WORKING DRAFT

Privacy Policy

This policy is a design draft based on the profiles and features planned for Louvelle. It does not claim that those features are live. The final version must accurately describe the deployed product, responsible entity, each provider, legal basis and actual retention periods.

Prepared September 23, 2026

1. Controller and scope

The data controller would be [full legal name], at [address], with a privacy contact at [email]. These details must be visible before real information is collected.

This policy would cover the website, family accounts and child profiles on Louvelle. Terms such as personal data, controller, processor and consent will be interpreted under the law that applies where the family lives.

2. Data the service may process

The design goal is to request only the information needed to provide the service. The expected categories are listed below and must be checked against an audit of the actual product before publication:

  • Adult account: email address, display name if requested, protected sign-in credentials, language preference and report or notification settings.
  • Child profile: a family-chosen alias, technical identifier and learning level. The initial model does not need the child’s email, phone number, legal name or location.
  • Learning activity: games and topics opened, answers, correct responses, scores, session duration, difficulty, skills practised, achievements and activity dates.
  • Service and safety: minimal technical logs, application version, device information and events needed to prevent abuse, diagnose errors and protect accounts.
  • Support and consent: messages sent by the adult, preferences and a record of the notice version, language, date, method and scope of authorisation.

3. Where data comes from and why it may be used

The adult would provide account and profile information. Progress data would be generated as a profile uses activities. Some technical logs may be created automatically as the service loads and is secured.

Intended purposes include creating and protecting accounts, providing games, saving progress, adjusting difficulty if the family enables it, showing reports, answering requests, fixing errors, detecting abuse, maintaining security and meeting legal duties. Each purpose must be linked to a valid legal basis in the relevant country.

Children’s data would not be used for personalised advertising, selling profiles, enriching commercial databases or inferring health, personality, official school performance or other sensitive traits. Changing this product decision would first require a separate assessment, clear notice and any legally required permission.

5. Children’s personal data

Louvelle is designed for family use with child profiles. The adult creates profiles and controls the account. The service must not ask a child for their own contact details or allow them to post information that reveals their identity.

If we learn that a profile was created without required authorisation, we will stop processing that depends on the authorisation, contact the adult where possible and delete or pause the data if valid permission is not obtained.

Information for children must use clear, age-appropriate language. The adult must be able to understand what Louvelle learns about the profile, access those data and request correction, download or deletion.

6. Progress, personalisation and automated decisions

Exercise history may be used to show progress and adjust an activity’s difficulty for a limited educational purpose explained to the family. A profile must not become a public ranking or be used to decide school access, employment, credit, healthcare or opportunities unrelated to the service.

The intended version must not make solely automated decisions with legal or similarly significant effects on a person. Before adding a recommendation or artificial intelligence system, we will assess its inputs, errors, bias, explanation, human oversight and child-specific risks.

7. Providers, recipients and disclosures

We may appoint providers to carry out operations only under documented instructions, confidentiality obligations and security measures. Before launch, we will publish their names, roles, countries, data categories and whether they may access children’s information.

We will not sell personal data or share children’s data with advertisers for behavioural advertising. Data would only be disclosed when needed for a feature requested by the adult, to protect a child, to meet a valid legal obligation or to defend against fraud or abuse. Each exception must be checked and documented.

The actual providers and recipients are not confirmed in this repository. Using a software library or dependency does not by itself show that its company receives user data.

8. Hosting and international transfers

The hosting region and provider locations have not been selected. If personal data are stored or accessed from another country, we will identify the countries and applicable legal mechanism, such as an adequacy decision or contractual safeguards, and explain how to request information about those safeguards.

Before choosing infrastructure, we will assess data residency, support access, subprocessors, backups, encryption and transfer routes, with special attention to children’s information.

9. Retention periods

Data will not be kept indefinitely. Exact periods must be set by category before the service operates and account for purpose, legal duties, dispute resolution and removal from backups.

  • Account and profile data: until the adult closes the account, plus only the time needed to handle requests and legal duties.
  • Learning progress: while the family keeps the profile, with a clear option to delete it or start again.
  • Security logs: the minimum period needed to detect incidents, investigate abuse and protect the service.
  • Consent, payment or legal-request records: as long as applicable obligations require.

10. Family rights and controls

The adult may request access, a copy, correction, updating, deletion, objection, restriction or portability where those rights exist under applicable law. In Mexico, a clear channel must also support ARCO rights and consent withdrawal under the requirements and timelines of the law in force.

Requests may be sent to [privacy email]. We may ask for proportionate information to verify that the requester controls the account or is authorised to act for the profile, without seeking excessive proof or unnecessary documents from a child.

Withdrawing permission does not make earlier lawful processing unlawful. It may make a feature unavailable. If a request is wholly or partly refused, we will explain why and how to complain to the relevant authority.

11. Cookies and similar technologies

The experience must work without advertising technologies or behavioural tracking aimed at children. Before launch, we will inventory cookies, local storage, pixels, SDKs, external fonts and telemetry, including items embedded by providers.

Language is selected through the page URL. If the product uses cookies needed for security or sessions, they will be explained in a separate notice. Optional analytics or other non-essential measurement will remain off until the consent required by applicable law is obtained, and a simple way to withdraw will be provided.

12. Security and incident response

We will apply technical and organisational controls proportionate to risk, including least-privilege access, separation between family accounts, suitable encryption, secure credential handling, administrative access logging, provider review, backups and an incident response process.

No connected system can guarantee zero risk. If a data breach occurs, the entity will investigate, limit the impact, preserve evidence and notify families and authorities within applicable legal deadlines where required.

13. Changes to this policy

We will publish the date and version of each change. If a change materially affects purposes, providers, transfers, rights or children’s information, we will explain it in advance and obtain renewed authorisation where the law requires it.

14. Contact and complaints

For questions or requests: [privacy email], [legal entity name] and [address]. The process, timelines and competent data protection authority must be adapted to each family’s market. Current contact details have not yet been confirmed.

Privacy and support channel: to be defined before launch