GDPR Compliance & Data Protection Policy
Effective Date: October 26, 2024 | Last Updated: October 26, 2024📑 Quick Navigation
📖 1. Introduction & Scope
FamilyNest ("we," "our," or "us") is committed to protecting the privacy and personal data of our users in full compliance with the General Data Protection Regulation (GDPR) and applicable European Union data protection laws. This policy applies to all visitors, users, and families who access our platform, services, or communicate with us.
We believe that transparency is foundational to trust, especially when it comes to family data. This document outlines how we collect, use, store, and protect your information, and how you can exercise your rights under EU law.
📊 2. Information We Collect
We collect data only when necessary and with clear purpose. Categories include:
- Identity Data: Name, username, profile picture, gender.
- Contact Data: Email address, postal address, phone number.
- Account Data: Passwords, security preferences, family member profiles.
- Usage Data: Pages visited, time spent, click patterns, device information, IP address.
- Family & Health-Related Data: Child's age/milestones, pregnancy stage, wellness tracking preferences (processed with explicit consent).
- Communication Data: Support tickets, survey responses, community forum posts.
- Payment Data: Processed securely via PCI-DSS compliant providers; we do not store full credit card numbers.
⚙️ 3. How We Use Your Data
We process your personal data for the following purposes:
- Providing, personalizing, and improving our parenting tools and family resources.
- Delivering age-appropriate content, milestone tracking, and developmental guides.
- Processing subscriptions, payments, and account management.
- Sending transactional emails, service updates, and security alerts.
- Delivering marketing communications (only with your explicit opt-in consent).
- Facilitating community features and peer-to-peer support forums.
- Analyzing platform usage to enhance user experience and safety.
- Complying with legal obligations and preventing fraud.
⚖️ 4. Legal Basis for Processing
Under GDPR Article 6, we process your data based on:
- Consent: Marketing emails, cookie preferences, community features.
- Contractual Necessity: Account creation, subscription management, core platform access.
- Legitimate Interests: Platform security, fraud prevention, analytics, service improvement (balanced against your rights).
- Legal Obligation: Tax compliance, data retention laws, child safety regulations.
🤝 5. Data Sharing & Third Parties
We do not sell your personal data. We only share information with trusted third-party processors bound by GDPR-compliant Data Processing Agreements (DPAs). These include:
- Cloud Hosting & Infrastructure: AWS, Cloudflare (security & delivery)
- Analytics: Google Analytics (anonymized & IP-truncated)
- Email & Marketing: Mailchimp, SendGrid (consent-based only)
- Payment Processing: Stripe, PayPal (PCI-DSS compliant)
- Customer Support: Intercom, Zendesk (ticket management)
We may also disclose data if required by law, to protect rights/safety, or during a corporate transaction (with prior notice).
🗓️ 6. Data Retention
We retain personal data only as long as necessary:
- Active Accounts: Data retained while your account is active.
- Deleted/Inactive Accounts: Removed within 30 days, except where legal/tax obligations require retention (up to 7 years).
- Marketing Consent: Data retained until you unsubscribe or withdraw consent.
- Support Tickets: Retained for 24 months after resolution.
- Children's Data: Deleted immediately upon parental request or when no longer needed for the stated purpose.
🛡️ 7. Your GDPR Rights
You have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete information.
- Erasure (Right to be Forgotten): Request deletion of your data, subject to legal exemptions.
- Restriction: Limit how we process your data in certain circumstances.
- Data Portability: Receive your data in a structured, machine-readable format.
- Objection: Opt out of marketing or legitimate interest processing.
- Withdraw Consent: At any time, without affecting the lawfulness of prior processing.
To exercise any right, contact our Data Protection Officer via the details below. We will respond within 30 calendar days.
🍪 8. Cookies & Tracking
Our platform uses essential cookies to function securely. Non-essential cookies (analytics, personalization, marketing) require your explicit consent via our cookie banner. You can manage or withdraw consent at any time through your account settings or the cookie control link in our footer.
Third-party partners may also set cookies subject to GDPR compliance and your consent preferences.
👶 9. Children's Privacy
FamilyNest is designed for parents and caregivers. We do not knowingly collect personal data from children under 16 without verifiable parental consent. If we discover unintentional collection, we will promptly delete the data and notify the parent/guardian.
🔐 10. Security Measures
We implement industry-standard technical and organizational measures to protect your data:
- End-to-end TLS 1.3 encryption for data in transit
- AES-256 encryption for data at rest
- Regular security audits, penetration testing, and vulnerability assessments
- Role-based access controls and multi-factor authentication for staff
- Strict data minimization and purpose limitation principles
- Incident response plan compliant with GDPR 72-hour breach notification requirement
🌍 11. International Data Transfers
As a global platform, some data may be processed outside the EU. All transfers are protected by:
- European Commission Adequacy Decisions
- Standard Contractual Clauses (SCCs)
- Additional safeguards including encryption and access controls
📧 12. Contact & Data Protection Officer
If you have questions about this policy, wish to exercise your GDPR rights, or report a concern, please contact:
- Data Protection Officer: dpo@familynest.com
- Support Email: privacy@familynest.com
- Postal Address: FamilyNest Data Privacy Team, 123 Parenting Lane, Suite 400, Dublin, D02 X285, Ireland
You also have the right to lodge a complaint with your local supervisory authority if you believe your data protection rights have been violated.