Privacy Policy

Last updated: September 18, 2026

Wrenzik ("we", "us") provides an online platform that tutoring schools, gyms, studios and therapy practices use to run schedules, attendance, payments and member portals. This policy explains what personal data we handle, why, and the rights you have under the EU General Data Protection Regulation (GDPR).

You can reach us about anything in this policy at [email protected].

Two roles: controller and processor

For the data of our own customers — the person who registers an organization, staff accounts, billing and support correspondence — we are the data controller.

For the data an organization stores inside Wrenzik about its students, members, clients and their families, that organization is the controller and we act only as its processor: we handle that data on the organization's instructions under our Data Processing Agreement. If you are a student, parent or member with questions about data your school, gym or practice keeps in Wrenzik, please contact that organization directly — we will assist them with your request.

Data we collect as a controller

  • Account data: your name, email address and hashed password, and your organization's name, type and chosen address on our platform.
  • Billing data: your subscription plan, invoices and payment status. Card details are entered directly with our payment provider, Stripe — they never reach our servers.
  • Support and contact data: emails you send us and our replies.
  • Technical logs: IP addresses, timestamps and security events (such as sign-ins) kept for security and troubleshooting; application logs deliberately exclude personal data.

Data we process on behalf of organizations

Organizations decide what they store. Typically this includes names, contact details, dates of birth, enrollment, attendance and booking history, payment records, and portal accounts for their students, members or clients — including minors where the organization works with children. Therapy practices may store client session records. The organization is responsible for having a lawful basis (including guardian consent where required) for the data it enters.

Purposes and legal bases

  • Providing the service and your account — performance of a contract (Art. 6(1)(b) GDPR).
  • Billing, invoicing and accounting — contract and legal obligation (Art. 6(1)(b), (c)).
  • Security, abuse prevention and service integrity — legitimate interest (Art. 6(1)(f)).
  • Answering messages you send us — legitimate interest or steps prior to a contract.
  • We do not use your data for advertising and we never sell it.

Cookies and local storage

Wrenzik uses no analytics or advertising trackers. We store only what the service needs to work:

  • A session (refresh) cookie — strictly necessary; it keeps you signed in, is HttpOnly and is sent only to our own domain.
  • A language cookie (klassio_lang) — remembers whether you chose English or Greek.
  • A theme preference (light/dark) kept in your browser's local storage.

Who we share data with

We use a small number of service providers (subprocessors) to run Wrenzik — hosting in the EU, payment processing, email delivery, networking and monitoring. The current list, including each provider's location and safeguards, is always published on our Subprocessors page.

Where a provider is established outside the European Economic Area, transfers rely on an EU adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses. We never share personal data with advertisers or data brokers.

Where data lives and how it is protected

  • All customer data is hosted in EU data centers, with encrypted backups stored in the EU and kept for 14 days.
  • Each organization's data lives in its own isolated database schema — organizations can never read each other's data.
  • All traffic is encrypted in transit (TLS); passwords and session tokens are stored only in hashed form.
  • Access is role-based, and security-relevant events are logged.

How long we keep data

  • Organization data: for the life of the subscription, then deleted within 30 days of termination (backup copies expire within a further 14 days).
  • Billing records: for as long as tax law requires.
  • Security and audit logs: up to 12 months.
  • Support correspondence: up to 24 months after the matter is closed.

Your rights

You can ask us for access to, correction, deletion, restriction or portability of the personal data we control, or object to processing based on legitimate interest — email [email protected] and we will respond within one month. You also have the right to lodge a complaint with your supervisory authority — in Greece the Hellenic Data Protection Authority (dpa.gr), in Cyprus the Commissioner for Personal Data Protection (dataprotection.gov.cy).

For data held about you by a school, gym or practice using Wrenzik, direct your request to that organization; we support them in fulfilling it.

Children

Portal accounts for minors are created only at the direction of the organization the child belongs to, which remains responsible for obtaining any guardian consent its law requires. We never knowingly collect children's data for our own purposes.

Changes to this policy

We will post any changes on this page and, for material changes, notify account owners by email. The "last updated" date above always reflects the current version.