GDPR & Your Rights
Last updated 5 July 2026 · Version 1.0
This notice sets out how KidzSync meets the EU General Data Protection Regulation (GDPR) and the rights you have over your personal data.
Controller & processor roles
KidzSync is the controller of your account data and the processor of data your centre records about children and families. Centres are the controllers of that content and instruct us under a data-processing agreement.
Legal bases we rely on
Contract (Art. 6(1)(b)); consent, including parental consent for children under Art. 8 (Art. 6(1)(a)); legal obligation (Art. 6(1)(c)); and legitimate interests in security and service reliability (Art. 6(1)(f)), balanced against your rights and freedoms — with particular weight given to children.
Your rights
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Erasure — ask us to delete your data (“right to be forgotten”).
- Restriction — limit how we use your data while a query is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, without affecting prior processing.
- No solely-automated decisions — we do not make decisions with legal or similarly significant effects by automated means.
How to exercise them
Email privacy@kidzsync.com (or, for content held by your centre, ask your centre). We respond within one month, extendable by two further months for complex requests, and free of charge in normal cases. We may ask you to verify your identity.
Complaints
If you're unhappy with how we handle your data, please contact our DPO at dpo@kidzsync.com first. You also have the right to lodge a complaint with your local supervisory authority — in Ireland, the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2 (dataprotection.ie).