Privacy
Your data stays yours.
ParentBorn privacy policy, version 1.4 dated 9 August 2026. It covers the website, account, family profile, Academy, ADDA and newsletter.
Controller
The controller is Andreea Dumitrescu, Romania. Contact: privacy@crestemparinti.ro.
Account data
We use your email address, technical account identifier, authentication provider, language, time zone and accepted document versions. You may optionally add a display name, given name, family name, country, preferences and an adult profile photo. The photo is stored privately in AWS and displayed through a temporary link; support cannot see it. Your password is managed by Amazon Cognito and is not visible to the ParentBorn team.
Family and children
The profile belongs to the adult and a child does not receive an account. You may optionally store a random identifier, non-identifying label, age band, school stage and topics selected from controlled lists. We do not request a child's real name, exact birth date, address, school, photo or medical information. Support does not see this information.
Academy and ADDA
We keep Academy progress so you can continue learning. ADDA history is off by default and is stored only after separate consent, which you may withdraw at any time. Children do not create accounts; please avoid names, addresses or other details that directly identify a child.
Newsletter
For newsletters we use your email, language, timestamp and consent version. The legal basis is consent. You may unsubscribe at any time; we do not sell or rent the list.
Purposes and bases
We process data needed for the account and requested features to provide the service; optional newsletter and ADDA-history data with consent; security data under our legitimate interest in preventing abuse; and records required to meet legal obligations.
Providers and location
Core infrastructure uses Amazon Web Services, including Cognito, Lambda, DynamoDB, Aurora and CloudWatch, in Frankfurt (eu-central-1), with restricted access. Amazon Web Services and a selected sign-in provider may process limited data outside the European Economic Area under applicable GDPR mechanisms, including adequacy decisions or standard contractual clauses. If you later choose Google or Apple sign-in, that provider processes its own data under its policy.
Retention
Web sessions expire within 30 days, transient checks within 10 minutes, and technical logs within 7–14 days. Account data, the optional profile photo and progress remain while the account is active. A removed photo is deleted from active storage. ADDA history, once enabled, will have a 90-day limit. After a verified erasure request, access is blocked immediately and the request is handled within one month; encrypted backup remnants expire with the backup cycle. Minimal consent evidence, GDPR requests and security audit records may remain for up to 3 years for compliance and legal claims.
Security
We use encryption in transit and at rest, role-based access, HttpOnly sessions, administrator MFA, minimized logs, and separation between Customer accounts and Admin Studio. No system can guarantee zero risk.
Your rights
You may request access, a copy, correction, erasure, restriction, portability or objection, and may withdraw consent without affecting earlier processing. We respond without undue delay and normally within one month. You may complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro.
Required, optional and automated decisions
Your email, technical identifier, authentication data and document versions are required for an account; without them we cannot provide access. The adult profile, photo, family profile, newsletter and ADDA history are optional as applicable. We do not use your data for solely automated decisions that produce legal or similarly significant effects, and we do not sell personal data.
Updates
Material changes receive a new version. If fresh consent is needed, we request it before the related feature continues. Paid services are not active in this version; this policy will be updated before payments are enabled.
Controller and contact
Use My data in your account or email privacy@crestemparinti.ro to ask a question or exercise your rights.
privacy@crestemparinti.ro
Complain to ANSPDCP
← Back