Last updated: 2 November 2025
KenyanTutors.com (the “Platform”, “we”, “us”, “our”) runs a community and marketplace where learners book independent tutors. This Policy explains how we collect, use, disclose, and protect personal data under the EU/UK GDPR, Kenya Data Protection Act 2019, and, where applicable, the California CCPA/CPRA and other local laws.
1) Controller & Contact
Controller: KenyanTutors
Privacy contact: hello@kenyantutors.com
DPO: No statutory Data Protection Officer appointed. Use the contact above.
EU/UK representative (Art. 27): If required, we will appoint a representative and update this notice.
2) Scope
This Policy applies to visitors, account holders (learners, parents/guardians, tutors), and anyone interacting with our services, communications, and support channels.
3) Data We Collect
- Account & profile: name, email, password, country/region, timezone, profile photo, bio, qualifications (tutors), availability.
- Bookings & payments: lessons purchased, schedules, prices, currency, partial payment details (via payment partners), invoices, VAT/tax data, tutor payout details.
- Communications: messages, support requests, community posts, reviews/ratings.
- Session artefacts: chat logs and—only if a participant starts recording—audio/video recordings and summaries.
- Device & usage: IP address, device/browser info, feature usage, cookies/SDKs, crash logs, approximate location (city/region).
- KYC/AML & compliance: identity checks (name, DOB, ID documents), sanctions screening results.
- Marketing preferences: opt-ins/opt-outs, campaign interactions.
4) Why We Use Data & Our Lawful Bases (GDPR)
We process personal data for the purposes below. For each purpose, we list the GDPR lawful bases that may apply.
Provide & secure the Platform
Accounts, bookings, payments, payouts, customer support, fraud prevention, and security.
Lawful bases: contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)).
Marketplace operations
Search and discovery, tutor listings, reviews/ratings, dispute handling, commission processing.
Lawful bases: contract; legitimate interests.
Quality & safety
Abuse prevention, safeguarding, audit trails; participant-initiated recordings only (no live monitoring).
Lawful bases: legitimate interests; consent where required; legal obligation.
AI features & automated recommendations
Tutor suggestions, lesson/quality summaries, moderation aids. EU/UK users may request an explanation of key input factors or contest a recommendation at hello@kenyantutors.com.
Lawful bases: legitimate interests; consent where required by local law.
Service communications
Receipts, operational notices, policy updates, security alerts.
Lawful bases: contract; legal obligation.
Marketing
Newsletters, offers, onboarding tips (only where permitted and with easy opt-out).
Lawful bases: consent; legitimate interests (soft opt-in where allowed).
Compliance
KYC/AML checks, taxes, sanctions screening, bookkeeping and audit trails.
Lawful bases: legal obligation; public interest; legitimate interests.
Legitimate interests include: operating a safe, reliable marketplace; preventing fraud/abuse; improving services; informing users about similar services (with an opt-out).
5) No Live Monitoring; Recordings When Started by a Participant
We do not monitor sessions live. If a participant starts a recording using Platform features (or where law allows and required consents are captured), we may store that recording and related chat logs solely for quality, safety, and dispute resolution. Access is limited to the session participants (and, for minors, their parent/guardian) and authorised staff where necessary. Do not publicly share recordings we provide to you.
6) Cookies & Similar Technologies
We use cookies/SDKs for essential functions (login, security), analytics, preferences, and—where permitted—marketing. Manage non-essential cookies via our cookie banner (consent) or your browser settings. Disabling some cookies may affect functionality.
7) Who Receives Your Data
- Other users: limited profile/booking details exchanged between tutors and learners to deliver lessons.
- Service providers (processors): hosting/cloud, payment processors, KYC/AML vendors, analytics, email/SMS, support tools, security/fraud vendors—under processing contracts.
- Independent controllers: payment partners for card processing; tutors for learner data they directly receive to provide lessons.
- Authorities: where required by law, legal process, or to protect rights/safety.
- Business transfers: in a merger, acquisition, or sale of assets, data may transfer under this Policy.
8) International Transfers & Safeguards
We may process data outside your country. Where required, we use appropriate safeguards such as EU Standard Contractual Clauses, the UK IDTA/Addendum, adequacy decisions, and technical/organisational measures. Kenya cross-border transfers are made under the DPA 2019 and its regulations. Contact us for details (redactions may apply).
9) Retention
- Account & bookings: for your account lifetime, then typically up to 6 years (tax, audit, disputes).
- Participant-initiated recordings: default 180 days, or longer if reasonably needed for an active dispute or legal obligation.
- KYC/AML: per statutory periods (commonly 5–7 years).
- Marketing data: until you withdraw consent or after a defined inactivity period.
We may retain de-identified/aggregated data that cannot reasonably identify you.
10) Is Provision of Data Mandatory?
Some data is necessary to enter into or perform the contract (e.g., account, booking, payment details). Without it, certain features or transactions cannot be completed. Optional data is clearly indicated where requested.
11) Children & Minors
You must be 18+ to register and use paid features. If under 18, a parent/guardian must create/manage the account, provide required consents, and supervise use. We do not knowingly collect children’s data contrary to applicable law (e.g., under 13 in the U.S. without parental consent).
12) Your Rights
We respond within legal timeframes and may verify your identity before acting.
- Kenya / UK / EU (GDPR): access; rectification; erasure; restriction; portability; object (including to profiling/marketing); withdraw consent; complain to a supervisory authority (ODPC, ICO, or your EU DPA).
- U.S. (CCPA/CPRA, if applicable): know/access; correct; delete; opt-out of “sale”/“sharing” for cross-context advertising; limit use/disclosure of sensitive personal information; non-discrimination. We do not knowingly “sell” personal data. If we “share” for cross-context ads, you can opt out via our banner or by contacting us.
Automated recommendations: You can request an explanation of key input factors, adjust preferences, or contest a recommendation by emailing hello@kenyantutors.com. We do not make solely automated decisions that produce legal or similarly significant effects without appropriate safeguards.
13) Marketing Choices
Opt out of marketing emails at any time via the unsubscribe link or by contacting us. We will still send essential service/transactional messages.
14) Security
We implement appropriate technical and organisational measures (encryption in transit, access controls, logging, periodic reviews). No system is perfectly secure; keep credentials confidential and notify us of any suspected compromise.
15) Payments, Taxes & Marketplace
Payments are processed by third-party processors; we do not store full card numbers. Where required by law, we may act as a marketplace facilitator to collect/remit taxes, which will be indicated at checkout. Tutors are independent providers and may be separate controllers of the learner data they receive.
16) Third-Party Links & Services
External sites and integrated services are governed by their own privacy policies; please review them before use.
17) Changes to this Policy
We may update this Policy from time to time. Material changes will be posted with a new effective date (and additional notice where appropriate). Continued use after changes take effect indicates acceptance.
18) How to Contact Us or Make a Complaint
Submit privacy requests: hello@kenyantutors.com
- Kenya: Office of the Data Protection Commissioner (ODPC)
- United Kingdom: Information Commissioner’s Office (ICO)
- EU/EEA: your local Data Protection Authority
- United States (California): California Privacy Protection Agency (CPPA) / California Attorney General
Note: If we later appoint an EU/UK representative, introduce new SDKs, or change processors/transfer safeguards, we will update this Policy and—where required—seek fresh consent.