Ximly logo

Ximly Privacy Policy

§ 1. Who the controller is and how to contact us

1.1. The controller of your personal data is Ximly sp. z o.o. with its registered office in Kraków, address: ul. Zamknięta 10/1.5, 30-554 Kraków, Poland, KRS 0001152079, NIP 6793320888 (hereinafter: "Ximly", "we").

1.2. In matters concerning your personal data you can contact us:

  • by e-mail: legal@ximly.app (data protection matters) or support@ximly.app (account and help matters),
  • in writing: at the registered office address indicated in section 1.1.

1.3. We have not appointed a Data Protection Officer. All personal data matters are handled by the Ximly team at the addresses in section 1.2.


§ 2. Who is responsible for which processing (controller roles)

2.1. Ximly is the controller of the data processed in connection with running the platform: accounts, bookings, the messenger, the virtual classroom, payment handling on the platform side, complaint resolution, security and accountability.

2.2. The Tutor is a separate controller of students' data to the extent that the Tutor conducts their own teaching activity. This covers the content of the notes, topics and learning objectives the Tutor creates about a student, as well as the students' data received from the platform for the purpose of conducting a lesson: first and last name, the shared contact details and the entries in the Tutor's calendar. The Tutor is bound by the confidentiality obligations and the data-use restrictions set out in the Terms of Service for Tutors (Document D2 § 11).

2.3. Stripe (Stripe Payments Europe, Ltd. and the entities of the Stripe group) is a separate controller of the data processed within Stripe's own legal obligations: identity verification of tutors (KYC, "know your customer"), anti-money-laundering and regulatory compliance. In the remaining scope (payment handling on Ximly's behalf) Stripe acts as a separate payment services provider — details in § 16.

2.4. WorkOS (the login provider) and the remaining entities in the table in § 7 process data on our behalf as processors, unless the table indicates otherwise.

2.5. Data related to the handling of reports, complaints, appeals and account deletion requests is accessible to Ximly support operators — details and restrictions in § 15.


§ 3. What data we collect

3.1. Account and registration data: e-mail address, first and last name, chosen language and time zone, an optional avatar, an optional additional e-mail address for notifications. Account creation takes place in two stages. Stage 1 — registration: you provide your e-mail address and make an age declaration: as an adult — a declaration of being at least 18 years old (a separate field; you do not provide a date of birth then), and if you are under 18 — your date of birth and the e-mail address of your parent/guardian; at this stage we present the Terms of Service and this Policy to you and record the fact of the documents' presentation, the manner in which the declaration was made (ticking a box or confirming with a button together with the version of the wording of the statement displayed next to the button), the version and language of the document, the time, the IP address and browser information (user agent) (§ 5 and § 21). We record the declaration of being at least 18 as the fact of ticking together with the time, IP address, user agent and the version of its wording. Stage 2 — completing account creation after confirming your e-mail address: you complete your profile (the tutor role can be chosen only by an account of established adulthood — from the declaration of being at least 18 years old or from a date of birth; Document D1 § 4.10), and if the Terms of Service have not yet been accepted under your account or a newer version is already in force, you accept them in the account gate — this Policy is then given to you to read (it is not a contract and is not subject to acceptance; we record the fact of its presentation). What is binding is the acceptance of the Terms made under your account — at registration or in the gate; a child aged 13–17 does not accept on their own, what is binding is the guardian's acceptance under the guardian's own account (§ 4.3). A child's account may also be created by a parent from their own account (§ 4.3 point 5).

3.2. Date of birth: we do not collect it from persons who have declared being at least 18 years old — this applies to tutors as well: a tutor's adulthood may follow from the declaration alone (Document D1 § 4.10, Document D8 § 5.1). For the accounts of students aged 13–17, the date is provided by the student (the invitation path — § 4.3 points 1–4) or by the parent (when creating the child's account — § 4.3 point 5). The parent may correct the date they entered within 24 hours of the creation of the child's account, as long as the child has not logged in; outside that window a saved date cannot be changed — neither by you nor by support (this safeguards the minor-protection system — § 4). If a student mistakenly provided an incorrect date, the remedial path is to register again with the correct date (Document D1 § 4.2); where the mistake indicates an age under 13, the account is blocked and the data deleted — once the data deletion is complete, the original e-mail address is released for a new registration. If it turns out that a person who declared adulthood is a minor, the support team records the corrected date on the account together with the reason and the person making the correction, and the account moves to the rules concerning minors (Document D1 § 4.2; § 11).

3.3. Telephone number (with country): required when completing account creation. Purpose: securing the account, helping to recover it and preventing duplicate accounts. We do not send SMS messages and we do not call — no SMS/voice channel exists on the platform; any future commercial contact by that route would require your separate, prior consent (Article 398 of the Polish Electronic Communications Law (ustawa — Prawo komunikacji elektronicznej, hereinafter: "PKE")). The number is passed to WorkOS (§ 7) as an element of account metadata.

3.4. Logging in: the basis is a one-time e-mail code from the login provider (WorkOS). You can also set a password (stored exclusively by WorkOS) or log in via Google, Apple or Microsoft (also via WorkOS) — from each source we receive the e-mail address, first and last name and the address verification status. When you set a password, we check in the Have I Been Pwned service whether it has leaked — sending only a short fragment of a hash, from which neither the password nor the person can be reconstructed.

3.5. Educational and Learning Space data (definition of a Learning Space: Document D1 § 1.2): bookings and lesson history, attendance (including who joined a video lesson and when), learning topics and objectives, files, the whiteboard, the lesson chat.

3.6. Conversations: message content, attachments, the edit history of every message (the other party to the conversation sees an "edited" label and the earlier versions of the text) and read receipts (the sender sees who read the message and when). Deleting a message also deletes its attachment from the file storage.

3.7. Payments: payment identifiers and statuses, settlement history, the proofs of payment uploaded under direct settlements with the Tutor, i.e. where the payment takes place outside the platform (definition of the settlement rails: Document D1 § 1.2), dispute data. We do not store card numbers — payment data (the card number, the Tutor's settlement data, and, for those conducting business activity or operating as a company, also business data including the tax identification number) is managed by Stripe (§ 16). We record only the kind of payment method and the identifiers assigned by Stripe.

3.8. Evidentiary data: the register of acceptances of legal documents (version, language, time, IP, user agent, and for minors — the attribution: who acted, who was the party, which guardian authorization event), the register of guardian authorization events (upon revocation of an authorization — together with the short reason for the revocation indicated by the parent, § 4.6), the register of cookie consents (§ 6, Document D7), the evidence of the declaration of being at least 18 (the fact of ticking, the version of the wording, time, IP, user agent), the event of the creation of a child's account by a parent together with the declarations made at that point (§ 4.3 point 5), and evidence of presentation of informational content (version of the wording, time): the information notice for the child at the first login (§ 20), the reminder to the parent that they make the decision to choose a tutor themselves, the notice to the child about the parent's access to their conversations (a precondition for activating the access — § 4.5, Document D8 § 3.6) and the notice to the parent about the purpose and limits of that access at its first opening (§ 4.5); as well as the log of the parent's openings of the child's conversations (the time at which each reading session of a conversation begins; a further opening of the same conversation by the same parent within 15 minutes belongs to the same session and does not create a separate entry — § 4.5).

3.9. What we do not collect: the tutor's settlement data collected in the course of identity verification — and, for tutors conducting business activity or operating as a company, also business data (tax identification number, business address); it is collected exclusively by Stripe in the course of KYC as a separate controller. Nor do we collect payment card data or biometric data. We do not carry out marketing profiling — that is, automated evaluation of your characteristics and behaviour, e.g. to target advertising — and we do not collect any marketing consent (§ 13).

3.10. Which data is mandatory and which is voluntary (Article 13(2)(e) GDPR):

  • account data (e-mail address, first and last name) and the age declaration (a declaration of being at least 18 or a date of birth — § 3.2) — a condition for concluding and performing the contract for the use of the platform; without them the account will not be created or will remain limited to a narrow list of actions (§ 4.1);
  • telephone number — required to complete account creation; without completed account creation you cannot book a lesson (§ 3.3);
  • the parent's/guardian's e-mail address — a condition for the use of the platform by a student aged 13–17 (§ 4);
  • payment data (card number, the tutor's settlement data) — collected exclusively by Stripe; without it you cannot use card payments or — as a tutor — settlements via Stripe (§ 16);
  • profile fields (avatar, description, location, additional e-mail address for notifications, preferences) — voluntary.

The only consequence of not providing data is the inability to use the feature for which it is needed; none of this data is required from you directly by a legal provision.


§ 4. Minors, parents and guardians

4.1. Age bands

(This part is written to you — the student.)

You may use the platform as a student if you are at least 13 years old. Three bands apply:

AgeRule
under 13an account is not permitted; the detection of such an account results in its blocking and the automatic start of data deletion. As evidence of the event we retain only the record "an account below the minimum age was blocked and passed for deletion" — without any personal data (no account identifier, no IP, no other data)
13–15use requires the authorization of a Parent/Guardian, which also includes the parent's consent for us to be able to use your data (required by Article 8 GDPR for persons under 16; in the system we record it as a separate consent scope)
16–17use requires the guardian's authorization in matters of contracts and payments (we no longer require the consent to data processing based on Article 8 GDPR — you are 16 or older)

As long as your account has neither a declaration of being at least 18 nor a date of birth, it has access only to a narrow list of actions (completing the age profile, logging out, deleting the account, data export, reading the documents, cookie consents) — we treat an unknown age as the youngest age. For the purposes of this rule, a declaration of being at least 18 is a known age.

4.2. The parent as party to the contract and payer

For every student under 18, the party to the contracts concluded on the platform and the payer of every obligation is the parent/guardian — not the child. The system does not allow the child to perform any payment action (a booking with a payment, a confirmation, an appeal against a payment decision go to the guardian), and a payment does not arise at all without the guardian's active authorization.

4.3. How guardian authorization works and what data we process then

  1. The child indicates the parent's e-mail address. From that moment we process that address as the parent's data; we create a technical parent account record containing exclusively that address (the first and last name is filled in only by the parent, at the first login).
  2. The parent receives an invitation e-mail containing a secure link valid for 72 hours. The invitation is the way of entering a parent account created on the child's indication (the second path — the parent's own registration and their creation of the child's account — is described in point 5); the link itself is stored with us exclusively as a hash (SHA-256), and sending is limited by rate limits. The invitation e-mail does not contain the child's name or lesson details.
  3. The parent logs in without a password (a WorkOS e-mail code), establishes their identity and accepts the Terms of Service (Document D1) under their own account; this Policy is given to them to read (we record the fact of its presentation). They then approve the authorization for the child, seeing its exact scope; for a child under 16 they give the consent to the processing of the child's data by a separate tick, and additionally confirm that they make the decision to choose a tutor themselves (Document D1 § 4.11).
  4. We record every authorization event (grant, re-approval, revocation, expiry upon reaching the age of majority) in an event register from which nothing can be deleted or changed, together with the scopes, the exact document versions, the time, the IP address and the user agent. The register is available to the parent in their panel.
  5. The second path — the parent creates the child's account. A parent may register their own account themselves (a declaration of being at least 18 and selection of the parent role — § 3.1) and create the child's account from their own panel in the web application ("Add a child"), providing the child's first and last name, date of birth and the child's e-mail address. In the same action the parent declares that they are the child's parent or legal guardian, approves the authorization scopes, confirms that they make the decision to choose a tutor themselves, and, for a child under 16, gives the consent to the processing of the child's data by a separate tick, distinct from the contractual-and-payment authorization. The link is active immediately — with no invitation and no 72-hour period; the child receives at their e-mail address a link to set a password. Legal bases: the contract with the parent, of which the child is the beneficiary (Article 6(1)(b) GDPR); for a child under 16 — the parent's consent to the processing of the child's data (Article 8(1) GDPR); in respect of the data of a child aged 16–17 — Article 6(1)(b) and (f) GDPR. We record the event and the declarations made in the register of point 4.

An honest description of the strength of verification: we verify control over the indicated e-mail mailbox (link + one-time code); we do not verify identity, that the person is of legal age, or family relationship — this is a deliberate and recorded limitation of the adopted authorization model. Providing the address of a person who does not hold parental authority violates the Terms of Service and may result in the invalidity of the authorizations granted. For a child's account created by a parent (point 5) we do not verify the child's existence or age other than by the parent's declaration; the child confirms their e-mail address by setting a password.

4.4. The parent as a data subject

(Sections 4.4–4.7 are written to you — the Parent/Guardian.)

If a child has indicated your e-mail address, we process it for the purpose of carrying out the authorization (Article 6(1)(c) and (f) GDPR in conjunction with Article 8(2) GDPR and Article 17 of the Polish Civil Code (Kodeks cywilny, hereinafter: "KC")). You receive the information notice in the first message from us. If you do not use the invitation, after 72 hours the technical record with your address becomes eligible for deletion and is deleted by the next daily cleanup process together with the child's unfinished account; it is also deleted when the child's account is deleted. If you created the parent account yourself (§ 4.3 point 5), we process your data on the basis of the contract for the use of the platform (Article 6(1)(b) GDPR), not the invitation — the 72-hour rule does not apply to you.

4.5. What the parent sees and does not see

The parent panel covers: the list of children, the creation of a child's account ("Add a child") and the correction of the child's date of birth within the 24-hour window (§ 3.2), the child's lessons, payments and arrears, the register of authorization events, the revocation of authorization and complaints concerning the child's lessons in which the parent has standing as the party to the contract and the payer (§ 4.2; Document D1 § 4.4, Document D4 § 10.2) — in such a complaint the parent sees its description and the messages exchanged with the support team in that proceeding, including those written by the child. It also covers read-only access to the child's conversations with tutors (the private child–tutor chat and the lesson chat of a lesson in which the child is the only student; the lesson chat of a group lesson remains outside the access, because it contains messages of other students) — exclusively messages sent from the access boundary moment: the latest of the date of entry into force of the version of the Terms of Service (Document D1 § 4.7) and the date of entry into force of the version of this Policy that introduced the access, and the moment the child first saw the notice about the access on the Platform (Document D8 § 3.6) — without earlier messages, including messages sent after those versions took effect but before the notice was shown to the child; the access is transparent to the child and the tutor (Document D8 § 3.6), is activated only after the child has seen the notice about it on the Platform (Document D8 § 3.6; evidence of presentation — § 3.8), does not extend to conversations with other students or to the child's reports (Document D8 § 8.5), does not allow the parent to write, change or report messages from within the child's conversation, and ends upon revocation of the authorization or when the child turns 18. When opening the access for the first time, the parent sees a notice about its protective purpose and limits and confirms that it was displayed (evidence of presentation — § 3.8). The legal basis for making the content available to the parent is the performance of the contract to which the parent is a party (Article 6(1)(b) GDPR) and our legitimate interest in protecting minors (Article 6(1)(f) GDPR; Article 28 DSA). It does not cover the tutor's notes about the child. Access to the content of the complaint proceeding itself follows from the fact that it is the parent who conducts it as the party to the contract and the payer (Document D1 § 12.5) — without the description of the objections and without the thread with the support team they could not exercise that right. The parent receives financial notifications as the payer; the child receives a copy of them in a limited version.

4.6. Revocation of authorization by the parent

You can perform the revocation with a single action in the parent panel (Article 7(3) GDPR), with a preview of the effects before approval; you indicate a short reason for the revocation, which we record in the register of authorization events (§ 3.8). The effects: unpaid lessons are cancelled without any debt, paid ones go through the standard refund path to you as the payer (Document D4 — the Cancellation Policy). The child's sessions are logged out, the tutor is notified.

4.7. Reaching the age of majority and other boundaries

On the child's 18th birthday the guardian's authority expires automatically (the event "ended — majority" in the register; executed at the first request, with a nightly fallback mechanism). This also applies to an account created by the parent (§ 4.3 point 5). Upon the conversion of the account the child's active sessions are invalidated, and further use requires acceptance of the Terms of Service under the student's own account (this Policy is presented at that time). Passing the age of 16 does not require re-authorization — the scope required from the guardian simply narrows.

4.8. Account deletion by the child

(This part is written to you — the student.)

If you are 13–17 years old, you may independently submit a request to delete your account and download an export of your data — these rights are always available, even with an incomplete authorization. You have the same rights if your account was created by your parent (§ 4.3 point 5). A parent with an active authorization may request the deletion of the account of a child under 16; for a child aged 16–17 we handle the parent's request with the child's participation — we ask the child for their position before carrying it out (§ 10.5).

4.9. Analytics and consents towards minors

For the accounts of persons under 16 and accounts of unknown age we disable analytics — including session recording (§ 19.4) — on the server side regardless of the decision expressed in the cookie banner (details — Document D7 § 5). Session recording itself is disabled more broadly — for all accounts of persons under 18, even with analytics consent (§ 19.4). For the purposes of this rule, a declaration of being at least 18 is a known age: we treat an account with such a declaration as an adult's account, and analytics is governed solely by your choice in the cookie banner. We direct no behavioural marketing or profiling at minors (§ 13.6).

4.10. The child's data passed on in connection with a lesson

For the purpose of conducting a lesson we pass on: to the video provider (Cloudflare RealtimeKit) — the participant's first and last name, account identifier and avatar address; to the fallback video provider (Zoom) — the meeting title (the name of the Learning Space + the topic); to the tutor's Google calendar — a lesson entry with the student's first name and the initial of the surname (the event is created as private, with no ability to invite additional guests). Details in § 7 and § 17.


§ 5. Why and on what basis we process data

5.1. The table of purposes and legal bases. The storage periods for each category — in the retention table (§ 9).

PurposeData categoriesLegal basis
Running the account and providing the platform service (bookings, Learning Space, messenger, virtual classroom)account data, educational data, conversationsArticle 6(1)(b) GDPR (contract — processing necessary to provide you with the service)
The age framework and guardian authorizationdate of birth, parent data, the register of authorization eventsArticle 6(1)(c) and (f) GDPR in conjunction with Article 8 GDPR and Article 17 KC (legal obligation and our legitimate interest: we must check the parent's consent before the child uses the service)
Declaration of adulthoodthe fact and version of the declaration, time, IP address, user agentArticle 6(1)(c) and (f) GDPR (accountability — Article 7(1) GDPR — and the protection of minors: we must be able to demonstrate on what basis we treated you as an adult)
The child's data entered by the parent when creating the child's account (§ 4.3 point 5)first and last name, date of birth, the child's e-mail addressArticle 6(1)(b) GDPR (the contract with the parent — the child is its beneficiary) and — for a child under 16 — Article 8(1) GDPR (the parent's consent)
Handling payments and settlements on both settlement rails (definition: Document D1 § 1.2), proofs of paymentpayment data, proofs of paymentArticle 6(1)(b) and (c) GDPR (contract and legal obligations, e.g. accounting ones)
Resolving complaints and disputes, including compiling the evidence passed to Stripe in the event of a chargeback (a chargeback — contesting a payment with the card issuer)complaint content, payment data, consent recordsArticle 6(1)(b) and (f) GDPR (contract and our legitimate interest — defence against claims)
Enforcing the rules: reminders about arrears, booking blocks, Warnings (definition: Document D1 § 1.2), appealspayment data, sanction registersArticle 6(1)(b) and (f) GDPR (contract and legitimate interest — protection against abuse); safeguards — § 11
Evidence of document acceptances and consents (including IP and user agent)acceptance registers, registration declarations, cookie consentsArticle 6(1)(c) and (f) GDPR (legal obligation and legitimate interest: we must be able to demonstrate who accepted what — Article 7(1) GDPR)
Account and session security: approximate IP geolocation, device attributes, the session listtechnical data (§ 14)Article 6(1)(f) GDPR (legitimate interest — protection of accounts; the balancing test in internal documentation)
Service communication (e-mail, push, in-app entries)account data, notification contentArticle 6(1)(b) GDPR (contract — these messages are part of the service); security and legal notices — Article 6(1)(c) and (f) GDPR; NOT consent (§ 13)
Product analytics, including session recording in the browser (exclusively after consent in the cookie banner; analytics never towards persons under 16 or of unknown age, session recording never towards persons under 18 — § 4.9, § 7.1, § 19.4)pseudonymous events in the browser; for session recording — a replayable record of the interface: mouse movements and clicks, scrolling, screen changes, changes of the visible page content, with the content of chat messages, the lesson chat and text fields masked (§ 19.4)Article 6(1)(a) GDPR + Article 399 PKE (consent — it operates only if you give it; Document D7)
Checking the consistency of a Tutor's profile data with documents the Tutor sent us (the "Verified" mark — Document D2 § 4.2; only at the Tutor's request or with their consent; processing for this purpose will begin only once the handling of checks is launched — we do not currently carry out checks)profile data covered by the check, documents sent (deleted after the check), a note of the result; we do not accept documents concerning criminal records (Document D8 § 5.2)Article 6(1)(b) GDPR (a step taken at the Tutor's request under the contract)
Parent/Guardian access to the child's conversations with tutors (Document D8 § 3.6)content and metadata of child–tutor conversations (the private chat and the lesson chat of a lesson in which the child is the only student) from the access boundary moment (§ 4.5, Document D8 § 3.6); a log of the parent's openings of a conversation (§ 3.8); evidence that the notice about the access was presented to the child and to the parent (§ 3.8; period — § 9.2)Article 6(1)(b) GDPR (a contract to which the parent is a party) and (f) (protection of minors — Article 28 DSA, Articles 22b–22c of the Polish Act on the protection of minors); as regards the tutor's messages — the same bases
Tax and accounting obligationssettlement documentationArticle 6(1)(c) GDPR (legal obligation)
Diagnostics and monitoring of the application's operationtechnical logs, error data (§ 9, § 14)Article 6(1)(f) GDPR (legitimate interest — keeping the platform running)

5.2. We do not conduct consent-based marketing — we do not send newsletters or commercial information and we do not collect consents for them. If we wanted to change that, we would first build a separate, voluntary consent mechanism and update this Policy (§ 13).

5.3. Wherever the basis is our legitimate interest (Article 6(1)(f) GDPR), you have the right to object — § 10.7.


§ 6. Cookies and similar technologies

6.1. The full, tabular list of cookies and browser-storage entries and the consent rules can be found in the separate Cookie Policy (Document D7) — available without logging in and without an acceptance gate.

6.2. Two corrections with respect to earlier versions of the documents: (a) cookies may contain personal data — in particular the authentication cookie app_token contains an encrypted token linked to your account; (b) browser settings are not a mechanism for expressing consent — you express consent to categories other than the necessary ones exclusively in the banner/consent settings, and we record the decision on the server side (Document D7 § 3).


§ 7. Who we pass data to (register of recipients)

7.1. The table below is the register of the main recipients of data. The "Transfer mechanism" column indicates the basis for passing data outside the European Economic Area (§ 8); where we indicate standard contractual clauses or equivalent mechanisms, we rely on the agreements concluded with the given provider, and you will receive a copy of the safeguards applied on request (§ 8.4).

RecipientRolePurpose / what it receivesRegionTransfer mechanism
Laravel Cloud (infrastructure operator)processor — application and database hostingall data processed in the application and in the database, to the extent necessary to maintain the infrastructure (servers, database, backups)the region indicated in the service configurationstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Stripe (Stripe Payments Europe, Ltd. and the group)payment services provider; in the KYC/AML scope a separate controllerhandling card payments, tutor KYC, disputes; payment/lesson/account identifiers; dispute evidence packages (including consent records with the document version)Ireland / global group (support from outside the EEA possible)standard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
WorkOS, Inc.processor (identity and login)e-mail code login, passwords, multi-factor authentication (MFA), Google/Apple/Microsoft login; e-mail, first and last name, locale, time zone, telephone number with countryUSAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Cloudflare, Inc. — a single entry covering: CDN/WAF (__cf_bm), Turnstile (anti-bot protection of the registration, login and password-reset forms — enablement for individual actions may differ depending on the configuration), the R2 file storage, Realtime/RealtimeKit (lesson video), cache purgingprocessorHTTP traffic (IP address, request metadata, browser signals), user files (private storage with signed links; public exclusively for avatars/logos), lesson audio-video streams together with the participant's first and last name, account identifier and avatarUSA (network edge incl. in the EU; file storage in the region indicated in the service configuration)standard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Transactional e-mail provider (configured transports: Resend, Inc. and — inactive — Mailgun/Sinch)processordelivering e-mails: address, first name, message content (including chat message previews in digest e-mails — § 13.5)USAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Exponent, Inc. (Expo)processorpush notifications to the mobile application: device token, notification title and content (including up to 100 characters of chat message content), conversation/Learning Space identifiers, sender's first name, avatar addressUSAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Pusher Ltd (Datadog group)processor (real-time event delivery)delivering chat events and notifications in real time — full event content (first names, conversation names, recent messages)USAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Google LLCprocessor (Calendar — § 17) and provider of the Google Meet optioncalendar entries with the student's first name and initial; Meet conferences; the tutor's Google account dataUSAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Zoom Communications, Inc.processor (fallback video provider)meeting title (Learning Space name, lesson topic, date), duration; Zoom-side recording disabledUSAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Featurebaseprocessor (help and user feedback)after clicking "Help & Support": a signed token with the account identifier, e-mail address, first and last name, role, time zone and language (without the date of birth and without the parent's address)USAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
PostHog (EU instance)processor (analytics and session recording) — exclusively in the browser, exclusively after analytics consent, without account identification (pseudonymous events)interaction events, page addresses (may contain technical identifiers), error data; session recordings: a replayable record of what happened in the interface during the session (mouse movements and clicks, scrolling, screen changes and changes of the visible page content) — without camera image, audio or lesson video, with the content of chat messages, the lesson chat and text fields masked (§ 19.4); never for accounts of persons under 18; recordings are stored for no longer than 90 days from recording, then deleted automaticallyEU (EU host)— (processing in the EEA)
Slack Technologies (Salesforce)processor (the team's operational alerts)technical alerts with identifiers (payments, complaints, Stripe accounts) — without names and addressesUSAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Laravel Nightwatchprocessor (application monitoring)data on requests, errors and jobs (may include the account identifier and the request path)USA and others — outside the EEAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
The Ximly support console (a separate operator application)an operator console operated by Ximly personnel — if we entrust its operation to an external entity, we will indicate it in this table as a processor (§ 15)signed webhooks with event identifiers (complaints, appeals, disputes); reading of report data by operators
DiceBear (api.dicebear.com)technical recipient (placeholder avatars fetched by your browser)the account identifier as the image seedoutside the EEAthe connection is established by your browser directly with the service
ui-avatars.comtechnical recipient (conversation avatars fetched by the browser)the conversation/Learning Space name in the URL (may contain a first and last name)outside the EEAthe connection is established by your browser directly with the service
IP geolocation providers: Cloudflare headers (primary, no outbound traffic), as fallbacks ip-api.com, ip2location.io, ipinfo.io, geoPlugin; the local MaxMind databasefallback processorsthe IP address — exclusively when the Cloudflare header is unavailableUSA and othersstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
HERE Global B.V.processor (location suggestions in the tutor profile)the text of the location query typed by the tutorEU/globalstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
Have I Been Pwneda password checking service using k-anonymity (a technique whereby the service cannot determine whose or what password is being checked)exclusively a 5-character prefix of the password hash — no personal data is disclosednot applicable
Operator of the whiteboard synchronization worker (tldraw)processor (lesson whiteboard content)whiteboard content, an access token (one-time, time-limited)outside the EEAstandard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider
YouTube (Google LLC)embedded video players (preview on the tutor profile, watching together in the classroom) — your browser connects to YouTubethe standard data of an embedded player — only after clicking play, at your request (Document D7 § 4)USAthe connection is established by your browser directly with the service
Public authorities (authorities entitled under legal provisions; the Polish National Revenue Administration (Krajowa Administracja Skarbowa, KAS) — when the provisions on reporting by platform operators so require, § 16.4)separate controllersto the extent required by lawPL/EUnot applicable

7.2. Data may also be received by: the tutor you learn with (as a separate controller — § 2.2), other participants of your Learning Spaces and lessons (to the extent visible in the product) and your parent/guardian (to the extent set out in § 4.5).


§ 8. Transfers of data outside the EEA

8.1. Your data may be processed outside the European Economic Area, including in the USA. This applies in particular to the providers indicated in the table in § 7 (among others the infrastructure operator, WorkOS, Expo, Slack, Cloudflare, Stripe — in the group scope, the e-mail providers). The earlier declaration that data is stored "exclusively in the EEA" was untrue and is withdrawn.

8.2. The basis for the transfer is — depending on the recipient — a European Commission decision finding an adequate level of protection (including the EU–US Data Privacy Framework for certified recipients) or standard contractual clauses (Article 46(2)(c) GDPR) together with a transfer impact assessment. The mechanism applicable to a given recipient is indicated in the "Transfer mechanism" column in § 7; for recipients outside the EEA we apply standard contractual clauses or equivalent mechanisms in accordance with the agreements with the provider, and if ensuring appropriate safeguards is not possible — we cease the transfer (§ 8.3).

8.3. Fallback clause: if an adequacy decision on which a transfer relies (including the DPF — currently challenged before the CJEU, case C-703/25 P) is annulled or suspended, we continue the transfer exclusively on the basis of standard contractual clauses or we suspend it.

8.4. You can obtain a copy of the safeguards applied (Article 15(2) GDPR) by writing to the address in § 1.2.


§ 9. How long we store data (retention table)

9.1. The periods the system actually enforces (the cleanup jobs run automatically):

CategoryPeriod
Unfinished accounts (with account creation not completed)after 48 hours the account becomes eligible for deletion and is deleted by the next daily cleanup process. Evidentiary exception: if legal evidence is linked to the account (a record of acceptance or presentation of documents, or the evidence of the declaration of being at least 18), the account is anonymized and the evidence itself is retained (§ 9.2)
Technical records of invited parents and unfinished authorizationsafter 72 hours they become eligible for deletion and are deleted by the next daily cleanup process; also deleted upon deletion of the child's account
In-app notifications (together with the rendered content, including message previews)90 days
Push device tokens90 days from last use
Push delivery confirmations (Expo)7 days from the reconciliation of delivery
In-app alerts (dismissed/expired)90 days
Data export archives7 days; the download link valid for 60 minutes
Whiteboard tokensexpired + 1 day
Registration declarations (the acceptance fields together with the IP address and browser information)for the lifetime of the account; declarations from an uncompleted registration are deleted together with the account (after 48 hours, by the next daily cleanup process). Declarations constituting evidence of acceptance or presentation of documents are retained under the rules of § 9.2 — also where the account is deleted or anonymized
Evidence of the declaration of being at least 18 (the fact of ticking, version of the wording, time, IP, user agent)for the lifetime of the account, and after its deletion or anonymization — retained as evidence under the rules of § 9.2 (an append-only register: an entry can be neither changed nor deleted). For an uncompleted registration, an account with such evidence is anonymized after 48 hours, not deleted — the evidence remains
The child's data entered by the parent when creating the child's account (§ 4.3 point 5)for the lifetime of the child's account
A child's account created by a parent that the child has never usedis not deleted automatically — the contract with the parent exists from the moment the account is created (§ 4.3 point 5); deletion takes place at the request of the parent or the child (§ 4.8, § 10.5)

9.2. We store the following categories for the duration of the relationship and for the period of pursuing or defending claims, and after account deletion we retain them on the basis of Article 17(3)(b) and (e) GDPR (the full list of exemptions — § 10.5):

  • payment and settlement documentation and proofs of payment,
  • complaint and dispute documentation,
  • the registers of Warnings and appeals,
  • evidence of consents and deliveries — a single category covering the evidence of document acceptances, the evidence of document presentation (without IP address or user agent), the evidence of the declaration of being at least 18 (with IP address and user agent — § 14.3), the register of guardian authorization events and the register of cookie consents (we retain the register of cookie consents for the accountability of consent — Article 7(1) GDPR; the period of its review is set by our retention map),
  • Learning Space activity logs,
  • the age correction record (§ 3.2, § 11) — with the corrected date of birth, the verbatim reason for the correction supplied by the third party, the operator's identifier, the source and the inventory of obligations drawn up at the correction; an append-only register,
  • content reports (Document D6 § 3) together with the decision and its statement of reasons — including the data of a reporter without an account (first and last name or entity name, e-mail address, the identification of the content, the description of the report): for the time the report is being handled and, after the decision, for the period during which the decision may be contested or claims connected with it may be pursued,
  • the evidence of presentation of the notice about the access to the child and to the parent (§ 3.8, § 4.5) — on the same terms and for the same period as the register of guardian authorization events,
  • the log of the parent's openings of the child's conversations (§ 3.8) — on the same terms and for the same period as the register of guardian authorization events (an append-only register: an entry cannot be changed or deleted); revocation of the authorization or the child turning 18 closes the access (§ 4.5) but does not delete the log — it remains evidence of accountability towards the child.

We store tax and accounting documentation for the periods required by tax law and the Polish Accounting Act (ustawa o rachunkowości).

9.3. Conversations (chat). We store the content of conversations for the lifetime of the participants' accounts; threads linked to a complaint or dispute — until the matter is closed and the limitation period has expired. After the end of the collaboration with a tutor, the parties' access to the conversations is subject to the Knowledge Cut rule (definition: Document D1 § 1.2) described in the Terms of Service (Document D1 § 6).

9.4. Other technical categories. We store raw webhook events received from Stripe, presence events at video lessons, notification delivery records and diagnostic entries of maintenance tools only as long as is necessary for the purpose for which they were collected — respectively: the accountability of settlements, the establishing of attendance, the demonstration of delivery and the fixing of failures — and then we delete them. Access tokens expire on the server side approximately 3 months after issue, and earlier they are invalidated by logging out or removing the session from the list (§ 12.3); an expired token no longer authenticates any request.

9.5. Diagnostic data (error monitoring) may include the content of failed e-mail messages and request payloads on error paths — we store it exclusively for the purpose of fixing failures, with access limited to the technical team.


§ 10. Your rights

10.1. You have the rights under Articles 15–22 GDPR, fulfilled within one month of the request (in complex matters +2 months, with information and the reason within the first month — Article 12(3) GDPR). Channel: the addresses in § 1.2; export and account deletion — self-service in the settings.

10.2. Access (Article 15). We answer an access request by e-mail, covering all the data we store about you — including the content created about you by tutors or by our team (§ 18), with respect for the rights of others. The self-service export (section 10.3) is a portability tool and does not replace a full answer to an access request.

10.3. Data portability (Article 20) — export. In the account settings you can order a JSON archive of your data. We inform you by e-mail when it is ready; the archive is available for 7 days, and the download link is valid for 60 minutes (it can be downloaded again). The scope of the archive includes, among others: the account, profiles, devices, notification preferences, the schedule, Learning Spaces, lessons, your messages and the attachment manifest, payments and confirmations, complaints, reviews, Warnings and appeals, evidence of document acceptances, registration declarations, the parked registration answer awaiting the age decision (date of birth and guardian address, if supplied), cookie consents and your privacy requests.

10.4. Rectification (Article 16). Most profile data you can correct yourself in the settings. The date of birth is immutable (§ 3.2) and is not subject to correction by support; the only exception is the 24-hour window in which a parent may correct the date they entered when creating the child's account (§ 3.2). Outside that window the remedial path in the event of a mistake is a new registration with the correct date (§ 3.2); the support team records a date only where an account with a declaration of adulthood turns out to be a minor's account (§ 3.2, § 11). For a student under 16, changing the first name, telephone or avatar requires the guardian's authorization.

10.5. Erasure (Article 17). We describe the actual course of the process — we do not promise "immediate permanent erasure", because that is not how this process works:

  1. You submit the request in the account settings (Privacy and Your Data). You can cancel the request as long as processing has not started.
  2. The request is verified by a support operator. Arrears, open disputes or ongoing payouts do not block the deletion as such — they justify only the retention of specific records (point 4). A refusal or partial refusal always contains the reasons and information on the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO) and on the judicial path (Article 12(4) GDPR).
  3. After approval, the data is anonymized. We delete or overwrite the identifying data — including the account at the login provider, files, exports, notifications, the public profile and the reviews written. The account record is irreversibly pseudonymized: a technical record without contact details remains, which in the ordinary course of operations cannot be linked to you.
  4. What we retain after deletion and why (Article 17(3)(b) and (e) GDPR): payment, settlement and dispute documentation (legal obligations, defence of claims), complaint and appeal documentation, the registers of Warnings, the evidence of document acceptances and presentation, the evidence of the declaration of being at least 18 (together with the IP address and user agent — § 9.1, § 14.3), the register of guardian authorization events (upon revocation — together with the indicated reason), the age correction record (with the corrected date of birth, the verbatim reason and the operator's identifier — § 9.2), the log of the parent's openings of the child's conversations and the evidence of presentation of the notice about the access (for the periods in § 9.2), content reports together with their decisions (§ 9.2), the register of cookie consents, Learning Space activity logs and the record of the deletion request itself. Other people's messages (including those written to you) remain untouched; your messages are redacted. Lesson notes and learning topics and objectives created by the tutor are not covered by the deletion of your account with us — they remain the teaching documentation of the tutor as their separate controller (§ 2.2, § 18.1); the tutor decides the period of their retention, and you may also exercise your rights regarding this content with the tutor.
  5. Data stored by Stripe as a separate controller (KYC) you pursue directly with Stripe; we will point you to the appropriate channel.

The one-month period of section 10.1 also covers this process and is our commitment.

10.6. Restriction of processing (Article 18). You submit the request via the channels in § 1.2. For the duration of the restriction we only store the data it concerns — we do not use it in any other way, except with your consent or for the establishment, exercise or defence of claims. We notify you of the lifting of the restriction before it is lifted (Article 18(2) and (3) GDPR).

10.7. Objection (Article 21). Against processing based on legitimate interest (§ 5) you may object at any time via the channels in § 1.2; we will indicate which operations we have suspended, or we will demonstrate overriding grounds.

10.8. Withdrawal of consent (Article 7(3)). The only processing operations based on consent are analytics (Document D7 — the withdrawal mechanism is there) and guardian authorization in the scope of the data of a child under 16 (withdrawal — § 4.6). Withdrawal does not affect the lawfulness of the processing carried out before the withdrawal.

10.9. The child's rights exercised by the guardian. A parent with an active authorization — granted when approving the child's account or when creating it (§ 4.3 point 5) — exercises the child's rights via the parent panel (the consent register, revocation) and via the channels in § 1.2 — in every matter concerning the child's data. Access to the complaint and payment surfaces that follows from being the party to the contract and the payer of a given lesson does not lapse with the revocation of the authorization or with the child reaching the age of majority: it concerns exclusively lessons contracted while the authority was in force, for which the parent remains liable (Document D1 § 4.8 and § 4.9).

10.10. Complaint. You have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych; ul. Stawki 2, 00-193 Warszawa; uodo.gov.pl) and to seek protection before a court.


§ 11. Automated decisions

11.1. Some decisions on the platform are made automatically, without human involvement. Below is the catalogue of those decisions together with the rules, the significance and the consequences (Article 13(2)(f) GDPR). We cite the values of the thresholds and time windows for information — the host documents are their binding source (the Cancellation Policy — Document D4; the Terms of Service — Document D1; the reserve parameters — Document D2-P § 5).

DecisionRuleEffectProtection measure
Calculation of the refund upon lesson cancellationautomatic time thresholds with a deduction cap — values in Document D4 § 3; the version of the thresholds covered by your consent is frozen at bookingthe refund is calculated without discretiona Lesson Complaint (Document D4 § 10); contacting support
Withholding the payout of the tutor's remuneration after a lessonafter the lesson ends, the tutor's remuneration is automatically withheld for the duration of the payout hold window — the parameter in Document D4 § 10; filing a Lesson Complaint within that window maintains the withholding until resolutionthe funds do not reach the tutor until the window elapses or the Complaint is resolvedthe expiry of the window does not close the Complaint path — after it, the report is received by the support team; the chargeback and the statutory rights remain unaffected
Handling a Lesson Complaint within the deadlinewe handle a Complaint within 14 days of its filing; the absence of a resolution within that period means the Complaint is deemed upheld (Article 7a of the Polish Consumer Rights Act (ustawa o prawach konsumenta))the Complaint is upheld in your favourrequires no action; before the maximum funds-hold period elapses, the matter is taken over by an employee of the support team, and a resolution is never made automatically to the consumer's detriment
Booking block for arrearsan obligation from a Payment Group (definition: Document D1 § 1.2) unpaid for more than 14 days after the group's payment deadline — regardless of the settlement method; under direct settlement with the Tutor the block is additionally triggered by the rejection of a payment confirmation, and immediately, without that grace perioda block on new bookings with all tutors, until repayment (lifted automatically)repayment; for a rejected confirmation — an appeal within 14 days, the filing of which suspends this block; contacting support
Warnings and the permanent blockthe rejection of a payment confirmation in circumstances indicating abuse results in a Warning (definition: Document D1 § 1.2); 3 active Warnings = a permanent booking block; Warnings do not expire on their own — they disappear after settlement, an upheld appeal or a decision of the support teama booking blockan appeal within 14 days — considered by a human (the support team); filing the appeal suspends the Warning and the block
Automatic resolution of the tutor's review of a paymentif the tutor does not review a reported payment within 14 days, the system resolves in favour of the student/payer (a refund or a cancellation of the debt)favourable to yourequires no action
Recalculation of settlements upon the tutor's change of cyclea change of the settlement cycle recalculates the Payment Groups (definition: Document D1 § 1.2); lessons already held become dueearlier due datesthe rules and procedure — Document D1 § 8; a complaint/contacting support
Derived parent–child blocksan arrear or block of the payer-parent (including a block for Warnings) blocks the child's bookings (the child is not the debtor)the child cannot book a lesson until the parent actsthe parent's action; the appeal against the Warnings lies with the payer-parent
Daily cancellation limita maximum of 10 cancellations per daya further cancellation that day is rejected; the limit resets at midnight (UTC)the limit does not restrict the statutory right of withdrawal (Document D1 § 10)
Age qualification based on the declaration of adulthood or the date of birthfrom the declaration of being at least 18 or from the date of birth provided the system automatically determines the age band: under 13 / 13–15 / 16–17 / adult; a future date is treated as an age under 13, and the absence of both a declaration and a date — as an unknown age (§ 4.1)under 13: blocking of the account and the start of data deletion (§ 4.1); 13–15: the guardian authorization gate together with consent to data processing (Article 8 GDPR); 16–17: the guardian authorization gate in matters of contracts and payments; unknown age: access limited to a narrow list of actions; the selection of the Tutor role with an unknown age or an age under 18 is rejected (a tutor's adulthood may follow from the declaration alone — Document D1 § 4.10)contesting the qualification via the channels in § 1.2 — the matter is examined by the support team; the date of birth is subject to correction only within the window of § 3.2 (§ 10.4)
Conversion of a child's account into an independent accounton the student's 18th birthday — also for an account created by the parent — the system automatically ends the guardian's authority (§ 4.7)the student becomes an independent party to the contract for the future; sessions are invalidated, and further use requires acceptance of the Terms of Service under the student's own account; obligations from before the 18th birthday remain with the parentno action required; doubts as to the date — via the channels in § 1.2, the matter is examined by the support team
Block upon detection of a false declaration of adulthoodwhen we receive credible information (e.g. a report from a tutor or a parent) that a person who declared being at least 18 is a minor — the decision to correct is made by the support team, and its direct effects are executed by the system automaticallyrecording of the corrected date of birth (the correction register — § 3.2) and invalidation of sessions; the account moves to the path involving a parent (13–17) or is blocked and deleted (under 13); the system draws up an inventory of the account's lesson obligations but does not settle them — the settlement (cancellations without debt, refund of the entire amount for lessons paid for but not held) is carried out manually by the support team (Document D1 § 4.2)contesting via the channels in § 1.2 — the matter is examined by a human (the support team); you may present your position and demonstrate your age

11.2. The right to human intervention (Article 22(3) GDPR). We undertake to provide, for each of the above decisions, a path for verification by a human, for presenting your position and for contesting the decision. You trigger the verification path via the channels in § 1.2, and in the matter of Warnings from rejected payments — by the formalized appeal within 14 days.

11.3. We do not profile you for marketing purposes.


§ 12. Data security

12.1. We apply technical and organizational measures appropriate to the risk, including: encryption of transmission (TLS), passwordless login with one-time codes and MFA, role-based access control, immutable evidentiary registers and separation of environments. We store user files (attachments, proofs of payment, export archives) in private storage, with access exclusively via short-lived signed links.

12.2. We deliberately do not make in this document general promises (e.g. "all data is encrypted at rest") that we could not demonstrate. We maintain a detailed description of the measures in internal documentation (Article 32 GDPR).

12.3. You manage your session in the settings: the list of active sessions shows the approximate location and the device and allows you to log out the other devices. The login cookie is valid for 90 days; the access token expires on the server side, and independently of that it is invalidated by logging out or removing the session from the list (see also Document D7 § 2).


§ 13. What messages you receive from us

13.1. Service communication (Article 6(1)(b) and (f) GDPR): bookings, reminders, cancellations and date changes, invitations, payments (payment requests, confirmations, refunds, disputes, arrears), chat messages and notifications, account and login matters, notices of changes to the legal documents. We send it by e-mail, push notification and an in-app entry.

13.2. The preference centre in the account settings allows you to switch categories off separately for each channel. The following categories cannot be switched off: authentication/security and legal notices (they are necessary for the performance of the contract and legal obligations). We send welcome messages once. An entry on the in-app notification list is always created, also with e-mail/push switched off.

13.3. Commercial information (marketing): we currently send none. We run no newsletter, we send no promotions via any channel and we collect no marketing consents. The start of such communication will be preceded by: a separate, voluntary and revocable consent mechanism (Article 398 PKE, Article 7 GDPR), a working opt-out mechanism in every message and an update of this Policy.

13.4. Informational-promotional banners in the application may appear on users' dashboards; we display them on the basis of legitimate interest (marketing of our own services, Article 6(1)(f) GDPR) and with targeting exclusively by the account language — without profiling. We direct no behavioural marketing at minors (§ 13.6). You have the right to object (§ 10.7).

13.5. Chat message content in notifications. A push notification about a new message contains up to 100 characters of its content (it reaches the device's lock screen via the push provider), and the digest e-mail about unread messages — the conversation name, the sender and a preview of up to 100 characters (it goes via the e-mail provider). The rendered content of notifications is stored on the in-app notification list for 90 days (§ 9).

13.6. Minors: we direct no consent-based communication and no behavioural marketing at persons under 16 and we do not profile them; we adopt the principle of no profiled advertising towards all persons under 18.


§ 14. Technical and session data

14.1. For account security and for setting the language/time zone we process, when the API is used: the IP address, the approximate location derived from the IP (country, region, city — not an exact one), the time zone, the operating system, the browser and the device type. We update this data no more often than every 15 minutes per session and store it in encrypted form with the session token. You see it on the session list in the settings.

14.2. Location recognition relies in the first instance on the header of our infrastructure (Cloudflare — with no outbound traffic); only when it is unavailable may the IP address be sent to the fallback geolocation providers indicated in § 7. Basis: Article 6(1)(f) GDPR.

14.3. We also record the IP address and user agent permanently as an element of evidentiary material: at document acceptances, at the declaration of being at least 18, at cookie consents and guardian authorization events (§ 3.8). In the support operations log (§ 15.2) we record the IP address without the user agent and delete that log after 30 days. Evidence of document presentation (§ 3.8) contains neither an IP address nor a user agent. The evidentiary records of the first sentence are retained also after the deletion or anonymization of the account (§ 9.2, § 10.5 point 4); the IP address and user agent from registration declarations concerning documents, on the other hand, are deleted together with the account (§ 9.1).

14.4. The access token expires on the server side; the login cookie is valid for 90 days. The control is the session list (§ 12.3) — logging out invalidates the credential.


§ 15. Support team access

15.1. Reports, complaints, disputes, appeals and account deletion requests are handled by the Ximly support team. The operator sees the data necessary to resolve the matter — including the complaint content, the payment and dispute documentation and (for a deletion request) the requester's first name, surname and e-mail address. Operators have no access to browsing your conversations — with one exception: where a specific message has been reported (Document D6 § 3), the operator handling the report sees that single reported message — its content, sender, time of sending and attachment metadata (file name, type and size) — including where it has already been deleted (it remains preserved as case material). The operator does not see the other messages of the conversation.

15.2. Every request in the console is logged (method, path, IP address, result, operator designation) for 30 days, and decisions (resolutions of complaints, appeals, deletion requests, lifting of Warnings) are permanently attributed to the operator designation in the case record and stored together with the case files for the entire period during which the case may be the subject of an appeal or a claim.

15.3. Confidentiality commitment: we share the content of your reports with the other party to a dispute exclusively to the extent necessary for them to take a position (rules — Document D1 § 12 and Document D2 § 9).


§ 16. Payments and tutor verification (KYC)

16.1. Card payments are handled by Stripe. We pass to Stripe the identifiers necessary for the settlement (the payment, lesson, Learning Space and account identifiers) and the payer's e-mail address; for obligations concerning a student under 18 the payer is the parent and it is the parent's data that enters the payment process (§ 4.2). You provide the card number exclusively to Stripe.

16.2. Tutors: identity verification (KYC) is conducted by Stripe as a separate controller: identity documents and settlement data go directly to Stripe. The connected account is created by the Platform as an individual's account; a tutor conducting activity in another form (e.g. a company) completes or corrects their entity's data directly in the Stripe panel (Document D2 § 7.1). We store locally: the KYC requirements status received from Stripe (including the list of deficiencies), the state of the connected account and the reason for any restriction (the latter is visible exclusively to the support team — it is sometimes marked by Stripe as sensitive), and the raw webhook events from Stripe (a webhook — an automatic technical message by which Stripe notifies us of events on the account) for the accountability of settlements.

16.3. Disputes and chargebacks: in the event of a dispute we compile and pass to Stripe (and, through it, to the card issuer) an evidence package which may include the record of your consent to the cancellation policy (version, date) and the lesson and payment documentation.

16.4. Platform tax reporting (DAC7): where the law so requires, Ximly will implement the reporting obligations of a platform operator (DAC7) towards the Polish National Revenue Administration (Krajowa Administracja Skarbowa, KAS). At present we do not collect identification or tax data from tutors for that purpose (§ 3.7, § 3.9); before we start collecting such data we will inform Tutors of its scope and update this Policy.


§ 17. The Google Calendar integration and video lessons

(Sections 17.1–17.4 are written to you — the tutor; sections 17.3 and 17.5 also concern students.)

17.1. As a tutor you may connect a Google account. The integration requests full read and write access to the calendar (and basic Google profile data); a connection without the full scope is rejected. Writing serves the creation, updating and deletion of lesson events; reading — the hourly checking of collisions of your other events with your availability (we block colliding slots).

17.2. We store: the e-mail address and identifier of the Google account, the profile data returned at connection and the refresh token — until the integration is disconnected (disconnection invalidates the token on the Google side and deletes our record). A daily job refreshes the token so that the integration does not expire.

17.3. The lesson events written to the tutor's calendar contain the student's first name and the initial of the surname and the lesson times; they are created as private, and guests cannot invite other persons. The ICS invitations sent to students by e-mail indicate the Ximly calendar address as the organizer.

17.4. Google Limited Use statement: Ximly's use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This means in particular: no sale of this data, no advertising based on it, no creditworthiness assessment and no training of AI models on this data.

17.5. Video lessons are conducted by us on Cloudflare Realtime (the participant is presented with their first and last name, account identifier and avatar); as a fallback — on Zoom (the meeting described with the Learning Space name and the topic; Zoom-side recording disabled). We record presence events (who joined and left, and when) for the purposes of attendance and settlements. We do not record lessons — see § 19.3 and Document D1 § 6.


§ 18. Content about you and the data you make public

18.1. Content created about you by the tutor: notes (you see only the published ones; drafts are private to the tutor), learning topics and objectives, the absence note (private to the tutor, but returned in your data export). You access this content in the product and by a request under Article 15 (§ 10.2). Notes and learning topics and objectives are the teaching documentation of the tutor as their separate controller (§ 2.2) and are not deleted together with your account with us (§ 10.5); we delete the absence note when your account is deleted.

18.2. Content created about you by us: the reasons for Warnings and blocks, the resolutions of complaints and appeals, the documentation of privacy requests.

18.3. A caution (Article 9 GDPR): the platform's text fields (chat, notes, complaint descriptions, absence reasons) are not intended for conveying health data or other special categories of data. Please do not enter it; anything entered we treat exclusively as the author's free-text content and delete on request.

18.4. The tutor profile is visible to logged-in users of the platform (it includes, among others, the first and last name, a description, the approximate location, YouTube video material). Reviews of a tutor are published with the author identified by their first name and the initial of the surname (if an adult author has no surname on record — by the first name alone); a review whose author was under 18 at the moment of posting is published exclusively with the author's first name (without the surname and without its initial) and with a neutral avatar containing no likeness and no elements derived from the data or identifiers of the author's account (Document D8 § 9.3). Reviews and the profile are deleted together with the author's account.

18.5. Placeholder avatars are generated by external services (DiceBear — on the basis of the account identifier; ui-avatars — on the basis of the conversation name): your browser fetches the image directly from these services (§ 7). This does not apply to the avatar accompanying a review whose author was under 18 at the moment of posting — such an avatar is neutral and is not created on the basis of the data or identifiers of the author's account (§ 18.4).

18.6. Classroom artefacts: the lesson chat, the whiteboard, the files and the attendance records remain in the Learning Space under the rules described in the Terms of Service (Document D1 § 6), including the Knowledge Cut rule after the end of the collaboration.


§ 19. Artificial intelligence and recording

19.1. We do not use artificial intelligence features. None of your data — including the content of conversations — is processed by AI systems or used to train models. The earlier provisions on "AI consents" are withdrawn as moot.

19.2. If in the future we introduce an AI feature: we will inform you in advance, indicate the legal basis and, where the law so requires, ask for a separate consent; we will carry out or update a data protection impact assessment (DPIA). Hard limits: no emotion recognition and no profiling of minors.

19.3. Lesson recording: we do not record. The platform does not record lessons (audio or video) and does not store recordings; recording on the side of the fallback video provider is disabled. The rules concerning possible recording by participants — Document D6.

19.4. Session recording in the browser (analytics): we do record — exclusively upon your consent. Irrespective of § 19.3, the analytics tool (PostHog — § 7.1) has session recording enabled: a replayable record of what happened in the application interface during your session — mouse movements and clicks, scrolling, screen changes and changes of the visible page content. The recording does not include camera image, audio or lesson video. The content of chat messages, the lesson chat and text fields is masked in the recording (replaced with placeholder characters) and does not reach the analytics tool — this applies to all accounts, because a conversation always contains the other party's messages as well. Recording starts exclusively after analytics consent in the cookie banner (Document D7 § 3) and never for accounts of persons under 18 or of unknown age — even where a person aged 16–17 has given analytics consent (the remaining analytics operates for them on the terms of § 4.9); withdrawing consent stops it immediately. Recordings are pseudonymous (a random identifier, not the account), stored in the EU instance for no longer than 90 days, and then deleted automatically. They serve only to understand how the product works and where errors occur; they are not used to assess users or to make decisions about them.


§ 20. Where we have your data from (sources — Article 14 GDPR)

20.1. The data you do not provide to us yourself:

  • from your child — the parent's e-mail address indicated at authorization (§ 4.4);
  • from your parent/guardian — if the account was created for you by your parent (§ 4.3 point 5): first and last name, date of birth and e-mail address; we show you this information at the first login in the web application, before you enter the panel (§ 20.2);
  • from the inviting person — the e-mail address of a person invited to a Learning Space or to a lesson;
  • from identity providers (Google, Apple, Microsoft via WorkOS) — profile data at login;
  • from Stripe — the KYC verification status and the state of the tutor's account;
  • from infrastructure providers — the approximate geolocation from the IP address, presence events at video lessons, notification delivery confirmations;
  • from other users — content in which they write about you (reviews, notes, reports, complaints).

20.2. We provide the information notice for persons whose data we have obtained from someone else at the latest with the first message to that person. To a child whose account was created by a parent we provide it on a screen at the first login in the web application, in a version adapted to their age (Document D8 § 12); that notice covers at least: an indication of who provided us with the child's data and which data, the rights the child has, the instruction on the right to lodge a complaint with the supervisory authority (the President of the Personal Data Protection Office — § 10.10), and a link to the full text of this Policy. We record the fact of its presentation (§ 3.8).


§ 21. Changes to this Policy and complaints

21.1. The Policy is versioned separately for each language; each version has a permanent address and a cryptographic hash of its content (SHA-256), and the archive of versions remains available. We give notice of every change by e-mail and by an in-app entry (legal notices cannot be switched off) — with an announcement at least 7 days before the changes take effect.

21.2. Continued use of the platform after the changes take effect requires confirming that you have read the new version. Even without the confirmation you retain access to: logging out, data export, account deletion, reading the documents, and a tutor — to the payout of their funds.

21.3. You may lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO) (§ 10.10). This Policy does not limit any of your statutory rights.