Privacy Policy
Last updated: 1 June 2025
This Privacy Policy explains how Noktua Academy("we", "us", "our") collects, uses, stores, and protects your personal data when you visit https://noktuaacademy.com or use our online tutoring services.
1. Who We Are — Data Controller
Noktua Academy is the data controller for personal data collected through this platform. We deliver live online mathematics tutoring via video call.
Contact: info@noktuaacademy.com
2. Personal Data We Collect
- •Account data: name, email address, authentication credentials (managed by Clerk)
- •Session data: booking history, session notes, homework files
- •Communication data: messages sent through the contact form
- •Technical data: IP address, browser type, country code (for legal compliance only)
3. How We Use Your Data
- •Create and manage your account
- •Schedule and deliver online tutoring sessions
- •Send session notes, homework, and progress updates
- •Respond to enquiries from the contact form
- •Comply with legal obligations including age verification and consent records
4. Legal Basis for Processing (EU/UK Users)
- •Consent (Art. 6(1)(a) GDPR): age verification and processing data relating to minors
- •Contract (Art. 6(1)(b) GDPR): delivering sessions and managing your account
- •Legal obligation (Art. 6(1)(c) GDPR): retaining records required by law
5. Children's Privacy
Noktua Academy provides tutoring to students of all ages. We take the privacy of younger users extremely seriously.
5.1 EU & UK Users — GDPR-K (Article 8 GDPR)
Under Article 8 GDPR, the minimum age for a child to consent to online data processing is 16 years. For students under 16, a parent or legal guardian must give consent before we process any personal data.
- •Users under 16 are directed to ask a parent/guardian to register on their behalf.
- •Parent/guardian consent is collected at account sign-up and stored with a timestamp.
- •Parents may withdraw consent at any time by emailing info@noktuaacademy.com — we will delete the account within 30 days.
- •We do not use data of EU/UK minors for any purpose other than the agreed tutoring service.
5.2 US Users — COPPA
Under COPPA, children under 13 require verifiable parental consent before we may collect or process their data.
- •We do not knowingly collect data from children under 13 without parental consent.
- •US users under 13 are directed to have a parent/guardian register on their behalf.
- •Parents may review, correct, or request deletion of their child's data at any time.
5.3 All Other Jurisdictions
We apply a default minimum age of 13 as a conservative baseline for all other countries.
6. How We Share Your Data
We do not sell your data. We share it only with these service providers:
- •Clerk — authentication and session management
- •Supabase / PostgreSQL — session records, notes, files
- •Cal.com — booking and scheduling
- •Vercel — website hosting
7. International Data Transfers
Some providers (including Clerk and Vercel) are based in the US. Transfers of EU/UK data are covered by Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework.
8. Data Retention
- •Account data: retained while the account is active, plus 12 months after deletion
- •Session notes and files: 12 months after the last session
- •Consent records: 5 years (legal compliance)
- •Data of minors: deleted within 30 days of a parental deletion request
9. Your Rights
9.1 EU/UK Rights (GDPR)
- •Access — obtain a copy of your personal data
- •Rectification — correct inaccurate data
- •Erasure — request deletion of your data
- •Portability — receive your data in a machine-readable format
- •Object — object to processing based on legitimate interests
- •Withdraw consent — at any time, without affecting prior processing
- •Complain — lodge a complaint with your national data protection authority
9.2 US Rights
- •Request access to or deletion of your personal data
- •Parents: review, correct, and delete your child's information
- •Opt out of any marketing communications
To exercise any right, email info@noktuaacademy.com. We respond within 30 days.
10. Cookies & Storage
- •nkt-consent-v1 (localStorage): records that you completed the consent flow. Never sent to our servers.
- •nkt-country (cookie, 24 h): your detected country code for jurisdiction rules. Not personally identifiable.
- •Clerk cookies: required for login sessions. Managed by Clerk.
We do not use advertising or tracking cookies.
11. Security
We use HTTPS, database access controls, and authentication handled by Clerk. No method of internet transmission is 100% secure, but we take appropriate measures to protect your data.
12. Changes to This Policy
We may update this policy and will update the date above when we do. Material changes will be communicated by email or a prominent notice on the website.
13. Contact Us
EU/UK users may also complain to their national supervisory authority (e.g. ICO in the UK, CNPD in Portugal).