KUKI-KUKI.COM - PRIVACY NOTICE
Website: https://www.kuki-kuki.com
Controller: Smart Health and Science ZZP (KvK 86191748)
Address: Kerkstraat 140, 6267EG Cadier en Keer, The Netherlands
Contact: info@smarthealthandscience.nl
Effective date: 23 APRIL 2026
Last updated: 23 APRIL 2026
This Privacy Notice (this “Notice”) describes how Smart Health and Science ZZP (the “Controller”, “we”, “us”) collects, uses, stores, and discloses personal data in connection with https://www.kuki-kuki.com (the “Service”), an extracurricular online education service for children aged 6-17 operated exclusively through parent-managed accounts.
This Notice is intended to satisfy applicable transparency obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) including Article 13, as well as to reflect child-appropriate safeguards consistent with the UK Age Appropriate Design Code (the “UK Children’s Code”) and parental rights/consent mechanisms where the U.S. Children’s Online Privacy Protection Act and Rule (“COPPA”) apply.
1. Controller; Contact; DPO
1.1 Controller. The data controller for personal data processed in connection with the Service is Smart Health and Science ZZP (details above).
1.2 Privacy Contact. For privacy-related enquiries and rights requests, contact: info@smarthealthandscience.nl.
1.3 Data Protection Officer. We have not appointed a data protection officer (DPO) as of the Effective Date. If we appoint a DPO in the future, we will publish the DPO’s contact details in this Notice.
2. Scope
2.1 Who this Notice applies to. This Notice applies to:
(a) Parents/Guardians who create and manage accounts (the “Account Owners”); and
(b) Children who use the Service under a parent-managed account.
2.2 No social functionality. The Service does not provide chat, community features, user-to-user messaging, or public profiles.
3. Personal Data We Collect
We collect and process the categories of personal data described below.
3.1 Data provided by the Parent/Guardian (Account Owner)
(a) Account information: parent email address, billing address, country/region.
(b) Wallet and payment information: Parent Wallet balance, Child Wallet balances, deposit and withdrawal history, transaction identifiers, and limited payment metadata received from our payment provider. We do not seek to store full payment card numbers ourselves.
(c) Support communications: information you submit when contacting customer support.
3.2 Data relating to the Child
(a) Child profile information: child name or nickname, age (required), optional child email address (if provided), internal account identifier.
(b) Learning progress and usage: lesson selection, lesson completion status, quiz answers and results, timestamps, and progress metrics.
No child username/password requirement. We do not require a child-specific username and/or password. Access to the Child profile is controlled through the parent-managed account.
3.3 Data collected automatically
(a) Device and usage data: IP address (used for security and approximate location), device type, browser type, pages/events, and error logs.
(b) Security and anti-fraud signals: login attempts, abnormal activity indicators, and related security telemetry.
4. Purposes of Processing
We process personal data for the following purposes:
(a) Account creation and administration of parent-managed child accounts;
(b) Provision and development of extracurricular educational content (including video/audio lessons) and progress tracking;
(c) Rewards administration tied to educational activity (see Rewards Policy);
(d) Wallet, deposit, withdrawal, and payment processing;
(e) Customer support and service communications to parents;
(f) Security, fraud prevention, and child protection, including maintaining integrity and availability of the Service; and
(g) Legal compliance, including responding to lawful requests and maintaining required records.
5. Legal Bases (GDPR / UK GDPR)
Where GDPR and/or UK GDPR applies, we rely on the following lawful bases, depending on the processing activity:
5.1 Contract (Article 6(1)(b)). Processing necessary for the performance of a contract with the Parent/Guardian, including account creation, Service delivery, wallet administration, and support.
5.2 Legitimate Interests (Article 6(1)(f)). Processing necessary for our legitimate interests, including Service security, fraud prevention, and reliability/performance improvements, subject to balancing against the interests and rights of children and parents and implementing heightened safeguards.
5.3 Legal Obligation (Article 6(1)(c)). Processing necessary to comply with legal obligations (e.g., tax/accounting, recordkeeping, responding to lawful authority requests).
5.4 Consent (Article 6(1)(a)). Processing based on consent, principally in relation to non-essential cookies and similar technologies where required by EU ePrivacy and/or UK PECR rules.
6. Children and Consent Mechanics
6.1 Enhanced protection. Children merit specific protection under data protection law. Where consent is relied upon for online services offered directly to children, GDPR Article 8 establishes rules on age of digital consent (with Member State variation).
6.2 Our operating model. As a strict baseline, all children aged 6-17 must be registered via a Parent/Guardian, and the Parent/Guardian controls the account and associated settings.
7. COPPA (United States - Children Under 13)
7.1 When COPPA applies. If COPPA applies (including where the Child is under 13 in the United States), we will:
(a) provide the Parent/Guardian with direct notice of our information practices; and
(b) obtain verifiable parental consent before collecting, using, or disclosing a child’s personal information, except where a COPPA exception applies.
7.2 Verification method. Our verifiable parental consent method is a small credit-card charge (micro-charge) to confirm the consenting adult.
7.3 Material changes. Where COPPA applies, material changes to data practices previously consented to may require renewed parental notice and consent.
8. Children’s Privacy Safeguards
We implement child-appropriate safeguards consistent with the UK Children’s Code, including:
(a) High privacy by default;
(b) Data minimisation (collecting only what is necessary for learning and safety);
(c) No targeted advertising / no profiling-based advertising (we do not serve ads);
(d) No geolocation features enabled by default; and
(e) avoiding design patterns (“nudges”) that pressure children to weaken privacy settings.
9. Cookies and Similar Technologies
9.1 Necessary cookies. We use necessary cookies to operate the Service (e.g., login/session and security).
9.2 Non-essential cookies. For non-essential cookies (e.g., analytics), where required we will:
(a) present a cookie banner;
(b) provide Accept / Reject controls; and
(c) not set non-essential cookies unless you take a clear affirmative action.
9.3 Controls. Cookie details and controls are available at: Cookie Policy and [Cookie Settings link].
10. Recipients; Sharing and Disclosures
We may disclose personal data to the following categories of recipients:
10.1 Service providers (processors). Third-party providers acting as processors on our behalf (e.g., hosting, security monitoring, payment processing, email delivery to parents, and analytics where enabled and consented where required), subject to contractual obligations governing confidentiality, security, and processing instructions.
10.2 Authorities and legal disclosures. Competent authorities or other parties where required by law or where reasonably necessary to protect children, users, or the integrity and security of the Service.
11. International Transfers
We operate globally and may process personal data outside your country of residence. Where required, we implement appropriate safeguards for international transfers.
Transfer mechanism: the European Commission’s Standard Contractual Clauses (Implementing Decision 2021/914, Module 2 — controller to processor) with each non-EU/EEA processor; the EU-US Data Privacy Framework where the processor is DPF-certified; and the UK International Data Transfer Addendum to the EU SCCs (or the UK International Data Transfer Agreement) for transfers from the United Kingdom.
12. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Notice, unless a longer retention period is required or permitted by law. Our baseline retention periods are:
(a) Parent/Child account data: retained for the lifetime of the account, and then 24 months following a deletion request (to address disputes, fraud, and legal obligations).
(b) Learning progress data: retained while the account is active; deleted or aggregated within 24 months following deletion.
(c) Payment records: retained for 5 years as required by tax/accounting law.
(d) Security logs: typically retained for 365 days, longer if required to investigate abuse or fraud.
We may retain certain data for longer where necessary to establish, exercise, or defend legal claims, or to comply with legal obligations.
13. Your Rights (and Your Child’s Rights)
13.1 GDPR/UK GDPR rights. Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, objection, and data portability.
13.2 Cookies consent management. You may manage your cookie preferences as described in Section 9 and via Cookie Settings.
13.3 COPPA parental rights. Where COPPA applies, parents may have rights to review and delete a child’s personal information and to refuse further collection or use.
13.4 How to exercise rights; verification. To exercise rights, contact info@smarthealthandscience.nl. We may require verification of identity and parental authority before fulfilling child-related requests.
14. Complaints
You have the right to lodge a complaint with the supervisory authority. Our lead EU supervisory authority is the Dutch Autoriteit Persoonsgegevens (AP).
15. Security
We implement appropriate technical and organisational measures designed to protect personal data (including access controls, encryption in transit, least-privilege access, and monitoring). No system can be guaranteed to be fully secure; we continuously review and improve safeguards.
16. Online Safety Act and DSA Notes
16.1 UK Online Safety Act (OSA). The UK OSA principally applies to regulated user-to-user and regulated search services. As the Service does not provide user-to-user interaction or a platform search service of that nature, it is typically outside those core categories at present; we will reassess if features change.
16.2 DSA. The EU DSA imposes obligations on certain intermediary services and online platforms. Although the Service is not a user-generated content platform, we adopt child-safety-by-design and clear information practices consistent with EU expectations and do not use advertising or profiling-based advertising to minors.
17. Changes to this Privacy Notice
We may update this Notice from time to time. We will post the updated version on https://www.kuki-kuki.com and update the “Last updated” date.
If a change is material for COPPA purposes (i.e., changes to collection, use, or disclosure practices previously consented to), we will provide direct notice to parents and obtain renewed consent where required.
18. Country Addenda
We operate in multiple regions and may publish country-specific addenda or supplemental notices where local laws require additional disclosures, rights, or mechanisms.
Country addenda (if any) will be made available at: [Country Addenda link] and/or presented based on your location.