Privacy Policy
Last updated: 23 September 2026 · Version 1.0
1. Who we are
MINDIDIA ("we", "us") is a family-safe learning and games platform operated by ASM Professional Services, registered in the Netherlands (KVK 42137630, VAT NL005526019B33). We are the data controller for the personal data described here. Contact for all privacy questions, including our data protection contact: drmarfani5@gmail.com.
This policy applies to the MINDIDIA website and app. It is written to meet the EU General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), the UK GDPR, and similar laws in the other countries where MINDIDIA is offered, including the US Children's Online Privacy Protection Act (COPPA).
2. Who can use MINDIDIA
- Only adults aged 18 or over can create an account (the "account holder").
- An account holder can add one adult profile and up to two child profiles. Children never create their own account and never sign in with an email address.
- When an account holder adds a child profile they confirm they are that child's parent or legal guardian and give consent. See our Children's Privacy & Safety policy for details.
3. What data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a secure one-way hash), sign-in method (email or Google) | You |
| Profile data | First name or nickname, age group (e.g. "Young Learners 7–9"), avatar colour, time zone | Account holder |
| Play data | Games played, answers, scores, XP, levels, achievements, favourites, play minutes per day | Generated as you play |
| Parent settings | Daily time limits, allowed play hours, parent PIN (stored only as a secure hash) | Account holder |
| Consent records | Date and version of the Terms and Privacy Policy you accepted, age confirmation, parental consent for each child profile | You |
| Subscription data | Plan, price, currency, trial dates, payment status. Card numbers are handled only by our payment provider and never reach us. | You and our payment provider |
| Technical data | Country (from your connection, to show local prices), browser type, text-size preference, security logs | Your device |
| Messages to us | Anything you write when you email us | You |
We do not collect: a child's date of birth, surname, photo, voice, video, precise location, school, contacts, or any health information. We do not use microphone or camera. We do not collect special-category data.
4. Why we use your data and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and run your account, profiles and games; save progress | Performance of contract |
| Enforce daily play-time limits and parent controls | Performance of contract; legitimate interest in child wellbeing |
| Process children's data | Consent of the parent or legal guardian (Art. 8) |
| Free trial, subscriptions, billing, local prices | Performance of contract |
| Keep invoices and tax records | Legal obligation |
| Suggest suitable games and adjust difficulty | Performance of contract |
| Security, preventing abuse and fraud, fixing errors | Legitimate interest |
| Service emails (confirmation, password reset, important changes) | Performance of contract |
| Optional news or offers (adults only, only if you opt in) | Consent — withdraw at any time |
5. Automated tools
We use automated tools behind the scenes to help create, sort and quality-check questions, detect duplicates, and suggest which games or difficulty level may suit a profile. These tools do not make decisions that have legal or similarly significant effects on anyone (GDPR Art. 22). There is no chatbot, voice assistant or avatar that talks to players, and children's play data is never used to train external AI models.
6. No advertising, no selling, no profiling for marketing
MINDIDIA shows no advertising, contains no advertising trackers, and never sells, rents or trades personal data. We do not build marketing profiles of children.
7. Who we share data with
Only with service providers ("processors") that help us run MINDIDIA, under written data-processing agreements, and only as far as needed:
- Hosting, database and sign-in infrastructure.
- Email delivery for account emails.
- Payment processing (card payments, fraud checks, invoices).
- Google, only if you choose "Continue with Google" to sign in.
We may disclose data if required by law, a court order, or to protect the safety of a child or the public. If MINDIDIA is ever sold or merged, data would only transfer under this policy and you would be told first.
8. International transfers
Some providers may process data outside the European Economic Area. When that happens we rely on an EU adequacy decision or the European Commission's Standard Contractual Clauses, plus extra safeguards where needed.
9. How long we keep data
| Data | Kept for |
|---|---|
| Account and profile data | While the account is open; deleted within 30 days after account deletion |
| Child profile and its play history | Deleted as soon as the parent removes the profile |
| Daily play-time counters | Up to 12 months, for parent reports |
| Accounts inactive for 24 months | We email a warning, then delete |
| Invoices and payment records | 7 years (Dutch tax law) |
| Consent records | While the account is open, plus up to 5 years to prove consent |
| Security logs | Up to 90 days |
10. Your rights
You (and a parent on behalf of their child) have the right to:
- Access — get a copy of your data.
- Rectification — correct wrong data (most can be changed yourself in the app).
- Erasure — have your account or a child profile deleted.
- Restriction and objection — limit or object to certain use.
- Portability — receive your data in a common machine-readable format.
- Withdraw consent at any time, including parental consent (the child profile is then deleted).
- Complain to a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also contact the authority in your own country.
Email drmarfani5@gmail.com from the address on the account. We reply within one month (extendable by two months for complex requests, in which case we tell you). We may ask you to confirm your identity. Exercising your rights is free.
California and other US states
We do not sell or "share" personal information for cross-context behavioural advertising. US residents may request to know, correct or delete their information using the same email address, and will not be treated differently for doing so.
11. Security
- Encrypted connections (HTTPS) everywhere.
- Passwords and parent PINs stored only as one-way hashes; PIN locks after repeated wrong attempts.
- Access rules checked on our servers for every request, so one family can never see another family's data.
- Play-time limits and scores enforced on our servers, not only in the browser.
- Staff access limited to what is needed, and logged.
If a data breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and inform affected account holders without undue delay.
12. Cookies and local storage
We use only strictly necessary storage (sign-in session, preferences). No advertising or tracking cookies. See our Cookie Policy.
13. Changes to this policy
If we make important changes we will notify account holders by email or in the app at least 30 days before they take effect, and ask for fresh consent where the law requires it. The version and date are shown at the top of this page.
14. Contact
ASM Professional Services, the Netherlands · KVK 42137630 · VAT NL005526019B33
Email: drmarfani5@gmail.com
MINDIDIA is operated by ASM Professional Services, the Netherlands · KVK 42137630 · VAT NL005526019B33 · drmarfani5@gmail.com