Privacy policy
What we store, why, who can see it and for how long. Written to be read, not to hide behind.
Who is responsible
Nextrum is run by Leo Constantinos Thriskos and Alexandar Jovanovic.
The limited company Nextrum AB is being formed and is not yet registered. Until then we are the data controllers as private individuals — not a company. We say so plainly because it is true, and so that you know who you are actually giving your details to. Once the company is registered this page will be updated with its registration number.
Mönsteråsgränd 4
122 42 Enskede
Stockholm, Sweden
Questions about your data: info@nextrum.se. We reply as soon as we can, and at the latest within one month.
In short
We store what is needed to match a student with the right tutor, book and hold the sessions, keep you informed about what is happening, and charge for the sessions. Nothing more.
We do not sell data. We do not pass it on for marketing. The public pages set no cookies, and visitor statistics and ad measurement only happen if you say yes. If you pay by card, Stripe sets two cookies to detect fraud.
Further down you will find why we are allowed to do this, who handles the data for us, how long it is kept and what your rights are. If you are a student, there is a section just for you.
What we store
About you, if you have an account
- Name, email address and — if you fill it in — phone number
- A profile picture, if you upload one
- Your code for recommending other families, and how many signed up with it
- We never see your password. It is handled encrypted by our login provider and is inaccessible even to us.
About the child
- Name, year group, school and the subjects concerned
- Study goals, if you fill them in
- Tasks, skill areas and material the tutor adds
- Answers to the digital tasks and how they were marked: what was answered to each question, whether it was right and when. The marking is automatic, but it decides nothing about the child: it shows the child, you and the tutor what has stuck
- Reports after each session: what you did, how it went, what needs practice
- If you have given the child a login of their own: the username, when you as guardian approved it, when the child last logged in and the notifications in the child’s view. We never see the password
- If you have added the child’s own email: the address, when the child confirmed it, whether you have turned on emails to the child and which emails the child has turned off. Only you, the child and we see the address, not the tutor. Attempts to log in with the address are counted for a day, to protect the child’s login, without the address or the IP address being stored in plain text
Your own notes about the child are private even from us. They sit in a separate table where neither tutor nor administrator has read access — that is a technical barrier in the database, not a promise to refrain from looking. We moved them there for exactly that reason: as long as they sat in the same row as the rest of the student record, a tutor could have read them through the API even though no screen displayed them.
About you if you apply to be a tutor
- Name, age, email, school, subjects and when you can work
- What you write in the free-text field, and your CV if you attach one
- If you are accepted: your profile text, town, subjects and the hourly rate we agreed
- Remove your personal identity number from the CV before you send it. We do not need it to read an application.
About the sessions and the contact
- Date, time, subject, length and format for each booked session
- If a session is cancelled: when it was cancelled and by whom
- If the tutor declines a time you suggested, or suggests another: what they write to you about why
- Messages between family and tutor in the platform’s chat
- Payments and pay statements: which session was paid, amounts and when. We never have the card details
If you write to us or something breaks
- If you use the contact form, we store your name, email address and what you wrote, so that we can reply.
- If something goes wrong on a page, we store the error, which page it was and what kind of browser, and which account was logged in, if any. That is so we can fix the error.
- The notifications in the views and the emails we send are kept for a while, so that we can see that they arrived.
About how you found us
If you send an enquiry we also store where the visit came from: which page you landed on, which website linked here, and the tags we ourselves put in the address when advertising. It is so that we know which channels actually lead to someone getting in touch. If you said yes in the box asking about it, your browser remembers where you landed until you close the tab, so that it is right even if you read a few pages first. If you said no, we only see the page where you sent the enquiry. You change your answer under Cookies and storage.
The data belongs to the visit, not to you. We build no profile from it, we do not follow you between visits, and it cannot be linked to any other site you have been on. If you send no enquiry, nothing is stored with us.
If you type a code in the enquiry form, or arrive there through a link or a poster with a code, we store the code with the enquiry. It is in a field you see and can empty before you send. A code comes from a poster or from a family or tutor who recommended us to you, and then we see who recommended you. Whoever recommended you sees how many signed up with the code and how many of them became customers, but not who. A family that recommended you gets an hour for free when a new family has had its first session, and can tell from that that someone they recommended has started.
Documents about the business
Agreements, certificates and insurance papers are kept in a separate closed storage. Only we can reach it, with one exception: an agreement we have with you, such as an employment contract or an agreement with your family, we can share with you, and then you see it under Profil & inställningar (profile and settings) in your view. No one else sees it. An agreement naturally contains data about the person it concerns. Teaching material is not kept there but together with the rest of the student’s data, so that the family and the tutor can reach it.
Why we are allowed to do this
Everything we do with the data rests on one of the legal bases in the General Data Protection Regulation (GDPR Article 6):
- Enquiries: to answer your request before you become customers (Article 6(1)(b)).
- Account, bookings, sessions, messages, notifications and payments: to perform the contract with you (Article 6(1)(b)).
- Data about the child, study plan, tasks and the answers to them, and reports: legitimate interest (Article 6(1)(f)). The child is not a party to the contract, but help for the child is what you asked for, and it cannot be given without the data. The child’s interests weigh the most in that balance, which is why we only collect what teaching needs.
- The child’s own login: the contract with you (Article 6(1)(b)). You are the ones who ask for it, create it and can remove it, and when you create it you confirm that you are the guardian and approve of the child using Nextrum. We store when that was done.
- The child’s own email and the emails to the child: the contract with you (Article 6(1)(b)). You are the ones who add the address, turn on the emails and can remove both, and the address is used only once the child has confirmed it. Counting attempts to log in with it is legitimate interest (Article 6(1)(f)): protecting the child’s login against guessing.
- Accounting records: legal obligation (Article 6(1)(c)), the Swedish Accounting Act.
- Job applications: legitimate interest (Article 6(1)(f)), being able to hire the right tutors. If you are hired, the contract applies.
- The contact form and error reports: legitimate interest (Article 6(1)(f)), being able to reply to whoever writes and to keep the website running.
- The change log and protecting the data: legitimate interest (Article 6(1)(f)), being able to show who did what and to notice if something went wrong.
- Us reading the chat: legitimate interest (Article 6(1)(f)), keeping the children safe and being able to sort out what has gone wrong between a family and a tutor.
- The code in the enquiry and recommendations: legitimate interest (Article 6(1)(f)), knowing which recommendations and posters lead to someone getting in touch. For the family that recommended, the free hour is part of the contract (Article 6(1)(b)).
- Visitor statistics and ad measurement: your consent (Article 6(1)(a)), which you can withdraw at any time.
We do not ask for sensitive data, such as health or diagnoses, and ask you not to write it in the text boxes. If something like that is there anyway, we remove it when we see it.
Who can see what
Access is restricted in the database, row by row — not only in the interface. That means the restriction holds even for someone who tried to go around the site.
- A tutor sees only the students they are matched with, and only their own sessions, tasks and the answers to them, material, messages and the agreements we have shared with them. They never see the child’s own email.
- A family sees only their own children, sessions, payments, messages and the agreements we have shared with them.
- A child with their own login sees only their own sessions, hours, study plan, notifications and NexLäx, and the reports if the parent has turned that on. Never prices, payments, offers, the parent’s details or anything about other families. The child can do their NexLäx levels and tick off their tasks, but cannot book, cancel or change anything else. The barrier is in the database: the child’s login reaches no tables, only what is the child’s own.
- We can reach what is needed to run the service and solve problems — with the exception of your private notes, described above. Each of us sees only what their own permissions cover, and none of us can see or change a child’s password.
- The chat between family and tutor is something we can open and read. We do so to keep the children safe, to make sure the tone is right and to be able to sort things out if something has gone wrong. We never write in it. You get no notification when we read and nothing is marked as read, but every time one of us opens a chat it is recorded in the log below: who and when, never the text.
- Files — material, profile pictures and agreements — sit in closed storage. Each file opens through a time-limited link that expires after an hour at most, for an agreement after five minutes. If such a link is passed on, it does not work for long.
We also keep a log of who on our side changed what and when: a match, an invoice, a session, a permission. It also records every time one of us has opened a chat. Who made someone an admin, and with which permissions, is recorded in a separate log that cannot be altered either. The log carries states, links and timestamps — never names, addresses, message texts or anything written about a child. It cannot be altered or deleted afterwards, not by us either, and that is the whole point of it.
Who handles the data for us
We use a few suppliers to run the service. They only get what their part needs, and may only use it for us. We have a data processing agreement with each of them (GDPR Article 28).
- Supabase: database, login and files. The servers are within the EU (Ireland).
- Vercel (USA): hosts the website itself, and counts visits if you said yes to visitor statistics. The counting happens without cookies: unique visitors are derived from a hash of IP and browser type with a salt that changes every day, and the raw IP address is not stored. The student view and the tutor view are not measured.
- Resend (USA): sends our emails, such as booking confirmations, reminders and notifications, and the emails to a child’s own address when you have turned them on. Resend gets the recipient’s address and the email’s content.
- Anthropic (USA): when a tutor chooses to, Anthropic’s AI rewrites the tutor’s notes after a session into a report, and suggests short greetings. Anthropic gets the notes and the student’s first name and school year. Personal identity numbers, phone numbers and email addresses are masked before anything is sent, and Anthropic does not train its models on it. We also use Anthropic to support our own work, for example to see which enquiries are waiting for a reply. It then gets students’ initials, school year and subject and masked free text, never names, email addresses or addresses.
- Stripe: receives card payments. You give your card details directly to Stripe, never to us, and we do not store them. Stripe gets your email address, the amount and which session the payment is for (subject and date), and we get back that the session is paid. For fraud checks and what the law requires of a payment service, Stripe is itself the controller, as described in Stripe’s privacy policy.
- Fortnox (Sweden): our bookkeeping, and the invoices when you have chosen to pay by invoice. Fortnox gets your name and email address, which sessions the invoice is for and the amount, and sends the invoice to you.
- Google: online sessions are held in Google Meet. Every confirmed online session gets its own room, and the link is on the session’s page. During the session, video and audio pass through Google, and Google sees the name each person enters when joining. We do not record the sessions. How Google handles the data is described in Google’s privacy policy.
Beyond them, nothing is fetched from anyone else. The fonts and the library the login needs are hosted by us.
Data that leaves the EU
Vercel, Resend and Anthropic are American companies, and Stripe and Google may process data in the USA. The transfers are protected by the European Commission’s standard contractual clauses and, for suppliers that are certified, also by the EU’s decision on the EU-US Data Privacy Framework. If you would like a copy of the safeguards, write to info@nextrum.se.
How long we keep things
- Enquiries: six months after the last contact, the name, email, the child’s name and what you wrote are removed. Only the date, school year, subject, where the visit came from and the code if you typed one remain, which do not identify you. This happens automatically every night. If the account a code belongs to is deleted, the code goes with it, and so does the link to who recommended you.
- Applications and CVs: deleted a year after they arrived, or thirty days after the last step in the recruitment if that is later. This happens automatically every night. If you become a tutor, the application stays while you work with us, and is deleted two years after your last session, report or login.
- Account and study history: as long as you use the service. If an account has not been used for two years, we get in touch and delete what does not need to remain. You can ask us to delete it earlier at any time.
- Contact messages: deleted six months after they arrived or were answered. This happens automatically every night.
- Error reports: deleted after 90 days, automatically.
- The reply to a suggested time: what the tutor writes when declining a time or suggesting another is deleted 30 days after the reply, or 30 days after the session. This happens automatically every night. The session itself remains.
- Notifications and sent emails: the notifications in the views are deleted after 180 days, and the records of each sent email after 90 days.
- The child’s login: as long as you keep it. If you remove it, or the child is deleted, the username, the login and the child’s notifications are deleted at once. Otherwise the notifications in the child’s view are deleted after 180 days.
- The child’s own email: as long as you keep it and the login exists. If you remove it or the login, or the child is deleted, it is deleted at once. An address that was never confirmed is deleted 30 days after we sent the link, and attempts to log in with an address after a day. This happens automatically every night.
- Accounting records: payments and payout records, seven years. That is required by the Swedish Accounting Act and not something we can shorten, not even on request.
- The change log: as long as the business exists. It carries states and times, never names or text, and it is our receipt of who did what.
- Agreements and certificates: as long as they apply, and after that as long as the law requires.
- Our own working notes: tasks and reminders we write for ourselves are deleted a year after they are closed, and what our AI assistant read and wrote is cleared after 90 days. This happens automatically every night.
What we delete may remain for a short time in our suppliers’ backups, until they are overwritten. Nobody uses them for anything other than restoring the service after a failure.
Children’s data
The service is about children, so their data is the most sensitive thing we handle.
- A child cannot create an account on their own. The parent registers, accepts the terms and enters the details about the child.
- The parent can give the child a login of their own to a simple view with NexLäx, sessions, hours, study plan and notifications, and pause or remove it at any time. The login is a username and a password. The technical address it needs (the username at barn.nextrum.se) never receives any email.
- The parent can also add the child’s own email. We send a link there, and the address is used only once the child has clicked it. After that the child can log in with it, and get emails about their sessions if the parent turns that on: when a session is booked or cancelled, and a reminder before the session. The emails never mention prices or payments, the child can turn them off, and the parent can turn them off and remove the address at any time. The parent controls the password, and we never send the child anything about the login or the password.
- We only collect what teaching needs: school year, school, subjects and goals. We never ask for personal identity numbers, diagnoses or grades, and ask you not to write such things in the text boxes.
- As a parent you can see, change and delete what is stored about your child at any time.
For you as a student
The same as above, but shorter.
- Your parent has asked us for help for you. To be able to help you, we store your name, your school year, your subjects, your tasks, how you answered the digital ones and what you and your tutor did in the sessions.
- Only your parent, your tutor and we at Nextrum can see it.
- If your parent has given you a login of your own, you do NexLäx and see your sessions, your hours, your study plan and your notifications at nextrum.se/barn. Nobody sees your password, not even us. If you want to change something, ask your parent.
- If your parent has added your email, you get an email where you confirm that it is yours. After that you can log in with it, and get emails about your sessions if your parent turns that on. You choose which emails you get under Inställningar (Settings) in your view, and every email has a link to stop them.
- We never sell it and never show it to anyone else.
- Do you want to know what is stored about you, or want something removed? Tell your parent, or email us at info@nextrum.se.
Your rights
You have the right to know what we have stored about you, to have it corrected if it is wrong, to have it erased, to restrict how we use it, to object to what we do on the basis of legitimate interest, and to receive what you yourself provided in a format you can take with you. If you said yes to visitor statistics or ad measurement, you withdraw it at any time under Cookies and storage, as easily as you gave it. For everything else, write to info@nextrum.se, and we reply within one month.
If you think we are handling your data wrongly, you have the right to complain to the Swedish Authority for Privacy Protection (IMY). Do get in touch with us first, it is usually quicker to sort out.
Do you have to provide the data?
No, but without it we cannot help you. An enquiry needs a name and an email address so that we can reply, and sessions cannot be booked without an account. Anything marked as optional can be left empty.
AI and automated decisions
We make no automated decisions about you or your child. AI is used to rewrite a tutor’s own notes after a session, when the tutor chooses to, to suggest a short greeting, and to support us when we plan our work. The AI suggests, and a person decides. It cannot change anything on its own.
If something goes wrong
If data were to end up in the wrong hands, we report it to the Swedish Authority for Privacy Protection within 72 hours, and tell those of you affected if it poses a risk to you.
Cookies and browser storage
The public pages set no cookies. Visitor statistics and ad measurement only happen if you say yes, and Stripe sets two cookies when you pay by card. Everything stored, and why, is on its own page: Cookies and storage.
Changes
If we change anything material we update the date below, and contact those of you with an account if the change affects you.
Last updated 1 October 2026. This is a translation; in the event of any conflict of interpretation, the Swedish version governs.