Privacy Policy

Last updated: 03 Jun 2020

We have presented this Privacy Notice to allow our users quick and easy access to the relevant areas of the Policy that they require, if you have any questions or queries please contact a member of the team: info@yakyak.digital

About YakYaK & Kids Know Best

YakYaK is an application designed for use with Android and iOS devices.

The YakYaK brand is owned and managed exclusively by Kids Know Best Limited, a company registered in England and Wales, Company Number: 10288812 with registered offices at: 25 Spelman Street, London E1 5LQ, United Kingdom.

How To Contact Us & Our Data Protection Officer (DPO)

Kids Know Best are the Data Controller for all personal information that we process unless stated otherwise.

Kids Know Best is registered with the Information Commissioner’s Office – registration number: ZA534781.

Entry details can be found here: https://ico.org.uk/ESDWebPages/Entry/ZA534781

You can contact our Data Protection Officer directly using the following methods:

Email: info@kidsknowbest.co.uk

Post:

Data Protection Officer
Kids Know Best Ltd
25 Spelman Street
London E1 5LQ, United Kingdom.

We have conducted a Data Protection Impact Assessment on all our processing activities to ensure that individual rights of any individual are never knowingly infringed.

Our Legal Basis for Processing

Under the General Data Protection Regulations (GDPR) there are various legal bases for the processing of personal data.

The legal basis that Kids Know Best relies on for users of the YakYaK application is always Consent which is requested from the parent or guardian to allow their child or dependent to access YakYaK.

This means that the Users of the YakYaK application, who may be under the age of 13, have consented for their details to be Processed by Kids Know Best via clear and specific opt-in of their parent or guardian.

Consent is always used for marketing communications from which you are able to withdraw at any time if you are subscribed. Marketing messages will only be sent via email to the Parent or Guardian whose email address is used to register the account.

Push notifications may be used where consent is provided specifically for them to be shown via the device used.

Privacy by Design

YakYaK has been developed using a Privacy by Design approach, this means that Privacy of our users and Information Security has been at the heart of the YakYaK application through all areas of development and we do not request, hold nor process any data that is not essential to the delivery of the core service.

Different Ways in Which We Collect Personal Data

Personal Data means any information relating to natural persons who:

can be identified or who are identifiable, directly from the information in question; or

who can be indirectly identified from that information in combination with other information.

Personal Data is received by the YakYaK application only by clear and affirmative input for the intended users by the parent or guardian.

These details are re-confirmed by use of a verification email that is sent to the parent or guardian.

What Information do we Process?

In order to carry out our day-to-day operations and offer the benefits to YakYaK users we obtain information from the parent or guardian of the child user.

In order to access the YakYaK application firstly YakYaK is downloaded from the relevant App store dependent on the user’s device.

Once the YakYaK application is opened on the device the following information is retained by YakYaK to create a unique profile prior to any registration process.

The above information obtained allows the User to engage with the YakYaK application and learn more about the application before committing to registration.

‘Full Account’ Data Requirements

In order to access all features available in YakYaK the user is required to create an account. When an account is created the following data is collected and retained.

Data Category (What data is obtained?): Email address.
Data Subject (whose data is this?): Parent or Guardian.
Description of the Data collected: Unique email of the parent or guardian.
How is the data captured and how is it stored?: Provided by parent or guardian within the application, application, Encrypted and stored securely in the UK on YakYaK server.
Security if the data is transmitted to YakYak servers: Encrypted (AES) within the application and application and secured at rest. Encryption key held by DPO.

Data Category (What data is obtained?): Password.
Data Subject (whose data is this?): Parent or Guardian.
Description of the Data collected: Unique password to be used to access YakYaK account.
How is the data captured and how is it stored? Provided by parent or guardian within the application, Encrypted and stored securely.
Security if the data is transmitted to YakYak servers: Encrypted (AES) within the application and secured at rest. Encryption key held by DPO.

Data Category (What data is obtained?): Username.
Data Subject (whose data is this?): User of the YakYaK application (data field completed by Parent or Guardian).
Description of the Data collected: Parent / guardian completes a username using the random word generator.
How is the data captured and how is it stored? Provided by parent or guardian within the application, Encrypted and stored securely.
Security if the data is transmitted to YakYak servers: Encrypted (AES) within the application and secured at rest. Encryption key held by DPO.

Data Category (What data is obtained?): Marketing Consent..
Data Subject (whose data is this?): Parent or Guardian.
Description of the Data collected: Opt-in flag for marketing emails.
How is the data captured and how is it stored? Provided by parent or guardian within the application, Encrypted and stored securely.
Security if the data is transmitted to YakYak servers: Encrypted (AES) within the application and secured at rest. Encryption key held by DPO.

How We Process Your Personal Information

We will only use your personal data when the law allows us and only for the following purposes:

To the extent that is required for us to carry out the full services on behalf of our users based on the Agreement we have with them.

Where we need to comply with our legal and/or regulatory obligations

YakYaK has been developed with your Privacy in mind and we have taken appropriate technical and organisational measures to protect the confidentiality and integrity of your data during storage, transit and all processing activities.

Sharing Personal Information with Third Parties

We go through a stringent due diligence process when we select any third parties to work with to ensure their ethics, policies and processes are in line with our own.

These Third Parties include:

Type of Service: Email Service Provider (ESP) – Service Notifications.
Reason why we should share data with them: So that we can send service notifications that are critical to the operation of the YakYaK service.
Our selected partner, their Web address and Privacy Policy: Amazon Web Services – Simple Email Service https://aws.amazon.com/ses/
How we manage your data with them: Data is retained in accordance with our Data Retention Policy.

Type of Service: Email Service Provider (ESP) – Marketing.
Reason why we should share data with them: So that we can send marketing emails (where explicit consent exists).
Our selected partner, their Web address and Privacy Policy:
HubSpot https://www.hubspot.com/
MailChimp https://mailchimp.com
How we manage your data with them: Data is retained in accordance with our Data Retention Policy.

Type of Service: Hosting Providers.
Reason why we should share data with them: So that we can provide our services to Customers and that data can be held within a secure data centre.
Our selected partner, their Web address and Privacy Policy: Amazon Web Services https://aws.amazon.com/privacy/
How we manage your data with them: Data is retained in accordance with our Data Retention Policy.

Type of Service: Application analytics.
Reason why we should share data with them: So that we can improve the services that we are offering to our Users by understanding their behaviour in aggregate when using YakYaK.

Our selected partners, their Web address and Privacy Policy:
Mixpanel
https://mixpanel.com/
https://mixpanel.com/legal/privacy-policy/

Google Analytics
https://analytics.google.com/analytics/web/#/
https://policies.google.com/privacy

Apple Analytics
https://developer.apple.com/app-store-connect/analytics/
https://www.apple.com/legal/privacy/en-ww/

How we manage your data with them: Non personally-identifiable information is shared with Mixpanel, Google and Apple. This anonymous data is retained indefinitely.

Type of Service: Advertising attribution and analytics.

Reason why we should share data with them: So that we can attribute app installations to the relevant advertising campaign and improve their performance.

Our selected partner, their Web address and Privacy Policy:
Facebook
https://www.facebook.com/about/privacy

How we manage your data with them: Non personally-identifiable information is shared with Facebook. This anonymous data is retained indefinitely.

We will only access your personal information where it is required to supply the services and we will always remain in control of any data that is being processed.

We will only disclose your information to parties not listed in this Privacy Policy in the following circumstances:

We have a legal obligation to do so, for example for law enforcement or regulatory bodies

To protect our interests and help us prevent fraud, detect crime or investigate any form of malicious or other activity which may be against our terms of service.

Where you give us specific permission to do so by providing consent

Your Rights

Under the GDPR you have rights we need to make you aware of, these are listed below.

Please contact our Data Protection Officer to discuss any of these rights and how we may assist: info@kidsknowbest.co.uk

Your right of access:

You have the right to ask us for copies of your personal information

Your right to rectification:

You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete

Your right to erasure:

You have the right to ask us to erase your personal information in certain circumstances

Your right to restriction of processing:

You have the right to ask us to restrict the processing of your information in certain circumstances

Your right to data portability:

This only applies to information you have given us. You have the right to ask that we transfer the information you gave us from one organisation to another, or give it to you.

Data Retention and Erasure Policy

We will only retain information for as long as required to deliver the services to our Customers safely and securely.

Our data retention policy is based on specific data types that we process:

Type of information collected & stored: Individuals who have completed the Short account process but never accrued any points.

Retention period (maximum): 4 weeks

Type of information collected & stored: Individuals who have completed the Full account process and have clicked the confirmation email but never accrued any points.

Retention period (maximum): 12 months

Type of information collected & stored: Full account registered users who have not logged in (engaged) with the application or any marketing collateral (emails etc).

Retention period (maximum): 12 months

In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

When the purposes we collected the data for have ended we will retain and securely destroy your personal information in accordance with applicable laws and regulations.

Changes to our Privacy Policy

This Privacy Policy goes through regular reviews and is updated where appropriate; the revised version will be visible on our websites.

Contact Us

Email: info@kidsknowbest.co.uk

Post:

Data Protection Officer
Kids Know Best Ltd
25 Spelman Street
London E1 5LQ
United Kingdom.