Who this policy applies to, and our role
TendKid provides software to organizations ("Organizations," e.g. schools, childcare providers, and similar operators) to help them manage staff operations, enrolment, check-in/check-out, and related administrative tasks. This policy explains how we handle personal data across the TendKid Admin Console, TendKid Admin API, TendKid Guardian, TendKid LiveOps, and the TendKid mobile apps (Security Guard, Monitor, Driver) (together, the "Services"), and is written to comply with the UK GDPR and the EU General Data Protection Regulation.
We act as a Data Processor for personal data about children, families/guardians, and day-to-day operational records (check-in/check-out logs, grades/classes, device activation) that an Organization submits to or generates within the Services. The Organization is the Data Controller for this data and is responsible for its own legal basis and compliance obligations.
We act as a Data Controller for data about an Organization's administrative users (staff who log into the Admin Console or Guardian app) that we collect to operate, maintain, and bill for the Services — account credentials, usage data, and billing/contact details.
Where an Organization uses a gateway to connect TendKid to its external information system, some data may sync automatically (read-only within TendKid) rather than being entered directly; the source system's own privacy terms may also apply.
Data we collect
Organization administrator & staff data (TendKid as Controller)
- Name, email address, role, and login credentials
- Device and usage data (log-ins, IP address, browser/device type, in-app activity)
- Communications with our support team
Operational, child, and family data (TendKid as Processor)
- Member account data (staff, enrolled individuals)
- Child/student enrolment records, grades, and class assignments
- Family and guardian contact and relationship information
- Check-in/check-out records and timestamps
- Device activation data (e.g. QR-code-based activation records)
- Data synced automatically from an Organization's external information system via a gateway
Billing and metrics data
- Daily active children (DAC) counts and related usage metrics, used to calculate billing
- Payment and invoicing details for the Organization's account
Cookies and similar technologies
This section applies to the TendKid Admin Console, which is the only TendKid web app accessed by external users. (TendKid LiveOps is an internal-only tool and is out of scope for this policy.)
- Strictly necessary session cookies — used to keep you logged in and maintain your session while using the Admin Console. These cannot be disabled, as the Console cannot function without them.
- Analytics cookies (Firebase Analytics) — used to understand how the Admin Console is used, subject to the same consent requirement described in Section 4.
Why we process this data
| Purpose | Typical legal basis |
|---|---|
| Providing and maintaining the Services (check-in/out, enrolment, device activation) | Art. 6(1)(b) — performance of a contract with the Organization |
| Calculating billing (including DAC metrics) | Art. 6(1)(b) — contract |
| Account security, fraud prevention, service integrity | Art. 6(1)(f) — legitimate interests |
| Complying with legal or regulatory obligations | Art. 6(1)(c) — legal obligation |
| Product improvement and support | Art. 6(1)(f) — legitimate interests |
Where TendKid processes child or family data as a Processor, the Organization is responsible for establishing its own legal basis (e.g. consent from a parent/guardian) for that data, including any obligations under Article 8 GDPR relating to children's data and consent.
International data transfers
Most of our infrastructure and sub-processors operate within the EU, so most personal data does not leave the EU/EEA. Where data is transferred outside the UK or EEA — for example, to Google for Firebase Analytics and Crashlytics — we rely on an applicable adequacy mechanism such as the EU-US Data Privacy Framework, or on appropriate safeguards such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses where an adequacy mechanism does not apply.
Data retention
We retain personal data only for as long as necessary to provide the Services and meet legal, accounting, or reporting requirements. Retention periods for operational and child/family data are generally set by the Organization's instructions and contract with TendKid; Organizations can request deletion or export of their data, subject to any legal retention obligations.
Security
We use technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit, access controls, and environment separation (local development, integration, and production environments), to protect personal data against unauthorized access, loss, or misuse.
Your rights
If TendKid is the Controller for your data (see Section 1), you can contact us to request:
- Access to your personal data
- Correction of inaccurate data
- Erasure of your data ("right to be forgotten")
- Restriction of, or objection to, processing
- Data portability
- Withdrawal of consent, where processing is based on consent
You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national Data Protection Authority).
If your question relates to a child's or family's data, please contact the Organization (e.g. the school or childcare provider) directly, as they are the Data Controller for that information. We will support the Organization in responding to your request as required by law.
Contact us
Data Controller / Data Protection contact:
TendKid PTE. LTD.
68 Circular Road, #02-01, Singapore 049422
privacy@tendkid.com
Changes to this policy
We may update this Privacy Policy from time to time. We'll post the updated version here with a revised "Last updated" date, and where changes are material, we'll take reasonable steps to notify Organizations.