โ† Back to app

Privacy Notice

Last updated: August 2026  ยท  Version 1.0  ยท  UK GDPR Article 13 compliant

๐Ÿ”’ Short version: Your document content is never stored on our servers. It is sent to Google's Gemini AI for analysis and immediately discarded. We collect no personal data about you as a user.

1. Who We Are

Data Controller: Privacomply Ltd

DPO / Responsible Person: Kevin Morrison, IAPP CIPP/E, IAPP CIPM

Email: privacy@privacomply.co.uk

Website: childsafe-ai.privacomply.co.uk

ChildSafe AI is a compliance assessment tool for organisations that process children's data. It is operated by Privacomply Ltd and designed by an IAPP-certified privacy professional.

2. What Data We Process and Why

2.1 Document Content You Submit

When you run a compliance analysis, the first 4,000 characters of your document are transmitted to Google's Gemini AI via our serverless function. This content is:

โš ๏ธ Please do not submit documents containing personal data (e.g., individual names, email addresses). ChildSafe AI is designed for policy documents and compliance reports, not personal records.

2.2 Data Stored in Your Browser (localStorage)

The following data is stored in your browser only โ€” it never leaves your device via our systems:

KeyWhat's storedRetention
childsafe_ai_historyUp to 25 analysis summaries: document name, score, risk level, framework tags, date. No document content.Until you clear browser data
childsafe_welcome_seenWhether you have seen the onboarding modal (value: "1")Until you clear browser data
childsafe_api_keyYour Gemini API key, if you choose to enter oneUntil you clear browser data or remove it
childsafe_ai_reviewersReviewer registry: name, qualifications, hashed PIN (SHA-256), review countUntil you clear browser data
childsafe_audit_logAnonymised audit entries: timestamp, framework IDs, document type, risk band. No document content. No names.Last 50 entries (FIFO); until you clear browser data

2.3 Server / Hosting Logs (Netlify)

Our hosting provider Netlify automatically records standard access logs including your IP address, request timestamp, and response size. These logs are retained for 30 days and are governed by Netlify's privacy policy.

3. Lawful Basis

Processing activityLawful basis
Transmitting document content to Gemini API for analysisLegitimate interests (Article 6(1)(f)) โ€” you actively submit the document for analysis; the processing is necessary to deliver the service you requested
Netlify access logs (IP, timestamp)Legitimate interests โ€” security, abuse prevention, service operation
Browser localStorage (history, reviewers, audit log)Legitimate interests โ€” functionality and audit capability; all stored locally under your control

4. Retention

DataRetention
Document contentSession only โ€” discarded immediately after analysis. Zero server-side retention.
Browser localStorageRetained until you clear your browser data. You are in full control.
Netlify access logs30 days (Netlify standard)

5. Processors and Data Location

๐Ÿ‡ฌ๐Ÿ‡ง All data processing takes place in the United Kingdom (London). ChildSafe AI is configured to route all AI inference through Privacomply's UK-region infrastructure. No document content is transferred outside the UK for processing.

ProcessorProcessing LocationPurposeSafeguard
Privacomply Ltd / Google Cloud (Vertex AI)London, UK (europe-west2)AI inference โ€” compliance analysisUK-region endpoint configured; data does not leave the UK for AI processing. Governed by Google Cloud DPA.
Netlify Inc.UK/EU CDN edge; function execution in configured regionHosting, CDN, serverless function proxyNetlify DPA; function acts as a transit proxy only โ€” no content storage. Processing region set to UK.

International Transfers

ChildSafe AI is designed for UK-only data processing. No personal data or document content is intentionally transferred outside the United Kingdom for AI processing. Should any incidental transfer occur via CDN infrastructure, Standard Contractual Clauses (SCCs) apply via both processors' DPAs.

6. Your Rights

As a UK data subject, you have the following rights:

To exercise any right, contact: privacy@privacomply.co.uk

You also have the right to lodge a complaint with the ICO: ico.org.uk/make-a-complaint

7. Automated Decision-Making

ChildSafe AI produces AI-generated compliance assessments. These are advisory outputs only and do not constitute automated decisions about individuals under Article 22 UK GDPR. All compliance certificates require human expert review and sign-off before they are issued.

8. Cookies

ChildSafe AI does not use cookies. Session data is held in browser memory (JavaScript) and, where applicable, browser localStorage under your control.

9. Children

ChildSafe AI is a professional compliance tool intended for use by organisations and privacy professionals. It is not directed at children and we do not knowingly collect data from individuals under 18.

10. Changes to This Notice

We will update this notice if our processing changes materially. The version number and date at the top of this page reflect the current version.

11. Contact

For any privacy questions: privacy@privacomply.co.uk

For general enquiries: kevin@outcomes.org.uk

ChildSafe AI Privacy Notice v1.0 ยท August 2026 ยท Privacomply Ltd ยท Designed by Kevin Morrison CIPP/E CIPM