Basam Tutor · Australia
Privacy Policy
Effective upon publication · Policy version 2026-10-10
Legal and privacy contact: support@basamtutor.com
1. Who is responsible and how to contact us
Basam Technology Limited operates Basam Tutor and decides how personal information is used for the marketplace. Its public company and contact details appear with these policies and on the Contact page. Send privacy enquiries, rights requests or complaints to support@basamtutor.com, marked "Privacy".
Google sign-in is optional. If you choose it, we receive your verified email address, name and a Google account identifier to create or securely link your Basam Tutor account and authenticate you. We request only basic identity, email and profile access, and do not request your Google password, contacts, Drive files or Gmail messages. We retain a hashed provider identifier for the account link. Temporary sign-in context expires after ten minutes and is removed when consumed or during a subsequent sign-in cleanup. Google processes the sign-in under its own privacy notice. You must still complete the required marketplace and role details, accept our Terms and acknowledge this Privacy Policy; Google sign-in does not replace parental permissions, tutor approval or account security checks. Existing accounts are linked only after fresh authentication to the matching Basam Tutor account, including enabled multi-factor authentication.
Contact support@basamtutor.com for the person responsible for privacy and any applicable appointed local representative or data protection officer. We provide relevant appointed contact details when required. The local supplement identifies additional rights and regulators. This policy covers learners, guardians, tutors, visitors and people contacting support; employment information is governed separately.
2. A practical summary
We use information to provide tutoring discovery, accounts, messages, bookings, classroom tools, payments, verification, support and safety. Authorized lesson participants see the information needed for that interaction; selected tutor profile details are public. Payment, hosting and communication providers receive information required for their roles. We do not treat a Terms checkbox as permission for all optional uses. Marketing, optional tracking, publicity and recordings have their own choices where applicable.
You can ask about your information, change relevant preferences and request correction, access or deletion. Deletion can be limited by justified financial, safety or legal record-keeping duties. The sections below explain recipients, international processing and retention criteria. Ask the privacy contact for information about an applicable provider, destination country or safeguard.
3. Information we collect and its sources
| Category | Examples and usual source |
|---|---|
| Account and contact | Name, email, telephone, country, timezone, role, login/session records and password hash, supplied by you or generated during account use. |
| Learner and guardian | Learner identity, guardian relationship, age/date of birth where collected for a legitimate purpose, grade, subject preferences, goals and permission records, supplied by the learner or authorized guardian. |
| Tutor and verification | Public profile, photo, qualifications, experience, subjects, rates, availability, identity/qualification documents, verification decisions and relevant checks, supplied by the tutor or an authorized verification source. |
| Lessons and communications | Proposals, bookings, rescheduling, attendance, in-platform messages, shared whiteboard work, files, notes and support messages, supplied by participants or generated by the service. |
| Financial | Amount/currency, transaction reference, payment status, invoices, refunds, ledger entries, commission, subscription and payout details, supplied by you, tutors or payment providers. |
| Technical and safety | IP address, browser/device information, timestamps, approximate country, authentication and fraud events, reports, diagnostic errors and performance measurements, generated during use or supplied by a reporter. |
| Choices | Policy version/acceptance, cookie and notification preferences, marketing permission and relevant parental or recording permissions, supplied through your choices. |
We may receive information about you from a guardian, another lesson participant, payment provider, a person making a safety report, or a verification source whose role is disclosed. We do not assume all third-party allegations are accurate. Where required, we provide notice of indirectly collected information unless a lawful exception applies.
Do not send complete payment-card credentials, medical histories or unrelated identity documents through ordinary chat. If a particular verification or learning accommodation needs sensitive information, we explain what is needed and limit its use. An identity photo does not by itself mean that biometric recognition is being performed. Any biometric processing requires an appropriate notice and lawful conditions.
4. Purposes and legal grounds
Where the applicable law requires a lawful basis, we identify the basis for the purpose and individual concerned. In particular, a guardian's contract does not automatically justify every use of a child's information. The following describes the purposes and grounds applicable according to the processing and governing law.
| Purpose | Information used | Legal ground, where applicable |
|---|---|---|
| Create and administer an account; provide agreed bookings, messages and classroom functions | Account, lesson and communication data reasonably needed | Necessary steps for or performance of the individual's contract; another assessed basis for a dependent learner. |
| Process charges, refunds, subscriptions and tutor payouts | Contact, transaction, invoice and payout data | Contract necessity; legal financial/tax duties where actually applicable. |
| Prevent misuse, secure accounts and investigate service failures | Sessions, technical events, reports and limited relevant content | Legitimate interests in a safe, reliable marketplace where legally available, after balancing rights; legal duties where applicable. |
| Verify tutors and protect learners | Proportionate documents, verification results and relevant safety evidence | Applicable legal duty, a properly assessed legitimate interest or consent where that is the appropriate basis. |
| Respond to support and privacy requests | Contact, case and relevant transaction records | Contract or legitimate interests in resolving requests; legal obligation for statutory rights. |
| Send necessary service notices | Contact, notification preferences and booking/security context | Contract or safety/security interests; not an automatic marketing opt-in. |
| Optional marketing, optional cookies and promotional testimonials | Contact/preferences or separately permitted content | Specific consent where required, or another lawful route that has been assessed and disclosed. |
| Emergency protection or lawful authority requests | Necessary information proportionate to the event | Vital interests or applicable legal obligations, only where the conditions are met. |
Where consent is used, we identify the purpose, allow refusal of unrelated optional uses and provide a withdrawal route. Withdrawal does not retrospectively invalidate lawful prior processing. Where we rely on legitimate interests, the intended interests are service security, fraud prevention, safeguarding, proportionate verification and efficient support; you may object as explained below. Sensitive data requires an additional applicable condition; ordinary contract language is insufficient.
5. Public profiles and information shared with participants
Approved public tutor listings may display the tutor's chosen name, profile image, biography, described qualifications, subjects, rates, general location, reviews and published availability. Tutors can review the relevant profile fields and must not add a home address, private phone number or email to a public biography. Private learner, guardian, payment and verification information is not public tutor-profile content.
Learners, guardians and tutors receive the lesson identity, timing and other information necessary to arrange or deliver their authorized lesson. Conversation and classroom participants can see the content you share with them. Guardian access is linked to the relevant learner context and lawful authority, not permission to view every conversation on the platform. Recipient tutors may have their own responsibilities for information they lawfully keep; they must not repurpose it for unrelated marketing.
6. Classroom media, whiteboards and device permissions
Joining an online lesson can involve camera video, microphone audio and screen sharing you activate. Your browser asks for the relevant device permission. The service exchanges connection and session information needed to connect participants; networking/relay services and a connected peer can receive network addresses or connection metadata. Do not assume your IP address is concealed from every participant. Screen sharing may expose notifications or other material on the selected screen.
Shared whiteboard pages, changes and uploads may be transmitted and saved to synchronize a lesson or recover its work. A saved whiteboard or attendance record differs from an audio/video recording. Live drawing previews are temporary and do not themselves change the saved page. We do not authorize covert recordings by participants.
If we introduce an optional recording, its separate notice must state what is captured, who can access it, the purpose, processor/location, retention, deletion arrangements and required permissions before recording begins. This policy does not authorize using private lesson content to train general-purpose AI models. Any future AI feature involving such content needs a separate assessment and notice, and permission where required.
7. Providers and other disclosures
We disclose only information reasonably needed for the recipient's role. Providers may act on our instructions, or as independent controllers for their own legal and payment obligations. A provider's status must be determined from its actual contract and processing; it cannot simply be labelled a processor for every activity.
| Recipient category | Relevant role and disclosure |
|---|---|
| Hosting, database, private file storage and backup | Store and operate account/service records; restricted technical access and recovery. AccuWebHosting supplies hosting/CDP services; contact us for the processing destinations relevant to your information. |
| Activated payment and payout services | Process financial transactions and applicable verification/anti-fraud checks. Providers can include Stripe, Paystack, Flutterwave or Foren only when activated for your transaction. The available provider is identified in the payment flow. |
| Email/SMS or approved support providers | Deliver authorized messages and handle provider delivery status. Email may be delivered through Brevo. Other communication providers receive information only for the channel actually enabled. |
| Classroom connectivity | Carry connection/relay metadata and, depending on architecture, encrypted media traffic. Connection/relay services receive the information necessary for the enabled classroom connection; ask us for relevant supplier and destination details. |
| Verification or screening services | Perform only the verification or screening checks actually activated and disclosed for the relevant purpose. |
| Optional measurement or advertising providers | Receive information only under an enabled lawful arrangement with applicable notice, choice and controls. |
| Authorized staff, advisers, authorities or business successor | Limited access for support, legal advice, investigations, legally justified disclosures or a business transfer with appropriate protection and notice. |
Disclosure to a service provider for the service is distinct from disclosure for that provider's own advertising. Any sale, advertising sharing or targeted-advertising arrangement must have the notice, permission and opt-out required by applicable law. You may ask the privacy contact whether a particular enabled service involves those activities and exercise applicable opt-out rights. Children's private learning, safeguarding and verification information must not be used for unrelated advertising.
8. International processing and safeguards
People in different countries may participate in one lesson. Hosting, backup, file-storage, communication, payment, connectivity or authorized support providers may process information outside your residence. We identify relevant processing destinations and safeguards in applicable collection notices or on request to the privacy contact. Foreign authorities may have access under the law governing the recipient.
Before a restricted international transfer, we assess the legally applicable route and recipient protection. Depending on the law and transaction, this may require a valid adequacy route, approved contractual safeguards, a transfer assessment and supplementary protection, or a narrowly applicable exception. Accepting this policy is not a universal transfer authorization. You may request information about applicable safeguards, with legitimate confidential material protected.
9. Cookies, local storage and communications choices
Necessary storage and session technologies support sign-in, security and core functions. Optional categories include preferences, analytics and marketing where enabled. Cookie settings provide category choices. Optional collection requiring permission must remain disabled until that permission is obtained; withdrawing permission stops the relevant future optional collection.
Cookie settings and the applicable collection notices explain enabled optional categories and controls. You may ask the privacy contact for active cookie/storage items, providers, purposes and durations. Browser restrictions may affect functionality. Authentication, country preferences and classroom recovery storage are assessed according to their actual use rather than all being automatically classified as necessary.
Choose notification preferences in account settings where supported. Necessary security, account, payment and legal notices may still be sent. Optional marketing requires the applicable permission and an effective unsubscribe route. We do not add a learner to advertising campaigns merely because their guardian booked a lesson.
10. Retention and deletion
We keep identifiable information for a defined purpose and the period justified by that purpose, legal obligations and disputes. A legal hold may extend a period for the affected records, with restricted access. We delete or appropriately de-identify information when it is no longer needed. Replacing a name with an identifier is not necessarily irreversible anonymization.
Retention depends on the following purposes and criteria, including the operational periods stated below. A legal hold affects only records needed for that purpose. Service providers may keep separate records under their own lawful obligations; ask us about the period relevant to your request.
| Record | Retention period or criterion |
|---|---|
| Active accounts, profiles and preferences | For the account relationship and proportionate closure handling; retain residual records only for the documented lawful purpose. |
| Financial transactions, invoices, commission and payouts | The tax/accounting period applicable to the transaction and a justified dispute/legal-claim period; closure does not erase required financial records. |
| Messages, whiteboard snapshots, uploads and lesson notes | For agreed learning access, recovery and a justified complaint period. Saved content is distinct from short-lived operation history. |
| Whiteboard operation history | Normally a 90-day operation-history period, subject to the configured lawful schedule. Saved page snapshots can outlast this history. |
| Browser error/performance records and read notifications | Eligible diagnostic records and read notifications are removed on a 90-day operational schedule. Separate security logs follow their justified security purpose. |
| Completed notification message bodies | Eligible completed message bodies are cleared after 30 days. Delivery metadata and independent provider records can have a different lawful period. |
| Requested export file | Access expires after seven days; removal is performed by a cleanup process. Copies downloaded by you are outside our direct control. |
| Identity, verification, security, support and safeguarding | For the documented verification, security, support or safeguarding purpose and applicable legal-claim or reporting period. No blanket permanent retention. |
| Backups | Restricted recovery copies until the applicable backup rotation/expiry. Backup access is limited and required deletions are reapplied after restoration. |
Closure can remove profile/contact information while retaining lawful financial, audit or dispute records. It is not immediate erasure of every backup or transaction record. Request deletion separately if needed; we explain what we retain and why. When a backup is restored, relevant deletion requests are reapplied where required.
11. Children and young people
We treat children's information with particular care. The legal age for a contract, the age for privacy consent and the age for a guardian's permission are different questions. Country-specific requirements are explained in the local supplement. Do not falsify age or guardian authority.
Children receive information appropriate to their age and understanding about what a tutor, guardian and the platform can see. We seek only information reasonably necessary for the learning activity. Required parental notice and verifiable permission must precede affected processing. A guardian can ask about a child's information or report an unauthorized account; verification protects the child and other people.
If required child/guardian permission is missing, we restrict the affected activity, contact the appropriate person where safe and lawful, and address deletion or justified retention. A school or tutor cannot authorize unrelated commercial uses merely because the activity involves education. Educational permission does not authorize advertising or publicity.
12. Security and incidents
We apply proportionate technical and organizational measures including restricted access, secure authentication, protected transmission, controlled document access and appropriate backups. Security is assessed and maintained according to the processing risks. No internet service can promise that a breach will never occur.
We investigate suspected incidents and notify affected people and regulators when legally required. Contact support promptly about suspicious access, an exposed document or an inappropriate message. Never send a password or live provider secret in a report. Internal incident diagnostics should minimize personal information and use need-to-know access.
13. Automated rules and human review
Automatic rules may protect accounts, rate-limit requests, assess booking eligibility, update status, send reminders and reconcile transactions. Public discovery can use filters and eligibility information. Such automation can affect access or payment timing, so you may contact support to challenge an error and seek meaningful review.
If a decision is made solely through automated processing with a legally significant or similarly substantial effect, we provide the applicable information about its logic and consequences and the available safeguards and rights. You may ask the privacy contact about an automated decision or seek review. Sensitive or child profiling requires the relevant additional assessment and protections.
14. Your rights and how to request them
Depending on the applicable law, you may have rights to obtain access and information, correct an error, request deletion, receive a portable copy, restrict processing, object to certain uses, withdraw consent, or challenge qualifying automated decisions. Some jurisdictions provide advertising opt-outs, appeal rights or additional controls over sensitive information. They are subject to their legal conditions and exceptions.
Use account privacy/export controls where available or contact the privacy/support address with the request. You do not need an active subscription to exercise a statutory right. We ask only for proportionate information needed to verify identity or lawful guardian/agent authority, and do not require unnecessary identity documents by unsecured email. We protect other people's data and explain lawful refusals, extensions and available appeal/complaint routes.
We follow the applicable statutory response period. A data export is not a full substitute for responding to all access questions. Exported files may omit credentials, other people's private data and protected internal material; ask support about a lawful request for omitted information or uploaded-file copies. There is ordinarily no charge; any permitted fee or refusal must satisfy local law. We do not punish you for exercising privacy rights.
15. Complaints, revisions and scope
Send a privacy complaint to the contact above, identify the concern and the remedy sought, and include only necessary information. We investigate, keep you appropriately informed and communicate an outcome. You can contact the relevant regulator or competent court without surrendering your rights; local routes are given in the supplement.
We date and version this notice and communicate material changes as required. We do not use a revised notice to retrospectively obtain consent. A new incompatible purpose or optional use may need fresh notice and permission before it begins. Third-party websites linked from the site have their own practices; our disclosure responsibilities still apply where we actually send information to them. Request an accessible copy or assistance understanding the notice.
Australia privacy provisions
Where the Privacy Act 1988 and Australian Privacy Principles cover the operator and processing, they govern collection, notice, use, security, access, correction and complaint handling. Applicable statutory scope and exemptions determine coverage.
We identify actual overseas recipient countries where practicable and comply with applicable APP 8 safeguards and accountability. Registration does not provide a generic waiver of overseas accountability. Sensitive information requires the applicable collection permission or lawful exception.
Children's privacy consent depends on capacity and maturity. Where a learner cannot understand the relevant processing, the appropriate guardian permission must be obtained. OAIC guidance recognizes a rebuttable practical presumption of capacity from age fifteen where individualized assessment is impracticable; this is separate from independent contracting eligibility.
You may seek access or correction and complain to our privacy contact. Requests are handled within the applicable reasonable period. Relevant unresolved matters may be raised with the Office of the Australian Information Commissioner according to its process. Additional rights apply only where the relevant law or commitment provides them.
Additional child-privacy requirements under the Children’s Online Privacy Code apply according to its finalized scope and commencement. We update the relevant information and protections as those obligations become applicable.
Basam Tutor operates an online tutoring marketplace connecting learners, guardians and independent tutors in supported markets. Contact support@basamtutor.com for policy questions, privacy requests or support.
