Overview & Commitment
At FamilyNest, we treat your family's data with the same care we would our own. As a platform serving parents, caregivers, and children, we recognize the heightened responsibility that comes with handling sensitive personal and family information. This document outlines our security architecture, data retention timelines, compliance frameworks, and your rights regarding your data.
Security Practices
We implement industry-leading technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.
🔐 Data Encryption
- In Transit: All data is encrypted using TLS 1.3 or higher.
- At Rest: Databases and backups use AES-256 encryption with key rotation every 90 days.
- Authentication: Multi-factor authentication (MFA) enforced for all admin and support access.
Access Control & Infrastructure
Our infrastructure is hosted on certified cloud providers with strict zero-trust architecture. Access to production databases follows the principle of least privilege, with all access logged, time-bound, and reviewed quarterly. Our development and staging environments never contain production data.
Vulnerability Management
We conduct automated penetration testing monthly, third-party security audits annually, and maintain a responsible disclosure program. All critical vulnerabilities are patched within 48 hours of identification.
Data Retention Policy
We retain your data only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce agreements. Once the retention period expires, data is securely deleted or anonymized.
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Account & Profile Data | Until account deletion + 30 days | Secure cryptographic erasure |
| Pregnancy & Child Milestones | While account is active | Immediate deletion upon request |
| Community Forum Posts | Indefinite (unless reported) | Manual removal or anonymization |
| Payment & Billing Records | 7 years (tax/legal compliance) | Archived securely, masked after 3 years |
| Support Tickets & Logs | 2 years | Automated secure wipe |
| Device & Usage Analytics | 90 days (aggregated/anonymized) | Automated rotation & hashing |
Compliance & Standards
FamilyNest adheres to rigorous international privacy and security standards, particularly those governing family and child-related data:
- GDPR & GDPR-K (EU): Full compliance with data subject rights, lawful processing bases, and data protection impact assessments.
- COPPA (USA): Strict verification for users under 13, parental consent mechanisms, and restricted data collection for minors.
- CCPA/CPRA (California): Transparency in data collection, opt-out mechanisms, and sale/sharing restrictions.
- SOC 2 Type II: Annual audits verifying security, availability, and confidentiality controls.
- ISO 27001: Certified information security management system.
We conduct bi-annual compliance reviews and maintain up-to-date records of processing activities (ROPA).
Child Data Protection
Because FamilyNest serves families, we enforce additional safeguards for any data associated with minors:
- Children under 13 cannot create independent accounts. Parental/guardian accounts are required.
- Child profiles (milestones, photos, preferences) are never used for advertising or profiling.
- Facial recognition, biometric scanning, and behavioral tracking are strictly prohibited.
- Parents retain full export, modification, and deletion rights for all child-associated data.
Incident Response & Transparency
Despite robust security measures, we maintain a formalized incident response protocol aligned with NIST and ISO standards:
- Detection & Triage: Automated monitoring and security team review within 1 hour.
- Containment & Eradication: Isolate affected systems, apply patches, and revoke compromised credentials.
- Notification: Affected users notified within 72 hours of confirmed breach per GDPR/COPPA requirements.
- Recovery & Post-Mortem: Restore services, publish transparency report, and implement corrective controls.
We publish annual security transparency reports detailing incident counts, response times, and systemic improvements.
Your Rights & Controls
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access & Portability: Download a complete copy of your data in JSON/CSV format.
- Correction: Update inaccurate or outdated information instantly.
- Deletion: Request permanent erasure of your account and associated data.
- Restriction: Limit processing while disputes are resolved.
- Opt-Out: Disable marketing communications and analytics tracking.
To exercise these rights, visit your Account Settings → Privacy & Data dashboard, or contact our Data Protection Officer directly.
Security & Privacy Inquiries
Have questions about our security practices, need to report a vulnerability, or wish to submit a data request? Our trust & safety team is here to help.
📧 Contact Our Security Team
We respond to all security and privacy inquiries within 2 business days.