Lezio EN · DE · RU · UK

Privacy Policy

Version 1.0 · In effect since 11 July 2026 · Revised 23 July 2026 (section 5: public teacher pages and booking requests)

This is a courtesy translation. The legally binding version is the German "Datenschutzerklärung".

Protecting your personal data matters to us. Lezio is built so that as little data as possible leaves our own system. The server, the file and image storage and most services run on our own infrastructure in the European Union. Exactly two functions use external providers – sending email, and calendar synchronisation with Google or Microsoft, which only happens if you set it up yourself. We set no tracking cookies, we show no ads, and we do not sell data.

1. Controller

The person responsible for data processing on Lezio:

Maksim Nikolaev
Am Frauenberg 20
99734 Nordhausen, Germany
Email: support@lezio.app

2. Principles and legal bases

We process personal data only as far as necessary to provide a working platform and our services. The main legal bases are Art. 6(1)(b) GDPR (performance of the user agreement), Art. 6(1)(f) GDPR (our legitimate interest, for example in the security and stability of the service) and Art. 6(1)(a) GDPR (your consent, for example for the optional calendar synchronisation).

3. Hosting and connection data

When you use the platform, technically necessary connection data – your IP address, the time of access, the requested resource, the status code and the user agent – is processed to deliver the service and keep it stable and secure (Art. 6(1)(f) GDPR).

Hosting and the file and image storage run on servers of netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany, exclusively within the European Union. A data processing agreement under Art. 28 GDPR is in place; netcup is certified to ISO 27001 and ISO 27701. The domain is managed through the registrar Porkbun.

4. Cookies

We use only strictly necessary cookies: a session cookie for login and, where relevant, storage of display preferences such as language and light or dark mode. These are required for operation (§ 25(2) TDDDG) and need no consent. We set no third-party tracking, advertising or analytics cookies.

5. Your account

Using Lezio requires an account. For it we process your name, your email address, a password stored only in hashed form, and your role (teacher, student or school). We send verification emails to confirm your address and to reset your password (see section 8). The legal basis is Art. 6(1)(b) GDPR.

You may add further profile details, such as date of birth or age, interests and country. These are voluntary, hidden by default, and shown only to users connected to you according to your visibility settings (Art. 6(1)(a) GDPR). A date of birth or age is never shown publicly. Profile data becomes public in exactly one case: when a teacher explicitly publishes their public booking page (see below). Everything else stays non-public.

Public teacher pages. Teachers can choose to publish a public page at a personal link showing the details they entered for it: name, photo, headline, description, subjects, languages, lesson format and – only if enabled – city and rate, together with free time slots. Publication requires an explicit action (Art. 6(1)(a) GDPR); unpublishing takes effect immediately and removes the page. Published pages may be indexed by search engines unless the teacher disables it; search engines can retain cached copies for some time after unpublishing.

Booking requests. When a visitor requests or books a lesson through a public page, we process the name, email address, optional message, chosen time slot, time zone and language they provide, plus the IP address of the submission for abuse prevention. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at the data subject's request). Open requests must be confirmed by email (double opt-in). Declined and expired requests are deleted after 90 days; the IP address is deleted after 30 days at the latest. Accepted bookings become a normal student relationship (section 6).

6. Lessons, balances and relationships

To provide the service we process the content you enter, in particular lessons and appointments, time and availability data, balance and payment amounts, and the relationships between teachers, students and schools (Art. 6(1)(b) GDPR).

Providing an address is optional. It is never public and is shown only to directly connected, trusted parties – for example between an assigned teacher and student and, where relevant, the associated school. We do not publish and do not sell data.

7. Messages, attachments, moderation and guardian access

The platform includes a chat where connected users exchange messages and attachments (images, documents, audio). This content is stored on our servers in the EU for delivery; transmission is TLS-encrypted, and message texts and attachments are additionally encrypted at rest (AES-256). This is server-side encryption, not end-to-end encryption: our systems can process the content where necessary for delivery, search and moderation.

To keep the platform safe, a reporting and moderation function exists. If an authorised person reports content, it may be made available for review and shared with us as far as needed to handle the case. The basis is our legitimate interest in a safe platform free of abuse (Art. 6(1)(f) GDPR). Violations, including unlawful or age-inappropriate content, may lead to suspension of access.

Guardian access (minors): at the student's or teacher's request, a guardian may be given a read-only view of the student's lessons and balance. Reading the chat with the teacher is included only if the guardian additionally enables it. The student can always see whether, and to what extent, guardian access exists. The legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in protecting minors (Art. 6(1)(f) GDPR).

8. Transactional email (Resend)

To send account emails – address verification, password reset and invitations – we use Resend (Resend, Inc., USA). We transmit the recipient email address and the content of the message. The legal basis is Art. 6(1)(b) or (f) GDPR. Safeguards for the US transfer are described in section 12.

9. Calendar synchronisation (Google or Microsoft) – optional

Only if a teacher actively sets it up can they connect their Google or Microsoft calendar to mirror lesson appointments and invite students as attendees. Only with this connection is appointment data sent to Google (Google Ireland Ltd. or Google LLC) or Microsoft (Microsoft Ireland Operations Ltd. or Microsoft Corporation). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by disconnecting.

Data received from the Google APIs is used only to provide and improve this calendar feature, in compliance with the Google API Services User Data Policy, including its Limited Use requirements. We do not share it with third parties for other purposes and do not use it for advertising.

10. Error diagnostics

Where enabled, we run a self-hosted GlitchTip instance on our own server in the EU for stability and debugging. Technical error and diagnostic data is processed in the most anonymised and aggregated form possible, and no data is passed to third parties (Art. 6(1)(f) GDPR).

11. Recipients and processors

Beyond this we disclose personal data only where you have consented, where it is needed to perform the contract, or where the law requires it.

12. Transfers to third countries

Where data is transferred to providers based or processing in the USA (Resend, Google, Microsoft), we rely on appropriate safeguards under Art. 46 GDPR, in particular the EU Commission's standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.

13. Retention

We keep personal data only as long as needed for the stated purposes or while your account exists. After account deletion the associated data is deleted, unless statutory retention obligations apply. Data in backups is overwritten in the course of the regular backup cycle.

14. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent at any time with effect for the future. To exercise these rights, contact support@lezio.app.

15. Right to complain

You have the right to lodge a complaint with a data protection authority. The authority responsible for us is the Thüringer Landesbeauftragte für den Datenschutz und die Informationsfreiheit (TLfDI), Häßlerstraße 8, 99096 Erfurt, Germany.

16. Minors

The platform is not aimed at younger children. Use requires that you are at least 16 years old or have the consent of a parent or guardian, which is confirmed at registration. Where a teacher or school invites students, that party confirms it is authorised to do so. A date of birth or age is shown only voluntarily and only to connected parties according to the visibility settings – never publicly.

17. Data security

Transmission is TLS-encrypted throughout. Credentials are stored only as a hash; access tokens for calendar synchronisation as well as chat messages and attachments are stored encrypted at rest. Data access is tenant-isolated.

18. Changes to this privacy policy

We update this privacy policy when changes to the platform or the law require it. The version published here at the relevant time applies (see the version and dates above).