorCloud Technology Limited
Address: GA-00-SZ-L1-RT-208, Level 1, Gate Avenue, South Zone, DIFC, Dubai.
Email: dpo@tutorcloud.in
General Support: support@tutorcloud.in
- LEGAL DOCUMENT
Privacy Policy
Effective Date: 24th January 2026

Your Data Protection
We implement
comprehensive security
measures to safeguard
your information

FERPA & COPPA Compliant
Full compliance with
education privacy laws
across multiple
jurisdictions

Your Rights
Access, correct, or
delete your personal
data at any time
This Privacy Policy explains how TutorCloud Australia Pty Ltd (ACN [ACN NUMBER]) and TutorCloud NZ Limited (NZBN [NZBN NUMBER]) (together, “TutorCloud”, “we”, “us” or “our”) collect, hold, use, disclose, store, secure and destroy personal information when you access or use the TutorCloud.AI website located at http://www.tutorcloud.in (and any regional or country subdomain served to Australian or New Zealand users), our mobile and tablet applications, and the AI-enabled learning, tutoring, assessment, content-generation and administrative services made available through them (collectively, the “Service”).
This Policy applies to all users of the Service whose personal information is subject to the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), or the Privacy Act 2020 (NZ) and the 13 Information Privacy Principles (IPPs), including learners (students), parents and legal guardians, teachers, school administrators, institutional partners, subscribers, visitors and prospective users.
Where the Service is provided to a school, school system, higher-education provider, tutoring centre, corporate learning function or other institution (each an “Institution”) under a written agreement, the Institution acts as the entity responsible for its student, staff and administrator records, and this Policy applies alongside that agreement. If there is any conflict between this Policy and a signed Institutional agreement (including any Data Processing Agreement or Data Sharing Agreement), the Institutional agreement prevails in respect of that Institution’s users.
This Policy is written to be read together with our Terms of Use and Cookie Policy. Capitalised terms not defined here have the meanings given in the Terms of Use.
- “Personal information” / “personal data” — information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether recorded in a material form or not (consistent with s6 Privacy Act 1988 (Cth) and s7 Privacy Act 2020 (NZ)).
- “Sensitive information” — information about racial or ethnic origin, political opinions or associations, religious beliefs or affiliations, philosophical beliefs, professional or trade association or trade union membership, sexual orientation or practices, criminal record, health information, genetic information, or biometric information/biometric templates.
- “Child” or “minor” — an individual under the age of 18. Additional protections apply to individuals under 16, and further-elevated protections apply to individuals under 13.
- “Parent” — a parent, legal guardian or person with lawful parental responsibility for a minor.
- “Institution” — any school, kura, early learning service, higher-education provider, tutoring provider, training organisation, corporate learning function or similar entity that has contracted with TutorCloud to provide the Service to its learners or staff.
- “AI-Enabled Feature” — any feature of the Service that uses artificial intelligence, machine learning, large language models (LLMs), speech-to-text, generative content or automated analytics, whether operated by TutorCloud or by a contracted AI/LLM provider on our behalf.
- “NDB scheme” — the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
- “OAIC” — the Office of the Australian Information Commissioner.
- “OPC” — the Office of the Privacy Commissioner (New Zealand).
We collect personal information reasonably necessary for one or more of our functions and activities. The categories we may collect are:
3.1 Account and Identity Information
- Full name, preferred name or display name, and (for learners) date of birth or year of birth used to determine age band.
- Email address, and (optionally) a mobile telephone number for account recovery and multi-factor authentication.
- Login credentials, password hashes, and Single Sign-On (SSO) identifiers issued by an authentication provider.
- Country, state/territory or region, time zone, and preferred language.
- Role type: learner, parent/guardian, teacher, school administrator or Institution administrator.
3.2 Institution and Roster Information
- School, kura or Institution name, campus, classroom, year level, class code and enrolment status.
- Rostering identifiers provided by the Institution or by an interoperability standard used to synchronise class rosters and course enrolments.
- Teacher-of-record and cohort assignments used to deliver the Service to the correct learners.
3.3 Learning Content and Activity Information
- Answers, submissions, drafts, essays, written work, coding submissions and other content you create using the Service.
- Interaction logs: pages viewed, features used, exercises attempted, hints requested, time-on-task, session duration and progression signals.
- Assessment scores, mastery states, competency indicators, personalisation states and learning-plan positions.
- Feedback, ratings, help-desk enquiries and free-text responses you submit to us.
3.4 AI Interaction Data
- Text prompts submitted to AI tutor / chatbot features, generative writing/coding features and adaptive-learning engines.
- Voice recordings and speech-to-text transcripts where you choose to use speech-based features.
- Webcam frames and derived engagement/attention signals where you (or a supervising Parent or Institution) have explicitly enabled camera-based proctoring or engagement features.
- Model outputs generated in response to your inputs and any user ratings applied to those outputs.
3.5 Payment and Subscription Information
- Billing name, billing address, invoice references and the type of plan you hold (Freemium or Institutional Licence).
- Payment-instrument tokens (masked card metadata such as last-four digits and card scheme) returned to us by our payment processors. We do not store full card numbers or CVV codes on our own infrastructure.
3.6 Device, Log and Technical Information
- Device identifiers, device model, operating system and version, browser type and version.
- Approximate location derived from IP address (city/region level).
- Diagnostic logs, crash reports, performance telemetry and error stack traces.
- Cookies and similar technologies (see Section 16 and the Cookie Policy).
3.7 Communications Information
- Records of messages, tickets and enquiries you send to us, including via email, in-product messaging, phone or video conferencing.
- Where you consent, records of webinars, live-tutoring sessions or class recordings hosted through the Service.
3.8 Sensitive Information (limited)
We do not solicit sensitive information as part of ordinary use of the Service. Where you or an Institution voluntarily provides sensitive information (for example, an accessibility accommodation, a health flag disclosed by a Parent, or a religious/cultural observance) we collect and use it only for the purpose disclosed at the time of collection, and only where we have your consent or another lawful basis under APP 3 or IPP 1–4.
- Directly from you when you register, log in, create content, complete forms, communicate with us or use features of the Service.
- From your Parent, where the Parent creates or manages a Child account on your behalf.
- From your Institution, where your account is provisioned or rostered by a teacher or Institution administrator.
- From authentication providers (Single Sign-On), rostering providers and interoperability standards you (or your Institution) use to log in or synchronise class data.
- Automatically, through cookies, SDKs, log files, telemetry and analytics as you use the Service.
- From payment processors, in the limited form described in Section 3.5.
- From publicly available sources, where relevant for institutional due-diligence, verification or safety investigations.
Where it is reasonable and practicable to do so, we collect personal information about you only from you. Where we collect information from a third party (such as a Parent, a school administrator, or a rostering provider), we take reasonable steps to ensure that you are aware of the matters listed in APP 5 / IPP 3, including the fact and circumstances of collection, the purposes of collection, and the consequences (if any) of not providing the information.
We use personal information only for the primary purposes for which it was collected, and for related secondary purposes that you would reasonably expect. Those purposes include:
- Providing, operating, maintaining and improving the Service, including AI-Enabled Features, adaptive learning, assessment, tutoring, content generation and reporting.
- Creating and managing your account, authenticating you, and enabling account recovery.
- Personalising your learning experience — recommending content, adjusting difficulty, generating hints and feedback.
- Delivering reports, dashboards and analytics to you, your Parent, your teacher or your Institution (as applicable to the account type).
- Communicating with you about your account, service changes, security notices and support enquiries.
- Sending, subject to your preferences and applicable law, product update emails, educational newsletters and, where lawful, direct-marketing communications from which you may opt out at any time.
- Processing payments and administering subscriptions and institutional licences.
- Detecting, investigating and preventing fraud, abuse, harmful content, cheating, security incidents and violations of our Terms of Use.
- Meeting our legal, regulatory, tax, audit and reporting obligations in Australia, New Zealand and, where relevant, in other jurisdictions in which we operate.
- Producing de-identified, aggregated or anonymised information for research, product development, benchmarking and publication of learning-outcomes insights.
Australian privacy law does not require a specific “lawful basis” in the GDPR sense, but requires that our collection is reasonably necessary for our functions and activities and (for sensitive information) that we obtain your consent under APP 3.3. Where we operate outside AU/NZ, or where users from other jurisdictions access the Service, we rely on the following legal bases as applicable:
- Performance of a contract with you or with your Institution.
- Your consent (which you may withdraw at any time; withdrawal does not affect prior lawful processing).
- Your Parent’s consent, where you are a Child.
- Compliance with a legal obligation to which we are subject.
- Our legitimate interests (or those of the Institution) in operating and improving the Service, where those interests are not overridden by your rights and interests.
- The vital interests of you or another individual, where safety is at stake.
TutorCloud uses AI-Enabled Features, including AI tutor/chatbot conversations, adaptive learning and personalisation engines, voice/speech recognition of spoken answers, generative content (essays, images, code) and (where enabled) video/webcam analysis for engagement or proctoring. Some of these features are powered by third-party large language model (LLM) providers under commercial agreements with TutorCloud.
7.1 Our Core AI Privacy Commitments
- We do not transmit directly identifying personal information (such as full name, email address, phone number, home address, government identifiers or payment details) to third-party LLM providers as part of AI inputs. Prompts are constructed using pseudonymised identifiers and, where practicable, learning content stripped of direct identifiers.
- Our written agreements with LLM/AI providers expressly prohibit those providers from using inputs, outputs or interaction data submitted by TutorCloud to train, fine-tune, retrain or improve their foundation models.
- AI-Enabled Features are not intended to be used to make solely automated decisions that produce legal or similarly significant effects on any learner. Grades, disciplinary outcomes, admission decisions and other consequential judgements remain the responsibility of the human educator or Institution.
- AI-generated content may contain inaccuracies, omissions or biases. Learners, Parents and teachers are advised not to rely on AI outputs as authoritative and to verify important information independently.
- Where you submit sensitive information into an AI input (for example, disclosing a health condition or personal circumstance), you are advised not to do so; we filter and moderate inputs where we can, but cannot guarantee the exclusion of every free-text submission.
7.2 Camera-Based and Voice-Based Features
Camera-based features (proctoring, engagement analytics) and voice-based features (speech-to-text, spoken-answer assessment) are off by default and require an affirmative act to enable. For learners under 18, only a Parent or an authorised Institution may enable such features on that learner’s behalf. Video and voice data used in these features is retained only for as long as needed to serve the feature and is not shared with third-party LLM providers for training.
Protecting children online is a foundational commitment of TutorCloud. We treat any learner under 18 as a “minor” and apply enhanced protections that scale with age band.
8.1 Age Bands and Consent Requirements
- Under 13: A Parent must create the account or, where an Institution rosters the Child under a lawful school-based use case, the Institution provides consent on the Parent’s behalf in its capacity as the responsible educational body. We do not knowingly permit direct account self-creation by children under 13 outside an Institutional setting.
- 13 to 15 inclusive: We require Parent involvement in account creation or, at a minimum, a Parent notification and acknowledgement. Additional data-minimisation controls apply.
- 16 to 17 inclusive: The learner may create an account with age-appropriate defaults; certain features (payment, sharing, marketing) remain restricted until the user turns 18.
- 18 and over: Full account capabilities are available, subject to the Terms of Use.
8.2 Enhanced Protections for Minors
- No behavioural or targeted advertising to any user we know or reasonably suspect is under 18.
- No sale of personal information about a minor (we do not sell personal information at all — see Section 11.5).
- Public-posting features are disabled by default for minors; where a Parent or Institution enables them, we apply content moderation and reporting tools.
- Data-minimisation defaults: we collect only what is reasonably necessary to provide the learning experience appropriate to the age band.
- Simplified, age-appropriate privacy notices are surfaced in-product for minor learners.
8.3 Alignment with Regional Frameworks
- In Australia, we apply the OAIC’s guidance on the handling of children’s personal information and align with the eSafety Commissioner’s expectations under the Online Safety Act 2021 (Cth), including the Basic Online Safety Expectations and any industry codes applicable to us.
- In New Zealand, we align with the Privacy Commissioner’s guidance on children and young people, and with the New Zealand Ministry of Education’s guidance and Netsafe’s guidance for digital services used in schools.
- Where our Service is used in an Australian or New Zealand school setting, the Institution acts as the primary data steward and we support the Institution’s compliance with its statutory duties.
When the Service is used under an Institutional relationship, the Institution is the primary body responsible for the collection and use of student personal information. TutorCloud handles that information under the direction of the Institution and in accordance with our Institutional Agreement, this Privacy Policy and applicable law.
9.1 Roles and Responsibilities
- The Institution determines the classes, cohorts and users to be enrolled on the Service, the features to be enabled, and the retention arrangements at the end of the enrolment.
- TutorCloud acts as the service provider and processes personal information for the Institution’s authorised educational purposes — namely, delivery of learning content, tutoring, assessment, analytics and administration.
- Institution administrators may, subject to the Institutional Agreement, view, correct, export or request deletion of the personal information of learners in their scope.
9.2 Australian Education Sector Alignment
- We support Australian schools and school systems in meeting their obligations under state and territory education-privacy frameworks, including but not limited to the NSW Privacy and Personal Information Protection Act 1998, the Victorian Privacy and Data Protection Act 2014 and the Victorian Schools’ Privacy Policy, the Queensland Information Privacy Act 2009, and equivalent frameworks in the ACT, SA, WA, TAS and NT.
- For higher-education providers, we support compliance with the Higher Education Standards Framework and applicable TEQSA guidance.
- For registered training organisations, we support compliance with the Standards for RTOs.
9.3 New Zealand Education Sector Alignment
- We support state schools, kura, integrated schools, private schools, early learning services and tertiary providers in meeting their obligations under the Privacy Act 2020, the Education and Training Act 2020 and applicable Ministry of Education guidance.
- We align with the New Zealand Digital Technologies Safe and Responsible Use framework and, where a school elects to participate, Netsafe’s schools programme requirements.
9.4 No Change of Purpose Without Notice
We do not materially change the purposes for which student personal information is used without first notifying the Institution and providing an opportunity to object or discontinue use before that change takes effect.
This section applies where you are a Parent of a learner who uses the Service. It applies to both AU and NZ Parents, subject to any specific rights that vary by jurisdiction (highlighted where relevant).
10.1 Parental Rights
- Give, refuse or withdraw consent for TutorCloud’s collection and use of your Child’s personal information (where consent is the applicable basis).
- Review the categories and, on request, the specific items of personal information we hold about your Child.
- Request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading personal information.
- Request deletion or de-identification of your Child’s account and personal information, subject to any Institutional retention requirement or legal exception.
- Restrict the features available to your Child (for example, disabling AI-tutor features, disabling voice or camera features, or disabling any peer-to-peer interactivity).
- Direct any questions or complaints to our Privacy Officer using the contact details in Section 17.
- Lodge a complaint with the OAIC (for Australian Parents) or the OPC (for New Zealand Parents) — see Section 17.
10.2 Parental Responsibilities
- Confirm you have lawful parental responsibility for the Child before enabling or approving the Child’s account.
- Supervise your Child’s use of the Service in a manner appropriate to their age and maturity.
- Help your Child understand the importance of not sharing personal information (their full name, address, phone number, financial details, images) with AI features, chatbots or third parties.
- Verify AI-generated content and outputs for accuracy before relying on them.
- Keep login credentials confidential and notify us immediately if you suspect unauthorised access to the Child’s account.
- Report any safety, welfare or content-moderation concerns to us using the contact channels published in-product.
We disclose personal information only for the purposes described in this Policy, and only to the following categories of recipient:
11.1 Within TutorCloud
Our staff, contractors and personnel need access to personal information to operate the Service. Access is granted on a least-privilege, need-to-know basis and is auditable.
11.2 With Your Institution
Where you are enrolled through an Institution, we share your account, activity and learning-progress data with authorised Institution staff (typically your teacher and Institution administrators). Learning content and communications you produce as part of coursework may be visible to your teacher.
11.3 With Parents
Where you are a minor, your Parent has access to summary account activity, progress reports and safety notifications. The scope of Parental visibility is described in the Parent Dashboard.
11.4 With Service Providers (Processors)
We engage a limited set of service providers to help us operate the Service. These providers are contractually bound to protect personal information and use it only on our instructions. Categories include:
- Cloud infrastructure and hosting providers (with data residency in Australia or New Zealand for AU/NZ user data).
- Authentication and Single Sign-On providers.
- Rostering, roster-synchronisation and Learning Management System interoperability providers.
- Payment processors.
- Transactional communications providers (email, SMS, in-app messaging, video-conferencing).
- Third-party artificial intelligence / large language model providers (bound by the restrictions in Section 7).
- Marketing and advertising delivery providers, only in respect of adult, non-Institutional users who have consented to such communications.
- Security, fraud detection, abuse monitoring and incident response providers.
- Professional advisers (auditors, insurers, lawyers) under duties of confidence.
11.5 We Do Not Sell Personal Information
TutorCloud does not sell personal information to third parties. We do not disclose personal information about learners for third-party advertising or profiling. We do not permit third-party advertising networks to track learners within the Service.
11.6 Legal and Safety Disclosures
We may disclose personal information where required or permitted by law, including:
- In response to a lawful, valid court order, warrant, subpoena or regulator direction.
- To Australian or New Zealand law-enforcement agencies acting under a lawful authority.
- To the OAIC, OPC, eSafety Commissioner or other regulator with jurisdiction over us.
- Where we reasonably believe disclosure is necessary to prevent or lessen a serious threat to the life, health or safety of any individual, or to public health or safety (consistent with APP 6 and IPP 11).
- In connection with mandatory child-safety reporting obligations that apply to us in a particular jurisdiction.
11.7 Business Transactions
If TutorCloud is involved in a merger, acquisition, restructure, asset sale, insolvency or similar transaction, personal information may be transferred as part of that transaction. The recipient will be required to honour the commitments in this Privacy Policy.
TutorCloud has designed the AU/NZ region of the Service to keep personal information about AU/NZ users within Australia or New Zealand for primary storage and processing. Specifically:
- Primary storage: Personal information about Australian users is stored in Australia. Personal information about New Zealand users is stored in Australia or New Zealand as configured by the applicable Institutional Agreement.
- Cross-border processing: We may, from time to time, engage service providers outside Australia and New Zealand for narrowly-scoped functions (e.g. product engineering support, global customer support outside AU/NZ business hours, LLM inference for AI-Enabled Features).
- Safeguards under APP 8 and IPP 12: Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs (in the case of AU data) or that the recipient is subject to comparable privacy safeguards (in the case of NZ data). We rely on contractual protections, technical safeguards (encryption in transit and at rest, key management) and vendor due-diligence assessments.
- Accountability: If an overseas service provider mishandles personal information about an Australian user, TutorCloud remains accountable under APP 8.1.
- Countries: The countries to which personal information may be disclosed are listed and kept up-to-date in our “Sub-processors” schedule, available on request from privacy-anz@tutorcloud.in.
We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law.
- Account data: For as long as the account is active. If an account is inactive for [24 MONTHS], we will contact the account holder and, absent a valid reason to retain, close and delete the account.
- Learning and assessment data: For the duration of the learner’s enrolment with an Institution (Institution-directed accounts) or the term of the subscription (Freemium/adult accounts), plus a reasonable archival period for grade appeals, audits and dispute resolution.
- AI interaction data: Prompts, transcripts, generative outputs and interaction metadata are retained for [12 MONTHS] by default, unless a longer or shorter period is agreed with the Institution.
- Voice and video data: Retained only for the duration required to deliver the feature, and in any event deleted within [30 DAYS] of the session unless expressly retained for a documented educational purpose.
- Payment records: Retained for the period required by tax, accounting and financial-services legislation in Australia and New Zealand (typically 7 years).
- Communications records: Retained for [24 MONTHS] from the date of last correspondence, unless required for legal, audit or safety purposes.
- Backups: Encrypted backups may retain personal information for up to [90 DAYS] after deletion from the primary systems.
When we no longer need personal information for any lawful purpose, we securely delete it or de-identify it in a manner consistent with OAIC and OPC guidance. De-identified data may be retained indefinitely for research, product improvement and impact reporting.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our safeguards include:
- Encryption of personal information in transit (using industry-standard TLS) and at rest.
- Role-based access controls, least-privilege access, mandatory multi-factor authentication for personnel with access to production data.
- Segregation of production, staging and development environments.
- Continuous logging, monitoring and threat detection.
- Regular vulnerability scanning, penetration testing and third-party security assessments.
- Documented incident-response procedures aligned with the NDB scheme and the NZ Privacy Act 2020 notifiable-privacy-breach obligations.
- Personnel training in privacy, security and safe handling of student data.
- Security expectations flowed through in written contracts to all sub-processors.
14.1 Notifiable Data Breaches (Australia) and Notifiable Privacy Breaches (New Zealand)
- If we form the reasonable belief that there has been an eligible data breach under Part IIIC of the Privacy Act 1988 (Cth), we will notify the OAIC and affected Australian individuals as soon as practicable, in accordance with the NDB scheme.
- If we form the reasonable belief that there has been a notifiable privacy breach under Part 6 of the Privacy Act 2020 (NZ) (i.e. one that is likely to cause serious harm), we will notify the OPC and affected New Zealand individuals as soon as practicable.
- Where a breach relates to an Institution’s data, we will notify the Institution without undue delay and support the Institution’s own notification obligations.
Subject to applicable law, you have the following rights in respect of personal information we hold about you:
- Access: Request confirmation of whether we hold personal information about you and a copy of that information, in a commonly used electronic form.
- Correction: Request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant or misleading.
- Deletion: Request deletion (or, where deletion is not possible, de-identification) of personal information, subject to legitimate retention grounds.
- Restriction: Request that certain features be disabled for your account (for example, AI-Enabled Features, voice/camera features, or optional communications).
- Objection to direct marketing: Opt out of direct marketing at any time, at no cost.
- Data portability: Request an export of your personal information in a structured, commonly used, machine-readable format where technically feasible.
- Withdraw consent: Where processing is based on your consent, withdraw that consent at any time (without prejudice to prior lawful processing).
- Complain: Lodge a complaint with us and, if unresolved, escalate to the OAIC or OPC.
To exercise any of these rights, contact our Privacy Officer at privacy-anz@tutorcloud.in. We will verify your identity (proportionate to the sensitivity of the request) and respond within 30 calendar days. Where a request is complex or numerous, we may extend the response window and will notify you of the extension. We do not charge a fee for reasonable requests.
Where the Service is provided through an Institution, you may need to direct certain requests (particularly access, correction and deletion of learning records) to the Institution, which is the primary data steward for that content. We will assist the Institution in fulfilling your request.
We use a small number of cookies and similar technologies to operate the Service, remember your preferences and understand aggregate usage. Full details of the cookie categories, the choices available to you, and how to manage them are set out in our Cookie Policy (Document 3 in this pack). We do not use third-party advertising cookies to track learners, and we do not permit behavioural advertising cookies to operate for accounts we know or reasonably suspect are used by minors.
If you believe we have breached this Policy, the Privacy Act 1988 (Cth), the APPs, the Privacy Act 2020 (NZ) or the IPPs, please contact our Privacy Officer:
Privacy Officer, TutorCloud AU/NZ
Email: privacy-anz@tutorcloud.in
Post (AU): [PO BOX / STREET ADDRESS], Australia
Post (NZ): [PO BOX / STREET ADDRESS], New Zealand
We will acknowledge your complaint within 5 business days and provide a substantive response within 30 calendar days. If you are not satisfied with our response, you may escalate:
- In Australia: Office of the Australian Information Commissioner (OAIC) — http://www.oaic.gov.au — 1300 363 992.
- In New Zealand: Office of the Privacy Commissioner (OPC) — http://www.privacy.org.nz — 0800 803 909.
- For online safety concerns (including for children): Australian eSafety Commissioner — http://www.esafety.gov.au; NZ Netsafe — http://www.netsafe.org.nz.
Changes to This Policy; Effective Date; Contact
This Policy is effective on 24 January 2026. The version referenced by this document is 1.0.
General privacy contact:
TutorCloud Australia Pty Ltd / TutorCloud NZ Limited
Attention: Privacy Officer
Email: dpo@tutorcloud.in
- LEGAL DOCUMENT
Privacy Policy
Effective Date: 24th January 2026

Your Data Protection
We implement
comprehensive security
measures to safeguard
your information

FERPA & COPPA Compliant
Full compliance with
education privacy laws
across multiple
jurisdictions

Your Rights
Access, correct, or
delete your personal
data at any time
TutorCloud Inc. (“TutorCloud”, “we”, “our”, or “us”), a Massachusetts corporation with its registered office at 500-West-Cummings Park, Suite 2700, Woburn, MA 01801, operates the TutorCloud.AI online learning platform, including its website located at https://tutorcloud.in/, its mobile applications, its administrator and educator dashboards, its application programming interfaces, and any related online services (collectively, the “Service”).
This Privacy Policy (the “Policy”) describes how we collect, use, disclose, retain, secure, and otherwise process personal information of individuals in the United States when they access or use the Service. It also explains the rights available to you and how to exercise them.
This Policy is designed to comply with, and should be read in conjunction with, the following United States federal and state laws applicable to us as a provider of an online educational service to a mixed audience of children under 13, minors aged 13 through 17, and adult learners aged 18 and above:
- The Children’s Online Privacy Protection Act, 15 U.S.C. 6501–6506, and the FTC’s COPPA Rule at 16 C.F.R. Part 312 (“COPPA”).
- The Family Educational Rights and Privacy Act, 20 U.S.C. 1232g, and 34 C.F.R. Part 99 (“FERPA”).
- The Protection of Pupil Rights Amendment, 20 U.S.C. 1232h (“PPRA”).
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, Cal. Civ. Code 1798.100 et seq. (“CCPA/CPRA”).
- The California Student Online Personal Information Protection Act, Cal. Bus. & Prof. Code 22584 et seq. (“SOPIPA”), and California AB 1584 (Cal. Ed. Code 49073.1).
- State student data privacy statutes generally in effect across US states, including but not limited to New York Education Law 2-d, Illinois Student Online Personal Protection Act (“SOPPA”), Connecticut Public Act 16-189, Colorado Student Data Transparency and Security Act, Utah Student Data Protection Act, and analogous statutes in other states.
- State comprehensive privacy statutes, where applicable, including the Colorado Privacy Act, Virginia Consumer Data Protection Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, and other comparable state laws that may govern the personal information of adult learners.
This Policy applies to personal information collected in the United States. Information collected from users outside the United States is governed by our region-specific policies published for those regions.
For purposes of this Policy the following capitalised terms have the meanings given below:
- “Child” or “Children” means a user under the age of thirteen (13).
- “Minor” means a user aged thirteen (13) through seventeen (17).
- “Adult Learner” means a user aged eighteen (18) or over.
- “Parent” means a parent or legal guardian of a Child or Minor user.
- “School” means a school, school district, local education agency, state education agency, private school, charter school, or any other educational institution (or teacher acting on their behalf) that uses the Service for educational purposes.
- “Institutional Account” means a School Account or a tutoring-center, corporate, or similar organisational account through which end-user accounts are provisioned.
- “Student Personal Data” means personal information relating to a student that is provided to us by, or created within, the Service in connection with a School’s or Institutional Account’s use of the Service, and which may constitute “education records”, “personally identifiable information from education records”, “covered information”, “student data”, or an equivalent category under FERPA, SOPIPA, or applicable state student data privacy laws.
- “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as defined under the CCPA/CPRA and other applicable US state privacy laws, and also has the meaning ascribed to “personal information” under COPPA where applicable.
- “AI Features” means any generative, adaptive, conversational, voice-recognition, video/webcam analytics, or personalisation features of the Service that are powered in whole or in part by artificial intelligence models, whether hosted by us or by third-party model providers.
- “Service Provider”, “Processor”, and “Contractor” have the meanings given under the CCPA/CPRA and other applicable state comprehensive privacy laws.
We collect the categories of personal information described below. The specific information collected in any given case depends on the account type (Child, Minor, Adult, Parent, Teacher, School Administrator), whether the account is a School Account or a consumer account, the features you or your School choose to use, and the settings and consents applied.
3.1 Identifiers and Account Registration Data
- Given name, chosen display name or username, and (for adult accounts only, unless otherwise required by the School) surname.
- Email address (for Children, we typically collect a Parent email address rather than the Child’s email address, unless the account is a School Account provisioned through a School-owned email address).
- Date of birth or self-reported age band, used solely to determine the correct age-appropriate experience, to apply COPPA parental consent requirements, and to enforce the age-appropriate design of the Service.
- Account credentials, including password hashes and, where applicable, single sign-on identifiers obtained from federated identity providers.
- Grade level, subject preferences, and language preferences.
3.2 School- or Institutional-Provided Data
- Roster data provided by Schools or their rostering service providers, including student identifier, class assignment, teacher of record, and grade level.
- Data provided via industry-standard rostering interoperability standards, learning-tools interoperability protocols, or federated identity/authorisation protocols.
3.3 Learning Activity and Usage Data
- Lessons attempted, questions answered, correct/incorrect responses, hints requested, time-on-task, mastery levels, streaks, and progress against a curriculum.
- Assignments assigned by teachers, submissions, grades, and teacher-generated feedback.
- Interactions with AI Features, including inputs, prompts, and outputs (subject to the AI Features section below).
3.4 Content You Submit
- Text you enter into the Service, including written essays, chat inputs, and answers.
- Voice recordings and transcripts generated by the Service’s voice/speech-recognition features when you use them.
- Images or video that you upload, and — where you affirmatively enable webcam-based features (for example, engagement analysis or proctoring) — video and image data captured while such features are active.
- Files, documents, or images you upload to the Service.
3.5 Communications
- Messages you send to us or to our support team, including chat transcripts, tickets, and survey responses.
- Communications you send within the Service to a teacher, tutor, coach, or Parent through Service messaging features.
3.6 Device, Log, and Technical Data
- Internet protocol (“IP”) address (which we truncate or hash for Child Users in accordance with COPPA).
- Browser type and version, operating system, device type and model, device identifiers, screen resolution, and time-zone information.
- Server log data including access times, pages viewed, referring/exit pages, and click-stream data.
- Approximate location derived from IP address (city or region only — we do not collect precise geolocation from Children).
3.7 Payment and Billing Data (Freemium and Institutional Licensing)
- For paid consumer subscriptions: billing name, billing address, and a payment token/last-four digits from our payment processor. We do not collect or store full payment card numbers on our systems.
- For Institutional Licensing: purchase-order data, invoicing contact, tax identification, and payment reference numbers.
3.8 Cookies and Similar Technologies
We use a limited number of cookies and similar technologies. See our Cookie Policy for details. We do not use behavioural-advertising cookies on any part of the Service directed to Children, and we do not permit third-party behavioural tracking on School Accounts.
3.9 Information We Do Not Knowingly Collect
- We do not knowingly collect biometric identifiers, biometric information, or precise geolocation from Children.
- We do not knowingly collect information from Children that is not reasonably necessary for their participation in the online educational activity.
We collect information from the following sources:
- Directly from you when you create an account, complete your profile, use the Service, submit content, take part in a lesson, contact us, or respond to a survey.
- From your Parent, teacher, tutor, or coach, where they set up your account, invite you to the Service, or provide information about you as part of the learning relationship.
- From your School or district, or from any rostering, single sign-on, or learning-management integration used by your School.
- Automatically, through cookies, server logs, and application telemetry when you interact with the Service.
- From service providers, such as our payment processor when you make a purchase, or our communications providers when they deliver a message to you at our request.
- From third-party sources in limited cases where required to prevent fraud, ensure security, or comply with law.
We use personal information for the following purposes, and only to the extent required for each purpose:
- Provide, operate, personalise, and improve the Service, including delivering lessons, tracking progress, generating reports, and adapting content to a learner’s demonstrated needs.
- Authenticate users, secure accounts, and prevent unauthorised access.
- Communicate with users, Parents, teachers, and Schools about the Service, including transactional messages, security alerts, and support responses.
- Provide AI Features requested by the user (subject to the safeguards described in Section 7).
- Understand how the Service is used, conduct educational research and analytics, and improve pedagogical outcomes, using de-identified or aggregated data where feasible.
- Process payments and manage subscriptions for adult and paid users, or invoices for Institutional Accounts.
- Respond to legal process, protect the safety of users, and enforce our Terms of Use.
- For Children, we use personal information solely to (i) provide the age-appropriate educational Service; (ii) maintain and analyse the Service for internal operations; (iii) protect the security or integrity of the Service; and (iv) fulfil other purposes permitted under COPPA 312.5(c).
We do not use Student Personal Data, or personal information of Children, to build advertising profiles, to target advertising to a user or a device, or to conduct amassed profiling for non-educational purposes. We do not sell Student Personal Data or personal information of Children.
For Adult Learners, we process personal information on one or more of the following bases: (a) performance of the contract to provide the Service to you; (b) your consent, where we ask for it (for example, to use certain optional AI Features); (c) our legitimate interests in operating, securing, and improving the Service, provided those interests are not overridden by your rights; and (d) compliance with a legal obligation.
For Children, we rely on verifiable parental consent as required by COPPA (or on School consent under COPPA’s school-authorisation exception, where the Service is used at the direction of a School for educational purposes). For Minors aged 13 through 17, we rely on the Minor’s own agreement to the Terms of Use, together with additional consents or approvals as described in Sections 8 and 10 below.
The Service includes AI Features such as: an AI tutor and chatbot; adaptive learning and personalisation engines; voice/speech recognition; video/webcam analytics for engagement and proctoring where affirmatively enabled; and generative content features that produce essays, images, code, and similar outputs. Some AI Features are powered in whole or in part by third-party large-language-model application programming interfaces provided by external model providers.
7.1 Our Commitments Regarding AI and Third-Party Models
- We do not send personally identifiable information about a user (including a user’s name, email address, precise date of birth, student identifier, teacher name, school name where materially identifying, or free-text account identifiers) as part of the payload transmitted to any third-party AI model provider. Instead, we use pseudonymous or de-identified session identifiers and strip inputs of directly identifying data before dispatch, to the extent technically feasible.
- We contractually prohibit our AI model providers from using inputs, prompts, outputs, or any content derived from the Service to train, fine-tune, retrain, evaluate, or otherwise improve their generally available foundation models or any other model made available to third parties.
- We contractually require our AI model providers to retain input and output data for zero-day or minimal-duration abuse-monitoring windows only, and to delete or return such data at the end of the applicable retention period.
- We do not use Student Personal Data to train or improve any generally available foundation model, and we do not permit our providers to do so on our behalf.
7.2 User Guidance and Limitations
- We advise users not to enter personal information about themselves or others into AI Feature inputs. Reasonable guidance and warnings are provided within the interface.
- AI Feature outputs may be inaccurate, incomplete, or inappropriate. Educational judgment by teachers, tutors, and Parents remains essential. AI outputs are not a substitute for professional advice.
- Where a user affirmatively enables voice or webcam features, audio or video captured is used only to deliver the requested feature, is not used to train third-party models, and is retained only for the period reasonably needed to deliver the feature and, where applicable, for a short quality-assurance window.
This Section applies to Children under the age of 13. It is intended to satisfy the notice requirements of the COPPA Rule at 16 C.F.R. 312.4.
8.1 Operator Contact
Operator: TutorCloud Inc.
Address: 500-West-Cummings Park, Suite 2700, Woburn, MA 01801.
Email: dpo@tutorcloud.in
Telephone: +1 617-752-0010
8.2 Categories of Personal Information Collected From Children
We collect from Children: first name or username (which we encourage not to identify the Child); Parent email address (for consumer accounts) or school-issued email address (for School Accounts); age band; learning-activity data; content submitted in the course of lessons and AI Feature interactions; and technical/log data (which we truncate or minimise where feasible). We do not collect surnames of Children (unless required by a School), photographs of Children (unless the Parent or School affirmatively enables a feature that captures them), precise geolocation, or contact information for Children other than as reasonably necessary to operate the Service.
8.3 How Children’s Information Is Used and Disclosed
Children’s information is used to provide the age-appropriate educational Service, to communicate with the Parent or School, to protect the security of the Service, to comply with law, and for other purposes permitted under COPPA. It is disclosed only to our vetted service providers under written contract limiting their use of the data to services provided on our behalf, and — for School Accounts — to the School as further described in Section 9.
8.4 Verifiable Parental Consent
For consumer accounts, we obtain verifiable parental consent before we collect any personal information from a Child, using a method reasonably calculated to ensure that the person providing consent is the Child’s Parent. Methods we use include, as appropriate, credit-card or debit-card charge with confirmation; signed consent form returned by mail, fax, or electronic scan; toll-free telephone confirmation; video-call confirmation; or the “email plus” method for internal-use collections that meet the COPPA criteria.
For School Accounts used at a School’s direction for educational purposes, we rely on the School to provide consent on behalf of the Parent, in accordance with the guidance issued by the Federal Trade Commission. Schools that use the Service warrant that they have the authority to do so.
8.5 Parental Rights
A Parent has the right to:
- Review the personal information collected from the Child.
- Direct us to delete the personal information collected from the Child.
- Refuse to permit further collection or use of the Child’s information, and terminate the account.
To exercise these rights, a Parent may contact us at dpo@tutorcloud.in. We will respond within a reasonable time and after we take steps reasonably designed to verify the identity of the requester.
8.6 No Behavioural Advertising or Third-Party Tracking for Children
We do not permit any form of third-party behavioural advertising, cross-context behavioural advertising, targeted advertising, or third-party analytics that construct persistent profiles, on any part of the Service directed to Children or on any Child account, in accordance with COPPA and applicable state law.
8.7 Community and Sharing Restrictions for Children
Child accounts are restricted so that they cannot make personal information publicly available, cannot post to public areas of the Service, cannot direct-message unknown users, and cannot upload profile photographs, in each case unless the Parent or School affirmatively enables the feature and, where required, provides additional COPPA-compliant consent.
When the Service is used by, or at the direction of, a School for educational purposes, this Section applies in addition to the general provisions of this Policy. In the event of any conflict between this Section and any written agreement with the School (including a data privacy agreement, addendum, or educator agreement), the written agreement controls with respect to Student Personal Data governed by that agreement.
9.1 Our Role Under FERPA
When we process Student Personal Data at the direction of a School, we act as a “school official” with a “legitimate educational interest” under FERPA’s school-official exception (34 C.F.R. 99.31(a)(1)(i)(B)), to the extent applicable. In that capacity:
- We use Student Personal Data only for the educational purpose(s) for which the School engaged the Service.
- We are under the direct control of the School with respect to the use and maintenance of Student Personal Data.
- We do not re-disclose Student Personal Data except as authorised by the School or as required by law.
- We maintain appropriate administrative, physical, and technical safeguards.
9.2 Our Role Under SOPIPA and State Student Privacy Laws
Where the Service is provided to a K-12 educational context, we operate as a “K-12 school service provider” or equivalent, and we undertake to comply with the substantive obligations of SOPIPA (Cal. Bus. & Prof. Code 22584–22585), California AB 1584 (Cal. Ed. Code 49073.1), New York Education Law 2-d, Illinois SOPPA, Colorado Student Data Transparency and Security Act, Connecticut Public Act 16-189, Utah Student Data Protection Act, and other comparable state student data privacy laws to the extent applicable, including the following commitments:
- We do not sell Student Personal Data.
- We do not use or disclose Student Personal Data for targeted advertising, and we do not build advertising profiles based on Student Personal Data.
- We do not amass a profile about a K-12 student except in furtherance of school purposes.
- Student Personal Data remains the property of, and under the control of, the School (or student and Parent, as applicable under state law).
- On termination of the School’s use of the Service or on the School’s written request, we delete or return Student Personal Data within the time frames required by the applicable state law and our data privacy agreement.
- We maintain administrative, physical, and technical safeguards appropriate to the sensitivity of Student Personal Data.
- We provide notification of security incidents to Schools as required by the applicable state law and our data privacy agreement.
9.3 PPRA
We do not conduct, administer, or facilitate the administration of any survey, analysis, or evaluation on behalf of a School that is designed to reveal information in any of the eight PPRA-protected categories (20 U.S.C. 1232h(b)) without the School’s confirmation that appropriate parental notice and, where applicable, consent have been obtained.
9.4 Creation of School Accounts
A user account is treated as a School Account, and Section 9 applies to it, when the account is (i) created by a teacher, School administrator, district administrator, or their delegate; (ii) provisioned by way of a rostering, single sign-on, or learning-management-system integration operated by or for a School; (iii) associated with a school-issued email domain and enrolled in a Class provided by a School; or (iv) covered by a written agreement between us and the School or district specifying that accounts under that agreement are School Accounts.
9.5 Institutional (Non-K-12) Accounts
Where the Service is licensed to an institutional customer that is not a K-12 School (for example, a tutoring centre, higher-education institution, or corporate learning customer), we process personal information of end users at the direction of that institutional customer under our applicable master services agreement or licence terms. FERPA, SOPIPA, and state K-12 student privacy laws apply only to the extent legally applicable.
10.1 Parental Rights
Parents of Children and, where afforded by state law, Parents of Minors, have the right to:
- Review the personal information we have collected from the Child or Minor.
- Request correction or updating of that information.
- Request that we delete the account and the personal information associated with it, subject to any applicable retention obligations imposed by law or by the School.
- Refuse further collection or use of the Child’s or Minor’s information and terminate the account.
- Receive answers to reasonable questions about our privacy practices as they relate to the Child or Minor.
10.2 Parental Responsibilities
Parents are responsible for supervising and supporting the Child’s or Minor’s use of the Service in a manner appropriate to the learner’s age and maturity. In particular, Parents are asked to:
- Read this Policy and the Terms of Use, and discuss them with the Child or Minor in age-appropriate terms.
- Ensure that the Child or Minor uses the Service in an environment that is safe, both physically and online, and with age-appropriate device controls.
- Encourage the Child or Minor not to enter personal information about themselves or others into any Service input field, including AI Feature prompts.
- Monitor the Child’s or Minor’s engagement with AI-generated content and correct any factual errors or inappropriate output.
- Keep account credentials secure and not share them with third parties.
- Notify us promptly of any suspected unauthorised access to the Child’s or Minor’s account or of any content that appears inappropriate.
We disclose personal information only in the limited circumstances set out below.
11.1 To Service Providers, Processors, and Contractors
We share personal information with service providers that perform services on our behalf, including cloud hosting, database services, single-sign-on providers, learning-management-system connectors, rostering interoperability providers, communication providers (email, SMS, in-app messaging, video), payment processors, customer-support tooling, error monitoring, security services, and AI model providers. All such service providers are bound by written contracts that limit their use of personal information to the services provided to us, and — for Student Personal Data and Children’s data — impose obligations consistent with FERPA, COPPA, SOPIPA, and applicable state laws.
11.2 To Schools, Teachers, and Institutional Administrators
For School and Institutional Accounts, we disclose Student Personal Data and other Personal Information to the applicable School, teacher, and administrator as reasonably necessary to deliver the Service.
11.3 To Parents
We disclose a Child’s information to that Child’s Parent on request, as required by COPPA and this Policy.
11.4 With User Direction or Consent
We may share personal information with third parties where you affirmatively direct us to do so, for example when you connect a third-party learning tool via a learning-tools-interoperability integration.
11.5 For Legal and Safety Purposes
We may disclose personal information when we in good faith believe such disclosure is necessary to (i) comply with law, legal process, or lawful requests from public authorities; (ii) protect the rights, property, or safety of TutorCloud, our users, or others; (iii) detect, prevent, or address fraud, security, or technical issues; or (iv) enforce our Terms of Use.
11.6 Business Transfers
If we are involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, personal information may be transferred to the successor entity, subject to this Policy and applicable law. Where required by COPPA, SOPIPA, or a School data privacy agreement, we will provide notice and, where required, obtain consent before Student Personal Data or a Child’s personal information is transferred in a manner materially inconsistent with this Policy.
11.7 De-identified and Aggregated Data
We may disclose de-identified or aggregated data that does not reasonably identify any individual and that is maintained and used in a manner consistent with applicable law. We commit not to attempt to re-identify such data, and we require our recipients to do the same.
11.8 No Sale, No Sharing for Cross-Context Behavioural Advertising
We do not sell Personal Information, and we do not share Personal Information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We do not sell Student Personal Data. We do not sell Personal Information of consumers we know to be under 16.
Personal Information collected from users in the United States is stored and processed on infrastructure located within the United States. We host United States data on a region-localised basis and do not routinely export it out of the United States. Limited exports may occur where reasonably necessary for global support, security incident response, fraud prevention, or legal compliance, and only to recipients bound by contractual and technical safeguards. If we host such data on cloud infrastructure operated by a global provider, the data-at-rest and data-in-transit locations are configured to remain within the United States region unless otherwise expressly permitted.
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, subject to the following:
- Consumer accounts: We retain account information for the life of the account. If the account is inactive for a continuous period exceeding twenty-four (24) months, we may delete or de-identify the account and its associated learning-activity data, following notice to the account holder or Parent as appropriate.
- School Accounts: We retain Student Personal Data for the period specified by the School’s data privacy agreement, or, in the absence of such a specified period, for the duration of the School’s active use of the Service plus a reasonable transition period, after which the data is deleted or returned as directed by the School.
- AI Feature inputs and outputs: We retain AI Feature inputs and outputs for a period no longer than necessary to deliver the requested feature and, where applicable, to comply with abuse-monitoring, safety, or legal-hold obligations. Retention periods and configurations are documented internally and made available to Schools on request.
- Payment and billing records: We retain to the extent required by applicable tax, accounting, and anti-fraud laws.
- Support communications: We retain for the period reasonably necessary to service the request and improve support.
- Legal hold: We may retain personal information for longer periods where required by law, litigation hold, or regulatory investigation.
De-identified and aggregated data may be retained for longer periods for product development, research, analytics, and demonstrating the educational impact of the Service.
We maintain administrative, physical, and technical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, or destruction. These include:
- Encryption of personal information at rest and in transit over public networks.
- Role-based access controls, principle of least privilege, and multi-factor authentication for administrative access.
- Segregation of production, staging, and development environments, and secure software development lifecycle controls.
- Vulnerability management, penetration testing, and independent third-party audits on a periodic basis.
- Employee training on privacy and security, and confidentiality and data-handling obligations imposed on personnel and contractors.
- Incident response procedures, including notification to Schools, Parents, and affected users as required by applicable federal and state law.
No security measure is infallible. We encourage users to choose strong passwords, keep credentials confidential, and notify us immediately of any suspected unauthorised access at dpo@tutorcloud.in.
15.1 Rights Available to California Consumers (CCPA/CPRA)
California consumers have the following rights, subject to verification and applicable exceptions:
- Right to know the categories and specific pieces of Personal Information we have collected, the sources of that information, the purposes for collecting it, and the categories of third parties to whom it is disclosed.
- Right to delete Personal Information we have collected from you.
- Right to correct inaccurate Personal Information.
- Right to opt out of any sale or sharing of Personal Information for cross-context behavioural advertising. (We do not sell or share for cross-context behavioural advertising.)
- Right to limit use and disclosure of Sensitive Personal Information beyond what is necessary to provide the Service. (We do not use Sensitive Personal Information for any purpose beyond permitted business purposes.)
- Right to non-discrimination for exercising your rights.
- Right to portability of Personal Information in a structured, commonly used, and machine-readable format.
15.2 Rights Available to Residents of Other US States
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have, to the extent applicable to their state of residence, rights of access, correction, deletion, portability, and opt-out of certain processing activities, together with a right to appeal any denial of a rights request.
15.3 How to Exercise Your Rights
To exercise any of the rights described in this Section, submit a request to dpo@tutorcloud.in. We will acknowledge the request within ten (10) business days (or such shorter period as required by law) and respond substantively within forty-five (45) days, extendable by an additional forty-five (45) days where reasonably necessary, with notice to you.
We will verify your identity through reasonable measures proportionate to the sensitivity of the request and the nature of the account. An authorised agent may make a request on your behalf; we will require appropriate proof of authority.
For School Accounts, requests to review, correct, or delete Student Personal Data should generally be directed to the School. We will assist the School in responding to such requests as required by our agreement with the School and by applicable law.
15.4 Right to Appeal
If we deny your request, in whole or in part, you have the right to appeal our decision. To appeal, reply to our denial email or write to dpo@tutorcloud.in with the subject line “Privacy Rights Appeal”. We will respond to your appeal within sixty (60) days.
The Service uses a limited number of cookies and similar technologies. Please see our Cookie Policy for full details, including how you can manage your preferences.
If you have a complaint about our privacy practices, please contact us first at dpo@tutorcloud.in so that we may have an opportunity to address your concerns. If you are not satisfied with our response, you may lodge a complaint with:
- The Federal Trade Commission (for COPPA and general federal privacy matters) at http://www.ftc.gov.
- The United States Department of Education, Student Privacy Policy Office (for FERPA and PPRA matters) at studentprivacy.ed.gov.
- The California Privacy Protection Agency or the California Office of the Attorney General (for California residents).
- The Attorney General or state consumer protection authority of your state of residence, where applicable.
We may update this Policy from time to time. When we do, we will revise the Effective Date and, in the case of material changes affecting how we collect, use, or disclose Personal Information — in particular Student Personal Data or Children’s data — we will notify Schools and, as appropriate, Parents and users, before those changes take effect. For material changes to our processing of Student Personal Data, we will obtain any required School or parental consent before the changes are applied to previously collected data.
Contact
For any questions about this Policy, please contact us at:
Privacy & Security Team: dpo@tutorcloud.in
Postal address: TutorCloud Inc., 500-West-Cummings Park, Suite 2700, Woburn, MA 01801.
Telephone: +1 617-752-0010
Compliance Officer Contact Form
Please complete all required fields
Message Sent Successfully
×Thank you for contacting us. We'll get back to you soon.