Privacy Notice
Last updated 12 August 2026.
EasyTutor is a workspace that tutors use to run their teaching business. This notice explains what personal data we hold, why we hold it, and what you can ask us to do with it. It is written to meet the Personal Data Protection Act 2010 (Malaysia).
Who is responsible for the data
The tutor or tuition centre that creates a workspace decides what to record about their students and guardians — they are the data user. EasyTutor processes that data on their instructions in order to provide the service. For your own account details, EasyTutor is the data user.
What we collect
- Account data — your name, email address, hashed password, role and workspace name.
- Records you enter — students, guardians, contact numbers, classes, schedules, attendance, progress notes, recording links, invoices and payments.
- Billing data — subscription status and bill history. Payments run through Billplz over FPX; we never see or store your banking credentials or card numbers.
- Technical data — sign-in timestamps, audit records of important changes, and standard server logs used to keep the service secure and available.
Students who are minors
Most students recorded in EasyTutor are children. The tutor who enters a child's details is responsible for obtaining consent from that child's parent or guardian first. Do not record more about a child than your teaching actually requires. We do not use student data to build profiles, and we never use it for advertising.
Why we process it
To operate your workspace, authenticate you, issue and collect subscription payments, send service messages such as email verification and password resets, keep an audit trail, and protect the service against abuse. We do not sell personal data, and we do not share it for anyone else's marketing.
Who else processes it
We use a small number of service providers, each handling only what their function requires:
- Vercel — application hosting and logs.
- Neon — the PostgreSQL database holding your workspace records.
- Resend — delivery of account and billing emails.
- Billplz — payment processing over FPX.
- Google — only if you choose to connect Drive or Meet. Access is read-only, limited to folders you select, and you can disconnect at any time.
- Meta — a measurement pixel on our public pages only, so we can tell which advertisements lead to sign-ups. It records the marketing page visited and whether an account was created. It is not present anywhere inside your workspace or the parent portal, so no student, guardian, attendance or payment record is ever sent to Meta.
Some of these providers store or process data outside Malaysia. We rely on their contractual data-protection terms for those transfers.
How long we keep it
Workspace records are kept for as long as your workspace exists. When you schedule deletion from Settings, there is a 7-day recovery window, after which the data is permanently removed. Backups are retained on a rolling basis and are overwritten in the normal course. Limited billing records may be kept longer where Malaysian law requires it.
Security
Passwords are stored using bcrypt and are never recoverable in plain text. Each workspace is isolated at the database level, so one workspace cannot read another's records. Google refresh tokens are encrypted with AES-256-GCM before storage. Traffic is served over HTTPS only.
Your rights
You may ask us to access, correct, or delete your personal data, to limit how it is processed, or to withdraw consent. You can export a complete machine-readable copy of your workspace at any time from Settings, and schedule its deletion from the same place. If you are a student or guardian whose details were entered by a tutor, contact that tutor first — they control those records — and contact us if you cannot reach them.
Cookies
EasyTutor sets one essential cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
Changes
If we make a material change to this notice, we will tell workspace owners by email before it takes effect.
Contact
To exercise any of the rights above, or to ask how your data is handled: use our contact form. See also our Terms of Use.