PLACEHOLDER — not legal advice, not reviewed by counsel. This involves minors’ data. Replace entirely before collecting a single form submission in production.
Privacy policy
What a lawyer needs to cover for SaharaT20, given that the subject of every record is a minor:
- What is collected, from whom. Students aged 13–17 may now create their own accounts, so information IS collected directly from teens. Under-13s are screened out by a neutral date-of-birth question (birth date not stored) and no account is created. Counsel must review teen-privacy obligations: state laws (e.g. California, and state age-appropriate-design and teen social-media laws), GDPR/UK rules for under-16s, and Korea’s PIPA for under-14s.
- Lawful basis and parental consent mechanics.
- Who sees the file: which reviewer, under what contractual confidentiality obligation.
- Retention period and deletion on request.
- Sub-processors — hosting, email, payment — named individually.
- Security measures. If you operate from Massachusetts, 201 CMR 17.00 requires a written information security programme regardless of company size.
- International transfers, and whether GDPR, UK GDPR, PIPL or India’s DPDP Act apply to any family you accept.
- Contact route for access, correction and deletion requests — publish privacy@saharat20.com here. Requests are fulfilled with
private.erase_family()plus deletion of the family’s storage folder.