Document type: Customer-facing privacy notice
Version: 0.3 draft
Controller: Converging Realities Ltd trading as Academbee
Last updated: June 2026
Legal review required before publication. This privacy policy should be cross-read with the Terms of service, Cookie policy, Subscription terms, Data processing agreement where applicable, and the billing-specific notice: Personal data in billing (GDPR).
Converging Realities Ltd (“Academbee”, “we”, “us”, “our”) is a company registered in Cyprus.
We operate the Academbee online platform for teachers, schools, education providers, and users interested in educational services, including our websites, dashboards, public profiles, messaging tools, subscription features, verification processes, and related services (the “Platform”).
For most processing described in this Privacy policy, Converging Realities Ltd is the data controller. This means that we decide why and how personal data is processed.
Company: Converging Realities Ltd
Trading name: Academbee
Address: Panagias Kikkou 38, 2331, Lakatamia, Nicosia, Cyprus
VAT: CY-10447220L
General contact: support@academbee.com
Data protection contact: Savvas Iedidis — privacy@academbee.com
Supervisory authority in Cyprus:
Commissioner for Personal Data Protection
Website: https://www.dataprotection.gov.cy
This Privacy policy explains how we collect, use, disclose, retain, and protect personal data when you use Academbee as:
This policy primarily covers customer-side use of Academbee. Where end-user, student, parent, or learner processing differs materially, we may provide a separate privacy notice or additional privacy information.
This policy applies to personal data processed through:
Academbee processes personal data to provide, secure, improve, and administer the Platform.
In practice:
“Personal data” means any information relating to an identified or identifiable natural person.
The personal data we collect depends on how you use the Platform.
We may collect:
We do not store your plain-text password.
If you create a teacher, school, or education provider profile, we may collect:
When you publish a profile, certain profile and listing data may become visible to other users and website visitors.
If you add a location to your profile, we may collect:
For privacy and safety reasons, we may reduce the precision of public location data, especially for individual teachers or tutors.
Where verification is required or requested, we may collect:
Verification documents are used for trust, safety, fraud prevention, platform integrity, and compliance purposes. They are not intended to be displayed publicly unless we expressly tell you otherwise.
When you subscribe to a paid plan or use paid services, we may collect:
We use Stripe to process payments. Full card numbers and card security codes are processed by Stripe and are not stored on Academbee servers.
More billing-specific detail is provided in Personal data in billing (GDPR).
If the Platform includes messaging, contact forms, inquiries, or lead features, we may process:
Message contents may include personal data provided by the sender. Users should avoid including unnecessary sensitive information in messages.
Phone numbers provided in inquiries are used for the inquiry process and are not displayed publicly unless the user expressly chooses to publish them through a supported public profile feature.
When you contact us or we contact you, we may process:
When you use the Platform, we may automatically collect technical and usage data, including:
We use this data to operate, secure, debug, monitor, and improve the Platform.
We may use cookies, local storage, pixels, SDKs, and similar technologies to:
More information is provided in section 15 and in our Cookie policy.
If we offer marketing communications, newsletters, promotions, or product updates, we may process:
Transactional emails, such as account activation, security notices, billing notices, renewal reminders, and service updates, are not marketing emails.
We may process:
We do not intentionally request special category personal data unless a specific feature clearly requires it and we have an appropriate legal basis.
Special category data includes information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, sex life, or sexual orientation.
You should not include special category data in your profile, listing, messages, support requests, or uploaded materials unless we specifically ask for it and explain why it is needed.
If special category data is submitted unnecessarily, we may delete it, restrict it, or ask you to remove it.
We collect personal data from:
We use personal data for the following purposes.
We process data to:
We process data to:
We process data to:
We process data to:
We process data to send:
Where we send marketing communications, we will do so only where we have a valid legal basis and will provide an unsubscribe option.
We process data to:
Where possible, we use aggregated or de-identified data for analytics and product improvement.
We process data to:
We rely on different legal bases depending on the processing activity.
| Processing activity | Main legal basis |
|---|---|
| Account registration and login | Contract — GDPR Art. 6(1)(b) |
| Providing the Platform and customer dashboard | Contract — GDPR Art. 6(1)(b) |
| Creating and managing profiles | Contract — GDPR Art. 6(1)(b) |
| Publishing public profile/listing information | Contract — GDPR Art. 6(1)(b); legitimate interests — GDPR Art. 6(1)(f) |
| Search and discovery features | Contract; legitimate interests |
| Messaging and inquiries | Contract; legitimate interests |
| Subscription management | Contract — GDPR Art. 6(1)(b) |
| Payment processing | Contract; legal obligation where accounting/tax records apply |
| Invoices, accounting, and tax records | Legal obligation — GDPR Art. 6(1)(c) |
| Verification and fraud prevention | Legitimate interests — GDPR Art. 6(1)(f); contract where verification is part of the service |
| Moderation and enforcement | Legitimate interests; contract |
| Security logs and abuse prevention | Legitimate interests — GDPR Art. 6(1)(f) |
| Support communications | Contract; legitimate interests |
| Transactional emails | Contract; legal obligation; legitimate interests, depending on the notice |
| Marketing emails | Consent — GDPR Art. 6(1)(a), or legitimate interests where permitted by law |
| Cookies strictly necessary for the service | Legitimate interests; contract |
| Non-essential cookies or similar tracking | Consent, where required |
| Legal claims and dispute management | Legitimate interests; legal obligation |
| Compliance with lawful requests | Legal obligation |
Where we rely on legitimate interests, our interests include operating a safe, reliable, commercially sustainable, and trusted education platform. We balance those interests against your rights and freedoms.
Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect processing already carried out before withdrawal.
Academbee allows teachers, tutors, schools, and education providers to create public profiles or listings.
If you choose to publish a profile, the following information may be visible publicly:
You are responsible for ensuring that the information you choose to publish is accurate and appropriate for public display.
We may limit, hide, approximate, or remove public information where needed for safety, privacy, compliance, moderation, or platform integrity.
If you schedule account deletion through the Platform, we may unpublish or remove your public profile from search, map, listing, and discovery features immediately during the deletion grace period. If the deletion completes, public profile data is deleted or anonymised according to the account-deletion manifest, subject to lawful retention exceptions. Messages or historic interactions may show a neutral label such as “Deleted user” where needed to preserve another user’s conversation history.
Verification documents are used to assess whether a teacher, school, or education provider may be marked as verified or trusted on the Platform.
Verification documents may include identity, business, school, professional, or supporting documents.
We apply access controls to verification documents and restrict access to authorised personnel or service providers who need access for verification, security, legal, or compliance purposes.
We do not publish verification documents unless you expressly request publication and we agree, or unless required by law.
We may retain verification records for a limited period after verification, rejection, suspension, or account closure where necessary for fraud prevention, platform integrity, legal claims, or compliance.
If account deletion completes, verification documents are deleted unless a legal hold, dispute, fraud-prevention need, or mandatory legal obligation requires temporary retention. Where a record must be retained, we restrict or minimise it where possible.
Where the Platform allows users to contact teachers, tutors, schools, or education providers, we may process message and inquiry data to:
Messages are not intended for emergency communications, highly confidential information, or unnecessary sensitive personal data.
We may apply automated or manual checks to detect spam, abuse, fraud, or prohibited content. We do not guarantee that all harmful or inappropriate content will be detected.
Payments are processed by Stripe or another payment provider we may appoint.
Academbee does not store full card numbers or card security codes on its servers.
We may store payment-related metadata, including Stripe customer ID, subscription ID, invoice ID, payment status, payment method type, card brand, and last four digits, where provided by Stripe.
Billing records may be retained for tax, accounting, audit, legal, and dispute-resolution purposes.
For more information, see Personal data in billing (GDPR).
We may send transactional and service-related communications, including:
These communications are necessary for the Platform and are not marketing communications.
You may not be able to opt out of essential service, security, billing, or legal emails while you maintain an account or subscription.
If we send marketing communications, we will do so in accordance with applicable law.
Marketing communications may include:
Where consent is required, we will ask for consent before sending marketing emails.
You can unsubscribe from marketing communications using the unsubscribe link in the email or by contacting us.
Unsubscribing from marketing emails does not stop transactional, billing, security, or legal communications.
We may use analytics to understand how the Platform is used and to improve performance, reliability, usability, and product features.
Analytics may include:
Where possible, we use aggregated, anonymised, or de-identified data.
Aggregated or anonymised data that no longer identifies a person is not personal data under GDPR. However, if we combine it with other data in a way that can identify a person, we treat it as personal data.
We use cookies and similar technologies to operate and improve the Platform.
Cookies may be grouped into the following categories:
These are required for the Platform to work.
They may be used for:
These cookies cannot usually be disabled through our cookie banner because they are necessary for the service.
These remember choices such as:
These help us understand how users use the Platform so we can improve it.
Where required by law, analytics cookies are used only with consent.
These may be used to measure campaigns or show relevant advertising.
Academbee should not use marketing cookies unless a compliant cookie banner and consent mechanism is in place.
You can manage cookies through:
Rejecting or disabling certain cookies may affect Platform functionality.
A separate Cookie policy should describe the specific cookies used, their providers, purposes, duration, and consent requirements.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on users, unless we clearly tell you and have a lawful basis.
We may use automated tools to support:
Where automated tools flag content or behaviour, we may conduct manual review where appropriate.
Academbee may use AI-assisted tools internally or within the Platform to improve productivity, support, moderation, content quality, search, or user experience.
Unless we clearly state otherwise:
If we introduce AI features that materially change how personal data is processed, we will update this Privacy policy or provide additional notice.
Users should not enter unnecessary sensitive personal data into AI-enabled features.
We may share personal data with the following categories of recipients.
We use trusted providers to help operate the Platform, including providers for:
These providers process personal data under contracts and may only process data according to our instructions, unless they are independent controllers for specific activities.
Payment providers such as Stripe process payment data to complete transactions, manage subscriptions, prevent fraud, and comply with financial regulations.
Stripe may act as an independent controller for some payment-related processing.
Email providers such as SendGrid may process email addresses, message content, delivery status, and related metadata to send transactional and service emails.
Hosting and database providers such as Vercel and Supabase may process personal data as part of hosting, storage, database, security, and infrastructure services.
We may share data with lawyers, accountants, auditors, insurers, consultants, or other professional advisers where necessary.
We may disclose data where required by law, court order, regulator, tax authority, law enforcement, or other competent public authority.
If Academbee is involved in a merger, acquisition, financing, restructuring, sale of assets, or transfer of business, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
If you publish a profile or listing, public profile information may be visible to other users, website visitors, and search engines.
If you communicate through the Platform, your message data may be visible to the intended recipient and authorised Academbee personnel where needed for support, security, moderation, or compliance.
Academbee should maintain an internal processor register before production and keep it updated.
The processor register should include, at minimum:
| Provider | Purpose | Data processed | Location / transfer safeguards | DPA status |
|---|---|---|---|---|
| Stripe | Payments and subscriptions | Billing and payment metadata | To be confirmed | Required |
| SendGrid | Transactional emails | Email addresses, email content, delivery metadata | To be confirmed | Required |
| Supabase | Database and authentication services | Account, profile, usage, and application data | To be confirmed | Required |
| Vercel | Hosting and deployment | Hosted application data, logs, technical data | To be confirmed | Required |
| Sentry or similar | Error tracking and monitoring | Error logs, technical metadata | To be confirmed | Required |
| Analytics provider | Usage analytics | Usage events, device/browser data | To be confirmed | Required |
| Support provider | Customer support | Support messages and contact data | To be confirmed | Required |
This public policy may refer to categories of processors. A more detailed public subprocessor list may be published separately.
Academbee is based in Cyprus, within the European Economic Area.
Some service providers may process personal data outside the EEA, the United Kingdom, or Switzerland.
Where personal data is transferred internationally, we use appropriate safeguards as required by law, such as:
You may contact us for more information about international transfer safeguards, subject to confidentiality and security limitations.
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
These measures may include:
No system is completely secure. Users are responsible for keeping login credentials confidential and for notifying us promptly if they suspect unauthorised access.
If we become aware of a personal data breach, we will assess it and take appropriate steps.
Where required by GDPR, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals, we will notify affected individuals as required by law.
We keep personal data only for as long as necessary for the purposes described in this Privacy policy, unless a longer retention period is required or permitted by law.
Retention periods may depend on:
Indicative retention periods are below.
| Data category | Indicative retention period |
|---|---|
| Account data | While account is active, then deleted or anonymised after account closure unless retention is required |
| Public profile data | While profile is active or published; removed or unpublished after account closure or request, subject to legal exceptions |
| Verification documents | Kept only as long as needed for verification, fraud prevention, legal claims, or compliance |
| Billing and invoice records | Normally retained for at least the legally required tax/accounting period; currently set as 7 years in billing documentation, subject to legal/accounting confirmation |
| Payment metadata | Retained as needed for subscription management, accounting, fraud prevention, disputes, and legal obligations |
| Support messages | Retained for as long as needed to handle support, improve service, and keep records of issues |
| Messaging and inquiries | Retained while needed to provide messaging, manage disputes, prevent abuse, and maintain security |
| Security logs | Retained for a limited period based on security needs, unless needed for investigation or legal claims |
| Consent records | Retained while needed to demonstrate compliance |
| Marketing preferences | Retained until you unsubscribe or object, and thereafter as needed to maintain suppression records |
| Account deletion requests | Retained as needed to operate the grace period, audit the request, and prove completion or lawful retention exceptions |
| Encrypted deletion email | Retained only until the completion email is sent or permanently undeliverable, then purged from the deletion request |
| Erasure ledger | Retained as a pseudonymous audit record using an HMAC user identifier, manifest version, completion timestamp, and non-PII receipt metadata |
| Backups | Retained for a limited backup cycle and then overwritten or deleted |
When deletion is not immediately possible, we may restrict, archive, or securely retain data until deletion is technically and legally possible.
Subject to legal conditions and limitations, you may have the following rights.
You may request confirmation of whether we process your personal data and a copy of that data.
You may ask us to correct inaccurate or incomplete personal data.
You may ask us to delete your personal data.
We may not be able to delete data immediately where we need to retain it for legal, tax, accounting, security, fraud prevention, dispute, or legal-claims purposes.
You may ask us to restrict processing in certain circumstances.
You may request a copy of certain personal data in a structured, commonly used, machine-readable format where the right applies.
You may object to processing based on legitimate interests.
You may also object to direct marketing at any time.
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You have the right to complain to a supervisory authority.
If you are in Cyprus, you may contact the Commissioner for Personal Data Protection.
To exercise your rights, contact us at:
You may also contact:
We may need to verify your identity before responding to a request.
We will respond within one month, unless the request is complex or we receive multiple requests, in which case we may extend the response period as permitted by law.
We will not discriminate against you for exercising your privacy rights.
You may request deletion of your account or removal of your public profile. Where self-service deletion is enabled, customers use Profile settings → Danger zone and end users use Account settings → Danger zone. Support or super-admin initiated deletion may be used where you cannot access the app or where a legal, safety, or fraud process requires staff handling.
Self-service account deletion normally uses a 14-day grace period. During that period, your account is placed into a restricted pending-deletion state. You may be able to view deletion status, cancel the request, sign out, and request a data export using the available Platform controls. If you cancel during the grace period, the account returns to active status, subject to subscription and moderation rules.
After account deletion:
Deleting your account removes or anonymises the canonical identity across customer and end-user roles linked to that identity. It does not automatically rewrite free-text message bodies that another user may need for their conversation history, but sender attribution and account references are anonymised where the erasure manifest requires it.
For completion emails, Academbee stores an encrypted notification email address on the deletion request only for the short period needed to send lifecycle emails. The decrypted address is used only by the transactional email worker at send time and must not be written to logs, analytics, receipts, or the erasure ledger. You may register again with the same email address as a new account after erasure completes.
Where possible, we will delete, anonymise, or restrict personal data that is no longer needed.
The Platform is intended for adults, teachers, tutors, schools, education providers, and users who are legally able to use the service.
The Platform is not directed at children below the age at which they may lawfully consent to information society services under applicable data protection law.
For Cyprus and many EU contexts, the default GDPR age for child consent is 16 unless national law provides otherwise. Counsel should confirm the correct age threshold for each target market before launch.
We do not knowingly collect personal data from children without appropriate consent or another valid legal basis.
If we learn that a child has provided personal data without appropriate consent or legal basis, we may delete or restrict the data.
Schools, teachers, and education providers are responsible for ensuring that any personal data they provide about minors is processed lawfully and with appropriate notices, permissions, and safeguards.
If you are a teacher, school, tutor, education provider, or organisation using Academbee, you are responsible for:
Where you act as an independent controller, you are responsible for your own privacy compliance.
Where we process personal data on your behalf as a processor, a separate Data processing agreement may apply.
The Platform may contain links to third-party websites, social media pages, payment pages, map providers, or external services.
We are not responsible for the privacy practices of third parties.
You should review the privacy policies of third-party services before using them.
If we offer integrations with third-party services, such as calendars, email tools, payment tools, analytics tools, or communication tools, personal data may be exchanged with those services when you enable or use the integration.
The data shared will depend on the integration and your settings.
We will provide additional information where required.
We rely on users to provide accurate and up-to-date information.
You can update certain account and profile information through your dashboard.
We may ask you to update or verify information where necessary for billing, verification, compliance, or platform integrity.
We aim to collect only the personal data that is necessary for the purposes described in this policy.
You should avoid submitting unnecessary personal data, especially in:
Some browsers may send “Do Not Track” or similar signals.
Because there is no consistent industry standard for these signals, the Platform may not respond to all such signals.
Where legally required and technically supported, we will respect valid consent choices made through our cookie consent tool or other recognised mechanisms.
We may update this Privacy policy from time to time.
If changes are material, we will notify users as required by law, which may include email notice, in-app notice, or prominent website notice.
The “Last updated” date shows when this policy was last revised.
Continued use of the Platform after an updated Privacy policy becomes effective may be subject to the updated policy, where permitted by law.
For questions about this Privacy policy or your personal data, contact:
Data protection contact:
Savvas Iedidis
privacy@academbee.com
General support:
support@academbee.com
Postal address:
Converging Realities Ltd
Panagias Kikkou 38
2331, Lakatamia
Nicosia, Cyprus
You have the right to lodge a complaint with a data protection supervisory authority.
For Cyprus:
Commissioner for Personal Data Protection
Website: https://www.dataprotection.gov.cy
We encourage you to contact us first so we can try to resolve your concern.