Last updated: August 2026 ยท Version 1.0 ยท UK GDPR Article 13 compliant
๐ Short version: Your document content is never stored on our servers. It is sent to Google's Gemini AI for analysis and immediately discarded. We collect no personal data about you as a user.
Data Controller: Privacomply Ltd
DPO / Responsible Person: Kevin Morrison, IAPP CIPP/E, IAPP CIPM
Email: privacy@privacomply.co.uk
Website: childsafe-ai.privacomply.co.uk
ChildSafe AI is a compliance assessment tool for organisations that process children's data. It is operated by Privacomply Ltd and designed by an IAPP-certified privacy professional.
When you run a compliance analysis, the first 4,000 characters of your document are transmitted to Google's Gemini AI via our serverless function. This content is:
โ ๏ธ Please do not submit documents containing personal data (e.g., individual names, email addresses). ChildSafe AI is designed for policy documents and compliance reports, not personal records.
The following data is stored in your browser only โ it never leaves your device via our systems:
| Key | What's stored | Retention |
|---|---|---|
childsafe_ai_history | Up to 25 analysis summaries: document name, score, risk level, framework tags, date. No document content. | Until you clear browser data |
childsafe_welcome_seen | Whether you have seen the onboarding modal (value: "1") | Until you clear browser data |
childsafe_api_key | Your Gemini API key, if you choose to enter one | Until you clear browser data or remove it |
childsafe_ai_reviewers | Reviewer registry: name, qualifications, hashed PIN (SHA-256), review count | Until you clear browser data |
childsafe_audit_log | Anonymised audit entries: timestamp, framework IDs, document type, risk band. No document content. No names. | Last 50 entries (FIFO); until you clear browser data |
Our hosting provider Netlify automatically records standard access logs including your IP address, request timestamp, and response size. These logs are retained for 30 days and are governed by Netlify's privacy policy.
| Processing activity | Lawful basis |
|---|---|
| Transmitting document content to Gemini API for analysis | Legitimate interests (Article 6(1)(f)) โ you actively submit the document for analysis; the processing is necessary to deliver the service you requested |
| Netlify access logs (IP, timestamp) | Legitimate interests โ security, abuse prevention, service operation |
| Browser localStorage (history, reviewers, audit log) | Legitimate interests โ functionality and audit capability; all stored locally under your control |
| Data | Retention |
|---|---|
| Document content | Session only โ discarded immediately after analysis. Zero server-side retention. |
| Browser localStorage | Retained until you clear your browser data. You are in full control. |
| Netlify access logs | 30 days (Netlify standard) |
๐ฌ๐ง All data processing takes place in the United Kingdom (London). ChildSafe AI is configured to route all AI inference through Privacomply's UK-region infrastructure. No document content is transferred outside the UK for processing.
| Processor | Processing Location | Purpose | Safeguard |
|---|---|---|---|
| Privacomply Ltd / Google Cloud (Vertex AI) | London, UK (europe-west2) | AI inference โ compliance analysis | UK-region endpoint configured; data does not leave the UK for AI processing. Governed by Google Cloud DPA. |
| Netlify Inc. | UK/EU CDN edge; function execution in configured region | Hosting, CDN, serverless function proxy | Netlify DPA; function acts as a transit proxy only โ no content storage. Processing region set to UK. |
ChildSafe AI is designed for UK-only data processing. No personal data or document content is intentionally transferred outside the United Kingdom for AI processing. Should any incidental transfer occur via CDN infrastructure, Standard Contractual Clauses (SCCs) apply via both processors' DPAs.
As a UK data subject, you have the following rights:
To exercise any right, contact: privacy@privacomply.co.uk
You also have the right to lodge a complaint with the ICO: ico.org.uk/make-a-complaint
ChildSafe AI produces AI-generated compliance assessments. These are advisory outputs only and do not constitute automated decisions about individuals under Article 22 UK GDPR. All compliance certificates require human expert review and sign-off before they are issued.
ChildSafe AI does not use cookies. Session data is held in browser memory (JavaScript) and, where applicable, browser localStorage under your control.
ChildSafe AI is a professional compliance tool intended for use by organisations and privacy professionals. It is not directed at children and we do not knowingly collect data from individuals under 18.
We will update this notice if our processing changes materially. The version number and date at the top of this page reflect the current version.
For any privacy questions: privacy@privacomply.co.uk
For general enquiries: kevin@outcomes.org.uk
ChildSafe AI Privacy Notice v1.0 ยท August 2026 ยท Privacomply Ltd ยท Designed by Kevin Morrison CIPP/E CIPM