Matheia · matimenti

Data Processing Agreement

Last updated: July 2026

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between a tutor or organization using Matheia to manage their own students (the “Controller”, “you”) and Matimenti Marcin Kobuszewski, operator of the Matheia platform (the “Processor”, “Matheia”). It forms part of the Provider Terms and applies where Matheia processes personal data on your behalf. It reflects Article 28 of the GDPR. Where Matheia acts as a controller in its own right (for example, for platform account data), the Privacy Policy applies instead.

2. Subject matter, nature, and purpose

Matheia processes personal data on your behalf only to provide the platform features you use to run your tutoring — such as managing your student roster, scheduling and delivering lessons, recording notes and materials, and facilitating payments and invoicing. Processing lasts for as long as you use the platform for these purposes, plus any period needed to return or delete the data. Matheia processes the data only on your documented instructions — which include your configuration and use of the platform and this DPA — unless required otherwise by law, in which case it will inform you unless the law prohibits it.

3. Categories of data and data subjects

The data subjects are your students and, where relevant, their parents or legal guardians. The personal data processed may include identity and contact details, lesson and scheduling records, notes and materials you or your students add, and the status of payments. Special-category data should not be entered into free-text fields; you are responsible for what you record.

4. Matheia's obligations as processor

Matheia will: process the data only on your instructions; ensure that persons authorised to process it are bound by confidentiality; implement appropriate technical and organisational security measures (see the Privacy Policy); assist you — taking into account the nature of the processing — in fulfilling your obligations to respond to data-subject requests and to ensure security, breach notification, and data protection impact assessments; and make available the information necessary to demonstrate compliance with these obligations.

5. Sub-processors

You authorise Matheia to engage sub-processors to provide the service, including Stripe (payments), FakturaXL (invoicing), Google (calendar and drive, where connected by you or your students), and hosting and email-delivery providers. Matheia imposes data-protection obligations on its sub-processors equivalent to those in this DPA and remains responsible for their performance. Matheia will inform you of intended changes to its sub-processors and give you the opportunity to object on reasonable data-protection grounds.

6. International transfers

Where a sub-processor processes personal data outside the European Economic Area, the transfer is protected by an appropriate safeguard under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

7. Assistance with data-subject rights

Taking into account the nature of the processing, Matheia will assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights. If Matheia receives such a request directly, it will forward it to you rather than responding itself, unless the law requires otherwise.

8. Personal data breaches

Matheia will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, and will provide the information reasonably available to help you meet your own notification obligations.

9. Return or deletion of data

On termination of the service, or at your request, Matheia will delete or return the personal data processed on your behalf and delete existing copies, unless the law requires it to be retained — for example, invoicing records kept for the statutory accounting period.

10. Audits and information

Matheia will make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — subject to reasonable notice, confidentiality, and measures to protect other users' data and the security of the platform.

11. Liability and governing law

This DPA is governed by Polish law and forms part of your agreement with Matheia. In the event of a conflict between this DPA and the Provider Terms or the general Terms on matters of personal data processing, this DPA prevails. Liability is subject to the limitations set out in the general Terms, to the extent permitted by law.

12. Contact

Data-protection contact: help@matheia.com. Processor: Matimenti Marcin Kobuszewski, 91A, 07-411 Ławy, Poland. NIP 7582274330, REGON 526832383.