cms.kids Privacy Policy
This document explains how the roles are divided between the kindergarten and the platform, what data we process ourselves, who data is shared with and what rights you have. What data about a child has been collected, and why, is disclosed by the kindergarten.
1. Who we are and how to contact us
This policy takes effect on 1 August 2026.
For questions about personal data, write to info@cms.kids.
2. Who is responsible for what: the kindergarten and us
Data about children and their families is entered into the system by the kindergarten. The kindergarten decides what information to collect, which members of staff can see it, how long to keep it and when to delete it. In GDPR terms, the kindergarten is the data controller.
We provide the kindergarten with the system and maintain it: we store the records and send out emails and notifications. We process the kindergarten’s data only on its instructions and do not use it for our own purposes.
There is one exception: for enquiries sent through the form on the cms.kids website, and for the web server’s technical logs, we are the controller ourselves.
The kindergarten determines the lawful basis for processing and obtains the necessary consents from parents itself, including consent to photography and to publishing photographs in reports. What data about a child has been collected, and why, is disclosed by the kindergarten — address such questions to it.
3. Website visitors and enquiries through the form
If you send an enquiry through the form, we store: the kindergarten’s name, your name, email address, phone number, city, number of children, the text of your message and the language of the form. The same data is also sent by email to info@cms.kids.
The web server keeps a standard access log: IP address, time, requested address and browser string. The log is capped in size: older entries are automatically pushed out by new ones.
4. Lawful bases for processing
Below are the bases for the data we control and for the technical mechanisms of the service itself. The bases for processing children's and families' data are determined by the kindergarten.
- Push notifications — the subscription is created after you allow notifications in the browser and is removed when you turn them off.
- An enquiry through the form on the website — your request prior to entering into a contract, and our legitimate interest in replying to it.
- Web server logs and rate-limiting by IP address — legitimate interest in the security and availability of the service.
- Session cookies — strictly necessary for the service to work: without them signing in is impossible.
- Loading fonts from Google's servers when pages open — legitimate interest in a consistent look of the site and the app.
5. Disclosure to third parties
Data is shared only with services the system cannot run without:
- Microsoft (Office 365) — delivery of all outgoing mail: the content of the emails, including invitations, notifications and invoices, passes through Microsoft's servers.
- Revolut Ltd — if the kindergarten has chosen payment via Revolut: the payment link carries the amount and the child's name.
- Browser push services — Google, Apple, Mozilla, depending on the parent’s browser. Notifications sent to a parent pass through them.
- Google Fonts — fonts are loaded from Google's servers; Google receives the IP address and the address of the open page.
- The kindergarten's payment page — if the kindergarten has set its own payment address. Who operates that page is the kindergarten's choice.
- The hosting provider — the system's database and files reside on its servers.
6. International data transfers
The companies listed above may process data outside the European Economic Area, including in the United States. Such transfers rely on the safeguards provided for by the GDPR: European Commission adequacy decisions and the EU standard contractual clauses.
7. Cookies
The application on the kindergarten’s subdomain sets two cookies, both strictly necessary for signing in. There are no advertising or analytics cookies, and therefore no consent banner.
- access_token — a staff session, valid for 30 days.
- parent_token — a parent's session in the family area, with the same lifetime.
The app also stores interface settings and the chosen theme in the browser. These values are not sent to the server.
Cookies are cleared by signing out or by clearing the site data in the browser — after that you have to sign in again.
8. Security
We take technical and organisational measures appropriate to the nature of the data: connections are encrypted, passwords are stored irreversibly, access is restricted by role, and the data of different kindergartens is kept separate. Photographs and attachments are served only to authenticated requests; the kindergarten’s logo and the application icons are publicly available.
Platform staff have technical access to the server and the database — it is needed for maintenance, updates and handling support requests, and is used only for that.
If we become aware of a data breach, we notify the affected kindergartens without undue delay and pass on everything we know. Notifying the supervisory authority and the parents is the kindergarten’s duty as controller.
9. Retention and deletion of data
Records are kept until the kindergarten deletes them, or until we delete them at its instruction.
Uploaded files are deleted on request to info@cms.kids.
Requests sent through the site form are kept no longer than needed to reply and discuss onboarding.
One-time links from emails are valid for 7 days.
10. Your rights and how to exercise them
If you are in the EU or the EEA, the GDPR gives you the following rights in relation to your data and your child’s data:
- to obtain access to the data and a copy of it;
- to have inaccurate or incomplete data corrected;
- to request erasure — subject to the limits described in the section on retention;
- to restrict processing or to object to it;
- to receive the data in a portable format;
- to withdraw consent — in particular, to switch off push notifications in your browser at any time;
- lodge a complaint with a data protection supervisory authority — where you live or work.
For data about a child and family, approach your kindergarten first: it is the controller and can make the changes in the system itself. If the kindergarten is unavailable, or the matter concerns data for which we are the controller (an enquiry from the website, server logs), write to info@cms.kids.
For data where we are the controller, you will receive a reply within the period set by the GDPR — one month from receipt of the request. A request concerning a kindergarten’s data is passed to the kindergarten without delay and we assist it technically; the kindergarten itself answers such a request.
We may ask you to confirm your identity, so that a child’s data is not disclosed to an outsider.
11. Changes to this policy
We may update this document. The version in force is always available on this page, and the effective date is given at the beginning.
We will notify kindergartens of material changes — those that alter the categories of data processed or the range of recipients — at the email address held in the system. The kindergarten, in turn, informs parents as data controller.