Privacy Policy
This policy explains how The Kids Gate handles personal data when families, children, teachers, schools and visitors use our website, mobile applications, account and enrolment portals, learning platform, dashboards and communications (together, the Services).
Privacy at a glance
A parent, guardian or authorised school adult creates and controls a child’s access. We collect the minimum information needed to provide learning, progress reporting and safe communication. The Services are ad-free for children. We do not sell personal data, use children’s data for behavioural advertising, or use identifiable children’s data to train general-purpose artificial-intelligence models.
Who we are and when this policy applies
The Kids Gate is provided by the following entities. The entity identified on your enrolment confirmation, invoice or school agreement is the primary organisation responsible for your personal data:
- PT Kids Gate Indonesia for customers and school arrangements contracted through Indonesia.
- GATE Edutech Solutions Pty Ltd (ACN 652 998 635) for Australia and other international customers, unless your order or agreement states otherwise.
These entities may share information with one another where necessary to operate the Services, support customers, meet legal obligations and maintain security. In that situation each entity handles the information under this policy and the law that applies to it.
The Australian entity is located at 1 Oxley Road, Hawthorn VIC 3122, Australia. PT Kids Gate Indonesia is located in West Jakarta, DKI Jakarta, Indonesia. The privacy contact for both entities is support@thekidsgate.com.
We handle personal data under Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP), Australia’s Privacy Act 1988 and Australian Privacy Principles where they apply, and other applicable local laws. If local law gives you stronger rights than this policy, those rights continue to apply.
Who uses the Services
- Parents and guardians create and manage family accounts and child profiles.
- Children, generally aged 5–12, use learning activities under an adult-managed profile.
- Teachers, school administrators and schools may use school-managed accounts, dashboards and communication features under a school agreement.
- Website visitors and prospective customers browse the website, submit enquiries or start enrolment.
Children must not create their own adult account. If we learn that a child has submitted personal data without the required adult or school authorisation, we will take reasonable steps to delete it.
Personal data we collect
The information we collect depends on how you use the Services. You may use a child’s nickname instead of a full name where a full name is not required.
| Category | Examples |
|---|---|
| Parent or guardian account data | Name, email address, telephone number, password or authentication information, country, province/state and city. |
| Child profile data | First name or nickname, age or grade/year level, selected subjects, school or class where relevant, avatar and settings supplied by the adult or school. |
| Teacher and school data | Name, work email, school, role, classes, staff permissions and school enquiry or agreement information. |
| Enrolment and order data | Plan, subjects, order and subscription history, coupons or referral codes, billing status, receipts and cancellation information. |
| Learning and progress data | Placement or diagnostic results; activities, lessons and quizzes completed; answers, accuracy, progress, mastery, learning gaps, achievements, tokens and rewards. |
| Messages and communications | Teacher–student and teacher–parent message content; sender, recipient, date/time, delivery or read status; approved attachments; support requests and enquiry-form content. |
| Payment records | Transaction identifier, provider, amount, currency, payment status and limited billing details. Full card, bank-account and e-wallet credentials are handled by the payment provider, not stored by us. |
| Device and usage data | IP address, browser and device type, operating system, app version, device identifiers, language/region preference, log-in events, screens or features used, diagnostics and security logs. |
| Cookie and local-storage data | Session, language, region, consent and checkout information, plus analytics data if analytics is enabled and permitted. |
We collect information directly from adults, children using an authorised profile, teachers and schools; automatically from devices and software; and from service providers such as payment processors. A school may also provide student and class information under its agreement with us.
Information we do not seek from children
Unless a feature is clearly introduced with a separate notice and appropriate consent, we do not ask children for a home address, personal telephone number, precise GPS location, government identifier, health information, biometric information, photograph, camera recording or voice recording.
Some activities play audio or invite a child to practise speaking aloud. The current service does not need to store the child’s voice to provide those activities. If an optional speech-recognition feature is introduced, we will explain whether audio is sent or stored and obtain any consent required before activation.
Why we use personal data
- Create and administer accounts, child profiles, classes, enrolments, subscriptions and access permissions.
- Deliver lessons, save progress, assess level, personalise the learning pathway and show reports to authorised adults.
- Provide safe teacher–student and teacher–parent messaging where the feature is enabled.
- Process transactions through Midtrans or Stripe, confirm payments, issue receipts and manage renewals or expiry.
- Send account, security, billing, learning-progress and support communications.
- Operate rewards and in-app achievements and prevent abuse of those features.
- Maintain, troubleshoot, secure and improve the Services, including through aggregated or de-identified analysis.
- Comply with legal, tax, accounting, safeguarding, dispute-resolution and regulatory obligations.
Adaptive learning and artificial intelligence
The Services use automated systems to analyse learning information such as answers, accuracy, completion and progress. The system uses that information to recommend an appropriate lesson, topic or level and to identify areas that may need more practice.
- The personalisation is used to support education, not to make legal, disciplinary, admissions, employment, credit or other similarly significant decisions about a child.
- Parents and authorised teachers can review progress and contact us if a recommendation appears wrong.
- We do not use identifiable children’s personal data to train general-purpose AI models or to build advertising profiles.
- We use de-identified or aggregated information where practicable when evaluating content and system performance.
Legal grounds for processing
Where the law requires a legal ground, we rely on one or more of the following:
- Consent, including consent or authorisation from a parent, guardian or school where permitted for a child’s data and consent for optional marketing or analytics.
- Performance of a contract, to provide the Services, account, enrolment, learning and support requested.
- Legal obligations, including financial records, consumer protection, safeguarding, regulatory requests and data-breach obligations.
- Legitimate interests, where permitted, to secure and improve the Services, prevent fraud, communicate with customers and operate the business in a way that does not override individual rights.
Children’s privacy and adult control
A parent or legal guardian normally creates a family account and provides the child’s profile information. For a school-managed service, the school confirms that it has the authority and notices or consents required to provide student information and enable the child’s use.
Where United States children’s privacy law applies, we provide direct notice and obtain verifiable parental consent before collecting personal information from a child, except where a legal exception applies. The verification method is described during sign-up. Parents may consent to internal use while declining optional disclosure that is not integral to the Service.
A parent or guardian may ask to review, correct or delete their child’s information, stop further collection, withdraw consent or close the profile. A school-managed account may require coordination with the school so that records are handled consistently with the school agreement and applicable education law.
Children are not advertising audiences
We do not show third-party behavioural advertising inside the child learning experience, sell children’s personal data, or allow unrelated third parties to contact children through the Services.
Teacher, school and messaging features
Messaging is available only when enabled for the relevant family or school account. Its purpose is educational and administrative communication between teachers and students, and between teachers and parents or guardians.
- A child cannot use the feature for open public chat or unrestricted child-to-child messaging.
- Parents, guardians and/or authorised school administrators may be able to view or obtain messages connected with the child, depending on the account type and school agreement.
- We may use automated filters and authorised human review to investigate reported content, protect users, enforce acceptable-use rules, meet safeguarding obligations and respond to legal requests.
- Users should not send health records, government identifiers, financial details, intimate images or other sensitive information through chat.
- Message notifications may be sent to the relevant adult, teacher or authorised student device according to account settings.
For school-managed accounts, the school generally decides why and how student data is used for education and acts as the data controller or equivalent decision-maker; The Kids Gate generally acts as its service provider or processor. The school agreement may allocate these roles differently where the law requires.
When we disclose personal data
We do not sell personal data or disclose it for cross-context behavioural advertising. We disclose only what is reasonably necessary to the following recipients:
| Recipient | Purpose and information involved |
|---|---|
| PT Kids Gate Indonesia and GATE Edutech Solutions Pty Ltd | Group operations, customer support, administration, security and compliance, subject to this policy. |
| Midtrans | Payments for Indonesian customers. Midtrans receives payment and transaction information under its own privacy notice. |
| Stripe | International card and supported payment processing, fraud prevention and transaction administration under Stripe’s privacy notice. |
| Amazon Web Services (AWS) | Cloud hosting, storage, databases, backups, security and content delivery for the Services. |
| Learning-platform technology | Moodle-based learning management and our Python services process profile, enrolment, activity and progress information. Where we self-host the software, it is not a separate recipient. |
| Authorised schools and teachers | Student profile, class, subject, learning, progress and message information needed for the enabled school service. |
| Email, support and notification providers | Parent/teacher contact details and message content needed to send account, service, support and safety communications. |
| Google services, if enabled | Website analytics through Google Tag Manager/Analytics only where permitted; the privacy-enhanced YouTube player loads after a visitor chooses to play a video. Child profile identifiers are not intentionally sent for website analytics. |
| Apple and Google app stores | App distribution, installation, device services and store purchases handled under the relevant store’s terms. |
| Advisers, authorities and transaction parties | Legal, audit, insurance, regulatory, law-enforcement, corporate transaction or safety purposes where permitted or required. |
Provider notices: Midtrans • Stripe • Google
International transfers
The Services support customers in more than one country. Personal data may be accessed, stored or processed in Australia, Indonesia, the United States and other countries where our contracted providers operate. Payment data may also be processed in the country of the payment provider or financial institution.
Before a restricted cross-border disclosure, we use measures required by the applicable law. These may include assessing the recipient’s protection, contractual data-protection terms, limiting the data transferred, security controls, recognised transfer mechanisms and consent where consent is legally appropriate. We remain accountable for our own disclosures as required by law.
Cookies, analytics and similar technologies
The website and applications use cookies, local storage and similar technologies to keep sessions secure, remember language and region, maintain preferences, support checkout and understand performance. Analytics tools are used only when enabled and permitted; where consent is required, non-essential analytics should not load until consent is given.
You can delete or block cookies through your browser and can change consent preferences where a consent control is displayed. Blocking essential cookies may prevent sign-in, checkout or preference features from working. The website’s separate Cookie Policy gives more detail about current technologies and retention periods.
Retention and deletion
We keep personal data only for as long as reasonably necessary for the purposes described above, considering the child’s best interests, account status, legal obligations, disputes, security and the school agreement. Our general approach is:
| Information | Typical retention approach |
|---|---|
| Child profile and learning data | While the profile is active; then deleted or de-identified after account closure, a valid deletion request or a defined period of inactivity, unless retention is required by law or a school agreement. |
| Messages | For the period needed for educational continuity, safeguarding, complaints and the applicable family or school account; then deleted or de-identified under our retention schedule. |
| Parent, teacher and school account data | For the account or agreement and a reasonable period afterwards for support, reactivation, disputes and compliance. |
| Payment, tax and accounting records | Generally seven years, or the longer or shorter period required by the relevant law. |
| Support and enquiry records | For as long as needed to resolve the request and manage reasonable follow-up, complaints or legal claims. |
| Security and technical logs | For a limited period based on security, fraud prevention and troubleshooting needs. |
| Backups | Deleted information may remain in protected backups until overwritten through the normal backup cycle; it is not restored except for recovery or security purposes. |
We periodically review information and delete or de-identify it when it is no longer needed. Deletion may not remove data that we must retain by law or information that has been irreversibly de-identified.
Security and data breaches
We use technical and organisational safeguards appropriate to the type of data and risk. These include role-based access controls, authentication, encryption in transit, encryption or equivalent protection where supported, secure cloud infrastructure, backups, logging, staff and contractor confidentiality, software maintenance and due diligence for service providers. Payment credentials are handled by payment providers designed to meet payment-industry security requirements.
No system is completely secure. If we identify a data breach, we will contain and assess it, take steps to reduce harm, document our response and notify affected people and regulators when required. Under Australia’s Notifiable Data Breaches scheme, notification is required for eligible breaches likely to cause serious harm; under Indonesia’s UU PDP and other applicable laws, different notification rules and timeframes may apply.
Your rights and choices
Depending on your location and subject to legal exceptions, you may have the right to:
- know whether and how we process personal data and obtain access to it;
- correct inaccurate or incomplete data;
- request deletion or destruction of data that is no longer required;
- withdraw consent, without affecting processing already carried out lawfully;
- object to or restrict certain processing, including certain automated processing;
- receive eligible data in a portable format;
- opt out of marketing and, where applicable, sale, sharing or targeted advertising (which we do not use for children); and
- make a complaint and seek review by the relevant regulator.
A parent or guardian may exercise rights for their child. For a school-managed account, you may contact the school first because the school controls some student records; you may also contact us and we will coordinate as required. We may verify identity and authority before disclosing or changing information.
Send a request to support@thekidsgate.com with the subject “Privacy Request”. We will respond within the time required by applicable law.
Marketing and service communications
We send operational messages needed to provide the account, learning, payment, security and support services. These are not marketing. We send promotional communications to adults only where we have the consent or other permission required by law. Every promotional email provides a way to unsubscribe. We do not send direct marketing to children.
Complaints
If you believe we have mishandled personal data, email support@thekidsgate.com with the subject “Privacy Complaint” and describe the issue. We will acknowledge the complaint, investigate it fairly, request further information if needed and explain our response. We aim to respond within 30 days, subject to the complexity of the matter and any shorter legal deadline.
If an Australian privacy complaint is not resolved, you may contact the Office of the Australian Information Commissioner (OAIC). In Indonesia, you may complain to the competent personal-data-protection authority or other authority empowered under the UU PDP. Other local regulators may also be available.
Third-party links and services
The Services may link to third-party websites, payment pages, app stores or media. Those services operate under their own privacy notices. Review those notices before providing information directly to the third party.
Changes to this policy
We may update this policy when our Services, providers or legal obligations change. The updated policy will show a new effective date. For a material change, we will provide additional notice and obtain new consent where required, including where a new use of children’s data requires it.
Contact us
| Organisation | Contact details |
|---|---|
| PT Kids Gate Indonesia | West Jakarta, DKI Jakarta, Indonesia Privacy and support: support@thekidsgate.com |
| GATE Edutech Solutions Pty Ltd | ACN 652 998 635 1 Oxley Road, Hawthorn VIC 3122, Australia Privacy and support: support@thekidsgate.com |
Please include your account email, your country, the child or school profile concerned (if relevant), and enough detail for us to understand the request. Do not email passwords or full payment-card details.