Legal
Privacy Policy
Needs professional review
Last updated 1 August 2026
This notice describes what happens to personal data on ayselmursal.com. It is written against the software as it is actually built: every category below corresponds to a field the system really stores, and where something is deliberately not stored, that is said too.
1. Who is responsible
The tutoring service is provided by Aysel Mursal, who teaches students in Azerbaijan, Türkiye, the United States and the United Kingdom. She decides what personal data is collected here and why, and is therefore the controller of it.
REVIEWER — the controller’s full legal name and trading status, correspondence address, and any company or tax registration number.
REVIEWER — whether a data protection officer, or a representative in the EU, the UK or Türkiye, must be appointed for this service — and if so, their contact details.
Until those details are confirmed, the working address for anything on this page is [email protected].
2. What is collected, and when
Nothing is collected passively beyond what section 6 describes. Each of the following happens only because you did something.
Booking a lesson
The booking form asks for a first name and an e-mail address. Everything else is optional: surname, telephone number, age, education level and a target exam date. Alongside that the system stores the programme and lesson type you chose, the start time, the time zone you selected, the language you asked the lesson to be taught in, and any note you typed into the free-text box. A booking reference is generated for you, and — for paid lessons — a snapshot of the price at the moment of booking, so a later price change never rewrites your record.
If you state that the student is under 18, the form requires a guardian’s name and e-mail address before the booking can be completed. Section 8 explains why.
The contact form
Name, whether you are the student, a parent or someone else, e-mail address, your message, and optionally a telephone number, the programme you are asking about and the language you prefer. Ticking the box that allows a reply is required — without it there is no lawful basis for answering you at all.
The readiness quiz
The readiness check can be taken anonymously. What is stored is the option you picked for each question, the resulting score, the band it falls into and the two weakest topic areas, with the language and market the attempt came from. Your name is never asked for. An e-mail address is stored only if you ask for the result to be sent to you, and a telephone number only if you volunteer one.
An account in the student area
E-mail address, display name, role, preferred language, time zone and market; the time of the last sign-in; and, if a password is set, the password itself stored only as a bcrypt hash. Sign-in links and password-reset links are stored only as SHA-256 digests, so a copy of the database does not hand out working links. Failed sign-in attempts and any resulting lock-out time are recorded.
During a course
Attendance, homework and materials assigned to a student, a running log of the kinds of mistake that recur (an error type and a topic area with a count — never the working itself), and Aysel’s private teaching notes.
Payment
No card number ever reaches this site. Where a market is settled by invoice or bank transfer, there is no card at all; where a card processor is enabled for a market, the card details are entered on that provider’s own hosted page and never pass through ayselmursal.com. What is stored here is the amount, currency, market, status, payment reference and — for a card payment — the processor’s opaque reference.
For every message the system sends, a log row records the recipient address, the subject, which template was used, the delivery status and the provider’s reference. It exists so that “did the confirmation arrive?” has an answer.
3. What is deliberately never collected or shared
- IP addresses are never stored in the clear. Anywhere an address is needed — abuse limits, the consent audit trail, the administrator audit log — it is first put through a salted SHA-256 digest and truncated. The digest is enough to notice that the same source is hammering a form; it cannot be turned back into an address.
- Lesson notes and quiz answers never leave the system. The variables an e-mail template may use are a fixed list — name, programme, date, time, duration, reference, links — and teaching notes, booking notes, error-log entries and quiz answers are not on it. E-mail is forwarded, archived and read on shared devices; a student’s mathematics stays inside the student area.
- Analytics receives no personal data. Events are drawn from a fixed vocabulary and their properties are filtered against a fixed key list (programme, market, language, currency, step, band, category and similar). Anything not on that list is dropped before the event is recorded, so a mistake at a call site cannot leak. There is no field on the analytics table that a name, an address or a piece of free text could reach.
- The tutor’s calendar receives no student data. When the optional Google Calendar integration is switched on, an event carries the programme name, the booking reference and the times. Nothing identifying the student and nothing about the lesson content is sent.
4. Why it is collected, and on what lawful basis
REVIEWER — confirm the framing below against each applicable regime — UK and EU GDPR, the Azerbaijani Law on Personal Data, and Turkish KVKK — and set out the KVKK basis separately if that is the right approach.
- Delivering a booked lesson — scheduling it, confirming it, reminding you about it, telling you when it moves or is cancelled, and teaching it. Necessary for the performance of the contract you entered into when you booked.
- Answering an enquiry — replying to the contact form. Consent, given by the tick box on the form, and recorded as its own record.
- Sending a readiness-quiz result by e-mail — consent, given by supplying an address for exactly that purpose.
- Taking payment and keeping accounting records — necessary for the contract, and thereafter a legal obligation under the applicable tax rules.
- Keeping the site standing up — rate limiting, spam traps and the administrator audit log. Legitimate interests: the site cannot be operated safely without them, and each stores a hashed identifier rather than an identity.
- Analytics — consent, off until you switch it on.
- Occasional marketing e-mail — consent, recorded separately from everything else and never bundled with a booking.
5. Consent: three purposes, recorded separately
The system distinguishes three, and stores each as its own record with the moment it was granted or withdrawn:
- Operational — the messages needed to deliver a lesson you booked: confirmation, reminder, change and cancellation. This is not a marketing choice and it cannot be switched off while a booking stands; withdrawing it means cancelling the lesson.
- Analytics — optional, and off unless you turn it on.
- Marketing — optional, and off unless you turn it on. Note that no marketing message is sent by this site today: the preference is recorded so that it can be honoured if that ever changes.
To withdraw analytics or marketing consent, use the cookie preference centre — the switches there write the same record the banner does, so a choice made in one place cannot disagree with the other. To withdraw a consent given on the contact form or the quiz, write to [email protected]. Withdrawing consent does not undo anything done lawfully before you withdrew it.
6. Cookies and similar storage
Only strictly necessary cookies are set by default. The cookie preference centre lists every cookie the site sets, with its purpose, lifetime and category, and carries the switches for the two optional categories.
7. How long it is kept
REVIEWER — the periods below are proposals, not advice. Confirm each against the applicable retention and tax rules before launch, and shorten anything that cannot be justified.
- Booking and lesson records, including teaching notes and the error log — proposed 3 years after the last lesson.
- Payment and invoice records — proposed to follow the statutory accounting
period.
REVIEWER — which period, in which country, given that the service spans Azerbaijan, Türkiye, the United States and the United Kingdom. - Enquiries that never became a booking — proposed 24 months from the last contact.
- Readiness-quiz attempts with no e-mail address attached — proposed 12 months. These carry no identity.
- E-mail delivery logs — proposed 12 months.
- Administrator audit log — proposed 24 months.
- Analytics events — proposed 14 months.
- Consent records — kept for as long as the related record exists, because they are the evidence that a consent was given or withdrawn.
Two honest notes. Rate-limit counters hold only a salted hash and a number, so
there is nothing in them to identify anybody. And there is at present no
scheduled job that deletes expired data automatically — erasure is carried out
by hand when it is requested or when a period is reached.
REVIEWER — decide whether an automated retention job is required before launch, and record the decision.
8. Students under 18
Where the booking form is told that the student is under 18, it requires a guardian’s name and e-mail address before it will accept the booking. That is the only reason guardian details are collected: so that a responsible adult is the one contracting for the lessons, receiving the confirmations and able to change or cancel them. A guardian sees the student’s bookings; a guardian does not receive Aysel’s teaching notes, because those are not sent to anybody by e-mail.
Age is asked for, not verified, and a booking made without stating an age does
not trigger the guardian requirement.
REVIEWER — confirm the age of digital consent that applies in each market, whether an explicit verification step is required, and how a guardian consent should be evidenced.
9. Who else processes it
This list depends on how the site is configured, and it changes when that configuration changes. As built, the possible processors are:
- Hosting and database — the application server and its
PostgreSQL database.
REVIEWER — name the hosting provider and the region the database sits in. - E-mail delivery — a transactional e-mail provider. The
system supports Resend and any SMTP service; with neither configured, nothing
leaves the server at all.
REVIEWER — name the provider actually in use at launch. - Payments — none in a market settled by invoice or bank
transfer, because no third party is involved in that flow. Where a card
processor is enabled for a market, that processor receives the payment details
you enter on its own page.
REVIEWER — name the processor and the markets it is enabled for at launch. - Google Calendar — optional and off by default. When it is connected, Google receives the programme name, booking reference and times of lessons, and no student data.
- Analytics — Google Analytics, and only when a measurement ID has been configured and you have accepted analytics. IP anonymisation is on and Google’s advertising signals are switched off.
- File storage — lesson materials are stored on the
application’s own disk unless an S3-compatible bucket is configured.
REVIEWER — name the bucket provider and region if one is used.
10. Where it is processed
The service spans Azerbaijan, Türkiye, the United States and the United Kingdom, and the people who use it are in all four. Personal data will therefore be processed outside the country you are in, and outside the country Aysel is in, depending on where the hosting and e-mail providers run.
REVIEWER — once the hosting, e-mail and payment providers are fixed, state where each stores data and identify the transfer mechanism relied on for each route — adequacy, UK IDTA, EU standard contractual clauses, or the equivalent under Azerbaijani and Turkish law.
11. Your rights
You may ask for a copy of the personal data held about you, ask for it to be corrected, ask for it to be deleted, ask for its use to be restricted, object to processing carried out on the basis of legitimate interests, ask for a portable copy of what you provided, and withdraw any consent you gave. Write to [email protected]. Some records — accounting records in particular — cannot be deleted on request while a legal obligation to keep them stands.
You may also complain to a supervisory authority.
REVIEWER — name the competent authority for each market and give its contact details, together with the response time to be committed to for a rights request.
12. Security
Passwords are hashed with bcrypt at cost 12 and never stored in a readable form. Reschedule links, sign-in links and reset links are stored only as digests. An account is locked after five failed sign-in attempts. Administrator actions are written to an audit log with a hashed IP address. Calendar access tokens are encrypted at rest. Rich text supplied through the admin editor is sanitised on the server before it can reach anybody’s browser.
13. Changes to this notice
The date this page was last edited is shown at the top. A change that affects
what is collected, or why, will be announced on the site before it takes effect.
REVIEWER — decide whether existing students and guardians should also be notified by e-mail, and within what period.
14. Getting in touch
Write to [email protected], or use the contact form. Related pages: Terms, Cancellation and Rescheduling, and Cookie Preferences.