Back to home
Security & Privacy
Protecting our members — and unconditionally our youngest ones — is the reason Dazzle exists. This notice explains how we safeguard your data and privacy.
Draft — pending DPO & Child-Safeguarding sign-off. This document is illustrative and not yet legally binding.
Our safeguarding-first commitment
Child-safety and data protection are designed into the core of the platform, not added afterwards. We follow privacy-by-design and privacy-by-default, and the strictest applicable standard where rules overlap.
Regulatory framework
We build to the GDPR, Spain's LOPDGDD (digital-consent age 14, with stricter under-18 guardian gating by policy), the Digital Services Act, the ePrivacy rules, and age-appropriate-design principles for minors.
Data we process & why
We process only what each purpose needs (data minimisation), with a defined lawful basis per purpose — for example providing the service, keeping the community safe, and meeting legal obligations.
Minors' data
Minors are hidden by default and never surfaced to strangers. We do not profile minors. Giftedness and neurotype information is special-category-adjacent, strictly opt-in, and never used for advertising or behavioural targeting.
Consent
Consent is captured as records with purpose, policy version, and who granted it (a guardian, for minors). It is revocable at any time; withdrawing consent is recorded and never silently deleted.
Security controls
We use encryption in transit (TLS) and at rest, with column-level encryption for minors' and other sensitive fields. We build to OWASP ASVS (L2 across the app, L3 for authentication and minor-data paths), with CSP, CSRF and XSS protections, signed media URLs, and antivirus and CSAM scanning of uploads before they are served.
Data residency
Personal data — and unconditionally all minors' data — is processed and stored in the European Union, and our sub-processors must offer EU residency under a compliant data-processing agreement.
Breach notification
If a personal-data breach occurs, we notify the competent supervisory authority within 72 hours where required, and affected members without undue delay.
Child-safety reporting
We detect, preserve, and report child sexual abuse material to the competent authorities as required by law, and never tip off offenders.
Your rights
You can access, correct, export, or erase your data and withdraw consent. See Your Rights for how to exercise them.
Contact
Questions about this policy? Write to our Data Protection Officer at dpo@dazzle.example.