GDPR & Child Data Privacy Commitment
How kidsday upholds European data protection standards, protects children’s personal data, and supports school Data Protection Officers (DPOs).
Our child data privacy pledge
“Under GDPR and EU data protection guidelines, children’s data receives special legal protection. kidsday serves as a Data Processor to educational institutions, ensuring all personal records, attendance logs, and media are stored securely within the EU with strict access limits.”
Data Architecture & Legal Roles
A clear governance model defines who directs processing and how kidsday safeguards every instruction.
Data Processor vs. Data Controller
Your school or center remains the Data Controller and determines why and how personal data is used. kidsday acts as the Data Processor, handling data only on documented instructions under a strict Data Processing Agreement.
EU Data Residency
Primary records and resilient backups are hosted within European Union data centers, helping institutions meet local residency and transfer-risk requirements.
Lawful Basis for Processing
Workflows support performance of contract, legal obligations, and consent-based processing. Photo and video permissions remain separate, explicit, and auditable.
Data Subject Rights
Operational pipelines help administrators answer family requests accurately and without unnecessary delay.
Right of Access (DSAR)
Self-service export tools help authorized administrators prepare comprehensive personal-data summaries for parents and guardians upon verified request.
Right to Erasure
Automated purge workflows permanently remove student profiles, media, and operational records after enrollment ends, except where financial or statutory retention duties still apply.
Right to Data Portability
Standardized JSON, CSV, and PDF exports support secure family or center migrations without locking personal data into proprietary formats.
Parental Consent & Child Media Protection
Granular, reversible permissions keep families in control of how a child’s image and information may be used.
Granular Consent Toggles
Multi-tier authorization separates internal classroom and family-app use from external promotional use, so consent is specific rather than bundled.
Consent Revocation
Preference updates take effect in real time, restricting media access across authorized classroom devices as soon as a parent or guardian revokes consent.
Zero Profiling
kidsday prohibits automated behavioral profiling, advertising profiles, and cross-service tracking of children.
Data Processing Agreements & DPO Support
Legal documentation and a direct compliance channel help privacy teams complete reviews with confidence.
Standard DPA
A standard Data Processing Agreement incorporating applicable EU Standard Contractual Clauses is available for institutional review and signature.
Sub-processor Transparency
A maintained list identifies vetted infrastructure and payment sub-processors. Material changes are communicated with 30 days’ advance notice.
Dedicated Compliance Channel
School Data Protection Officers can request security questionnaires, audit evidence, and tailored privacy assessments through our compliance team.
Need a Data Processing Agreement (DPA) for Your School?
Request our standard DPA by email or arrange a custom privacy review with our Data Protection Team.