Privacy Policy & GDPR Compliance

Last updated: 10/21/2025

1. Introduction

Johnny Robinson trading as John Lindon Mathematics Tutor ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR) and UK data protection laws.

2. Data Controller

Data Controller: Johnny Robinson trading as John Lindon Mathematics Tutor
Address: 7a Clegir, Bryn Celyn, Conwy, LL32 8PW
Email: john@conwymaths.com
Phone: +44 7585 936073

3. Personal Data We Collect

3.1 Student and Parent Information

  • Names and contact details (email, phone, address)
  • Date of birth and age
  • Educational level and academic needs
  • Special educational needs or disabilities (where relevant)
  • Emergency contact information
  • Payment and billing information

3.2 Session Information

  • Session attendance records
  • Academic progress notes
  • Learning objectives and outcomes
  • Homework assignments and feedback

3.3 Website and Digital Information

  • Website usage data (via cookies)
  • Booking form submissions
  • Email communications
  • Online session recordings (when consented)

4. Legal Basis for Processing

We process your personal data under the following legal bases:

4.1 Contract Performance

Processing necessary to provide tutoring services, manage bookings, and process payments.

4.2 Legitimate Interest

Improving our services, maintaining records, and conducting business administration.

4.3 Legal Obligation

Safeguarding requirements, health and safety obligations, and tax/accounting records.

4.4 Consent

Marketing communications, session recordings, and sharing progress with schools (where explicitly consented).

5. How We Use Your Data

  • Providing and managing tutoring services
  • Communicating with students and parents
  • Scheduling and confirming appointments
  • Processing payments and maintaining financial records
  • Tracking academic progress and preparing reports
  • Ensuring safeguarding and health & safety requirements
  • Improving our services and website functionality
  • Complying with legal and regulatory obligations

6. Data Sharing

We do not sell or rent your personal data to third parties. We may share your data only in the following circumstances:

6.1 With Your Consent

  • Sharing progress reports with schools (with explicit consent)
  • Referring to other educational professionals (with consent)

6.2 Legal Requirements

  • Safeguarding disclosures to relevant authorities
  • Compliance with court orders or legal processes
  • Cooperation with law enforcement when required

6.3 Service Providers

  • Payment processing services (with appropriate safeguards)
  • Email and communication platforms
  • Website hosting and technical support

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encrypted data transmission and storage
  • Secure password policies and access controls
  • Regular security updates and monitoring
  • Limited access to personal data on a need-to-know basis
  • Secure disposal of physical and digital records
  • Regular backup and recovery procedures

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Student records: 7 years after last session
  • Financial records: 6 years for tax purposes
  • Safeguarding records: Until the individual reaches age 25
  • Marketing data: Until consent is withdrawn
  • Website data: As specified in our cookie policy

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

9.1 Right of Access

Request a copy of the personal data we hold about you.

9.2 Right of Rectification

Request correction of inaccurate or incomplete personal data.

9.3 Right of Erasure

Request deletion of your personal data (subject to legal obligations).

9.4 Right to Restrict Processing

Request limitation of how we use your personal data.

9.5 Right to Data Portability

Request transfer of your data to another service provider.

9.6 Right to Object

Object to processing based on legitimate interests or for marketing purposes.

9.7 Right to Withdraw Consent

Withdraw consent for processing based on consent (does not affect lawfulness of previous processing).

10. Cookies and Website Data

Our website uses cookies to improve your experience:

10.1 Essential Cookies

Necessary for website functionality and security.

10.2 Analytics Cookies

Help us understand how visitors use our website (anonymized data).

10.3 Preference Cookies

Remember your settings and preferences for future visits.

11. Children's Personal Data

As we provide tutoring services to minors, we take extra care with children's personal data. We rely on parental consent for processing children's data and ensure that our practices are appropriate for their age and understanding. Parents/guardians can exercise data rights on behalf of their children.

12. International Data Transfers

We primarily store and process data within the UK. If we need to transfer data internationally (for example, for cloud services), we ensure appropriate safeguards are in place, such as adequacy decisions or Standard Contractual Clauses.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated to you directly, and the updated policy will be posted on our website with a new "Last Updated" date.

14. How to Make a Complaint

If you have concerns about how we handle your personal data, please contact us first. If you remain unsatisfied, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Email: casework@ico.org.uk

How to Exercise Your Rights

To exercise any of your data protection rights or if you have questions about this Privacy Policy, please contact us:

Email: john@conwymaths.com

Phone: +44 7585 936073

Post: 7a Clegir, Bryn Celyn, Conwy, LL32 8PW

Response Time: We will respond to your request within one month of receipt (or two months for complex requests).

Consent Record

By using our services and providing your personal data, you acknowledge that you have read and understood this Privacy Policy. For processing based on consent, we will obtain your explicit consent before processing your data.