Privacy Policy
Last updated: 8/11/2026
Privacy Policy
Last updated: 21 July 2026
Kidy (hereinafter referred to as "Kidy", "we", "our", "us") is committed to protecting the privacy and security of your personal data. This Privacy Policy describes how we collect, use, store, and protect your information when you use the Kidy platform (website, mobile application, and associated services).
Kidy is a SaaS (Software as a Service) platform designed for educational institutions (kindergartens, schools, after-school programs) and operates in compliance with the General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679.
Data Controller
The Kidy platform is operated by 2Lines Sistem SRL, a company registered in Romania, tax ID RO16807695, trade register number J2004001481239, with its registered office in Bucharest, Romania.
For any question regarding this policy or to exercise your rights, you can contact us at contact@kidy.pro.
For children's data and for data generated within the activity of an educational institution, that institution is the data controller and 2Lines Sistem SRL acts as a data processor. See section 4.
1. What Data We Collect
We collect the following categories of personal data:
a) Data provided directly by users
- Account data: first name, last name, email address, phone number, role within the institution (administrator, educator, parent)
- Institution data: institution name, address, billing information
- Payment data: payment information is processed by Stripe and is not stored on our servers
- Communications: messages sent through the integrated messaging platform
b) Children's data
- First and last name
- Date of birth
- Attendance and absence records
- Enrollment data and class/group assignments
- Relevant medical information (allergies, special conditions) – only if provided by parents or the institution
c) Automatically collected data
- IP address
- Browser and device type
- Pages visited and session duration
- Cookie data (see our Cookie Policy)
- Push notification tokens (Firebase Cloud Messaging)
d) Data collected by the mobile app
- Precise location (GPS) – collected only when a staff member taps the clock-in/clock-out button in the app. The geographic coordinates at that moment are transmitted in order to confirm attendance at the institution's location. We do not track location in the background and we do not collect the location of parents or children. The permission can be refused or withdrawn at any time from the operating system settings; clock-in then remains available via QR code scanning.
- Camera – used to scan clock-in QR codes (images are processed locally on the device in real time and are neither stored nor transmitted) and, optionally, to take a profile photo — in that case only the photo you explicitly confirm is uploaded (see section e) below).
- Biometric authentication – if you enable fingerprint or face unlock, the verification is performed entirely by the device's operating system. Kidy only receives the result (success/failure). Biometric data never leaves the device and is not accessible to us.
- Push notification token – a device identifier generated by Firebase Cloud Messaging, used solely to deliver notifications. It is deleted when the app is uninstalled or when the account is deleted.
e) Profile photos (optional)
- What we collect: users may optionally upload a profile photo for their own account and for the children in their care. Uploading a photo is never required.
- How photos are selected: photos are chosen through the operating system's photo picker or taken on the spot with the camera — the app does not request or receive permission to access the device's photo gallery; it only receives the photo you select.
- How we process them: on upload, EXIF metadata (including GPS coordinates) is stripped server-side, and the image is resized and converted to WebP format.
- How we store them: storage is private; images are served exclusively through expiring signed URLs, visible only to authorized users within the same organization (institution).
- What we do NOT do: photos are not shared with third parties, are not used for advertising, and are not used to train artificial-intelligence models.
- Control: the photo can be replaced or deleted at any time, directly from the app.
- Purpose: app functionality only — visual identification of users and children in the interface.
2. How We Use Your Data
We use your data for the following purposes:
- Service delivery: managing accounts, authentication, administering institutions and student/child data
- Communication: sending push notifications, transactional emails, and in-platform messages
- Billing: processing payments and issuing invoices
- Platform improvement: statistical analysis and technical issue diagnostics
- Legal compliance: fulfilling applicable legal obligations
- Security: fraud prevention and platform protection
3. Legal Basis (GDPR Art. 6)
We process your data based on the following legal grounds:
- Performance of a contract (Art. 6(1)(b)): processing is necessary for providing the Kidy service under contractual terms
- Consent (Art. 6(1)(a)): for analytics and marketing cookies, push notifications, and marketing communications
- Legitimate interest (Art. 6(1)(f)): for platform improvement, fraud prevention, and IT security
- Legal obligation (Art. 6(1)(c)): for compliance with tax and reporting requirements
4. Children's Data
Kidy processes children's data exclusively as a data processor, under the instructions of educational institutions (data controllers). Institutions are responsible for obtaining the necessary consent from parents/legal guardians.
We do not collect data directly from children. All children's data is entered by authorized institution staff or by parents through the application.
Children's data is used exclusively for educational and administrative purposes: attendance, group management, parent communication, and reporting.
5. Data Sharing with Third Parties
We do not sell your personal data. We share data only with the following categories of providers:
- Amazon Web Services (AWS): infrastructure hosting – EU region (Frankfurt, Germany). Data processing agreement in place.
- Stripe: credit card payment processing. Stripe acts as an independent controller for payment data. Stripe Privacy Policy.
- Firebase (Google): push notification delivery. Google processes only device tokens and notification content.
- Google Analytics / Google Tag Manager: traffic analysis exclusively on the public website kidy.pro (anonymized/pseudonymized data). The Kidy mobile app does not use Google Analytics and contains no analytics or advertising tools whatsoever.
- Email providers: transactional email delivery.
All our providers are GDPR-compliant and have signed Data Processing Agreements (DPAs).
6. International Data Transfers
Your data is stored on AWS servers located within the European Union (Frankfurt, Germany). In cases where a service provider transfers data outside the EU/EEA, we ensure adequate safeguards are in place (Standard Contractual Clauses, adequacy decisions, or other approved mechanisms).
7. Data Retention
We retain your data according to the following rules:
- Account data: for the duration of the active account + 30 days after deletion
- Children's data: for the duration of enrollment + according to the institution's retention policy
- Billing data: 10 years as required by Romanian tax legislation
- Security logs: 12 months
- Cookie data: according to the durations specified in the Cookie Policy
Upon termination of an institution's subscription, data is retained for a 30-day grace period, after which it is permanently deleted.
8. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15): you can request a copy of your personal data
- Right to rectification (Art. 16): you can correct inaccurate data
- Right to erasure (Art. 17): you can request the deletion of your data ("right to be forgotten")
- Right to restriction of processing (Art. 18): you can limit data processing
- Right to data portability (Art. 20): you can receive your data in a structured, commonly used, and machine-readable format
- Right to object (Art. 21): you can object to processing in certain circumstances
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing
To exercise your rights, contact us at contact@kidy.pro. We will respond within 30 days.
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) – www.dataprotection.ro.
For detailed instructions on deleting your account and associated data — including what is deleted, what we are required to retain, and how long processing takes — see the Account and Data Deletion page.
9. Cookies
We use cookies and similar technologies for platform functionality, analytics, and marketing. For full details, please refer to our Cookie Policy.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Secure authentication with JWT tokens
- Multi-tenant database isolation
- Regular encrypted backups
- Continuous monitoring and access logging
- Role-based access control (RBAC)
11. Contact Information
For any questions regarding this policy or your personal data:
- Email: contact@kidy.pro
- Platform: kidy.pro
12. Changes to This Policy
We reserve the right to update this Privacy Policy. Significant changes will be communicated via email or in-platform notification. The date of the last update is indicated at the beginning of this document.
Continued use of the platform after changes are published constitutes acceptance of the new version of the policy.