App privacy policy
Effective from [TO BE ADDED: date]
1. Who is responsible for your data
The Edko app is operated by dark-solutions s. r. o., Levanduľová 641/20, 900 43 Kalinkovo, Slovakia, company ID (IČO) 54269181, registered in the Commercial Register of the Municipal Court Bratislava III, section Sro, file No. 157962/B, email ahoj@edko.digital (“Edko” or “we”).
Two parties are responsible for your data, depending on which data it is:
- Data in the kindergarten (the child, reports, absences, announcements, classes, applications) is processed by Edko for your kindergarten. The kindergarten is the controller, Edko is its processor and follows its instructions and the data processing agreement. Please send questions and requests about this data directly to the kindergarten. If you send them to us, we will pass them on to the kindergarten.
- Your user account (sign-in email, password, sign-ins, the device for notifications, the app language) is managed by Edko as the controller, because one account can belong to several kindergartens (for example when you have children in two kindergartens).
2. How an account is created
You cannot sign up for Edko on your own. An account is created only when the kindergarten invites you by email and you accept the invitation. The invitation is valid for 14 days. If you have children in several kindergartens, the invitations are joined into one account by email address.
3. What data we process and why
3.1 Your account (controller: Edko)
- Data: email, name, password (stored only in encrypted form, nobody can see it), the time the account was created, and for Edko staff also the second authentication factor.
- Purpose: signing in, resetting the password, protecting the account.
- Legal basis: performance of the contract for using the app (Art. 6(1)(b) GDPR); for a parent who is not a party to the contract, the legitimate interest of the kindergarten and Edko in delivering information about the child (Art. 6(1)(f) GDPR) [TO BE VERIFIED: lawyer].
- Password reset: to limit misuse, we remember for 24 hours to which address and when a request was made.
- App language: if your kindergarten also offers English, we save the language you chose in the app (Slovak or English; at your first sign-in according to your phone’s language, you can change it in My account). We use it to show you the app, to send you notifications and emails and to pick the kindergarten’s texts. Only you can see your language: neither the kindergarten nor Edko staff can see it, and it is not written to the change history. In the demo, the language is saved on the phone only. Purpose and legal basis as for the account (an app setting, Art. 6(1)(b) GDPR) [TO BE VERIFIED: lawyer].
3.2 Notifications on your phone (push)
- Data: the device identifier for notifications (push token), the type of device (iOS or Android), when the device was last in contact.
- Purpose: to let you know that a report is ready, an announcement has arrived or there is an invitation to a kindergarten event (also its change, cancellation and a reminder the day before), or that the kindergarten has published or corrected the lunch menu (the menu’s period, without its content), or has added a document or a new version of it, if it chose to notify parents (the document’s title, without its content); to let a teacher know that a deadline is approaching.
- Content of a notification: a short text, for example the name of the report and the child’s first name, or the title and the beginning of an announcement (at most 140 characters). You see the whole report only in the app.
- Notifications are delivered by the Expo service and then by Apple (iOS) or Google (Android). These services can see the content of the notification.
- When you sign out of the app, we delete the token. We also delete it when the service tells us that the device no longer accepts notifications. We keep at most 10 devices per account. If another person signs in on the same phone, only they receive notifications on it from then on.
- You can turn notifications off at any time in your phone’s settings.
3.3 Data in the kindergarten (controller: the kindergarten, processor: Edko)
- Child: first name, surname, class.
- Parent: name, email, which child you belong to.
- The “EN” badge: if the kindergarten offers English and at least one parent of a child uses the app in English, the kindergarten admin and the teacher who teaches the child’s class see an “EN” badge with the child, so that they write to the child’s parents in English. The badge does not show which parent it is, and other parents cannot see it. The badge is not stored anywhere, it is worked out from the parent’s language (section 3.1).
- Texts in English: the English texts of reports, announcements, events, the lunch menu and documents are written by the kindergarten itself (the teacher writes text answers in English for a child with the “EN” badge). Edko does not machine-translate anything and does not send the kindergarten’s texts to any translation service. Where an English text is missing, we show the Slovak one.
- Staff: name, email, role, classes and covering, permission to send announcements.
- Reports: the teacher’s answers about the child’s day (for example lunch, nap, mood), who filled in the report and when. A parent sees a report only after its deadline. A report that is missing a required answer is not sent to parents. Edko records only the day on which you first opened a report in the app (not the time). The kindergarten only sees whether you opened the report, and only from the next day.
- Absences: the day of the child’s absence, an optional note, who reported the absence.
- Announcements: the title and text of the announcement, who it was for and when you opened it.
- Kindergarten events: the title, the day and time, the place and description of the event, which classes it is for, who created it and to whom the invitation was sent.
- Lunch menu: the period, the text of the menu (also by days with allergen numbers), photos or a PDF of the menu, or a link to the canteen’s website, and who published the menu. Photos are redrawn in the browser before they are uploaded, so no location or device data is saved. The menu is seen by parents and kindergarten staff; files are opened only through temporary links. For a link to the canteen’s website, the app shows you its address before opening it: the page is not managed by Edko and its operator’s policy applies to it.
- Kindergarten documents: for example the school rules or the activity plan as a PDF or a photo, the title, the category, which classes the document is for, its validity, the file size, who uploaded or changed the document and when. They are uploaded by the kindergarten admin and by a teacher with permission to send announcements (only for the classes she teaches). A photo is made smaller before uploading and saved without metadata, that is without location and device data. A document is seen by the parents of children in the classes it is for and by kindergarten staff; the file is opened only through short-lived links that stop working after a while. What happens with a document on your phone is described in section 3.10.
- Who can pick up a child: the person’s first and last name, their relation to the child (for example grandmother), an optional note (for example “only on Fridays”), until when they are valid and who added or changed them and when. People are added by the kindergarten admin or by the child’s parent in the app; we store them without a photo and without an ID number or address. The list is seen by the child’s parents, the admin and the teacher who teaches the child’s class that day; Edko support can see it read-only, and only when the kindergarten admin temporarily allows support access. When the list changes, the other parents of the child get a notification without the person’s name. If you add another person, please tell them the kindergarten keeps them on the list for this purpose.
- Consent for an event: for an event where the kindergarten asks for consent, we store the answer Agree or Disagree for the child, who gave it (a parent or the kindergarten) and when. An answer in the app is not a signature; it is a record a parent made in their signed-in account. Details are in section 3.14.
- The purpose and legal basis are set by the kindergarten; the kindergarten will give you this information.
3.4 Email for parents without the app
If you do not have notifications from the app turned on on any device, we send you the report by email with its full content, so that you get it even without the app. Once you install the app and allow notifications, report emails stop. Each report arrives separately at the time of its deadline. We also send invitations, password resets and announcements to parents without the app by email. Emails come in the language of your account if the kindergarten offers it, otherwise in Slovak.
An invitation to a kindergarten event (for example a show or a photo day) is sent by email only to parents without
the app; with the app you get a notification and add the event to your calendar in the app. The email contains the
title, the date and time, the place and the description of the event, an attachment with a calendar invitation (an
.ics file) and links for adding it to Google and Outlook calendars. You open them in your own calendar, Edko does not
write anything there. If the invitation came to you by email, you also get changes of the day, time or place and the
cancellation of the event by email, even if you install the app in the meantime. The reminder the day before an event
is sent only as a notification in the app.
The lunch menu is sent by email only to parents without the app, when the kindergarten publishes it or corrects it with a notification. The email contains the text of the menu, photos of the menu directly in the email, for a PDF a link to download it (valid while we keep the menu) and for a link to the canteen’s website a button with its address.
Kindergarten documents are not sent by email. A parent with the app finds them in the Documents tab.
3.5 History of changes and system events
The app keeps a history of changes in each kindergarten, so that the kindergarten can show who worked with the data.
- Data: the name and email of the user who made the change, the time of the change and the changed data (the original and the new value); for staff also the time of signing in to the app. Viewing data is not recorded in the history (not even opening an announcement or a report).
- The app also records what it did itself (for example sent a notification or an email), without the content of the messages and without email addresses.
- Purpose: security and being able to show changes, for example who reported a child’s absence or edited a report and when.
- Who sees it: the kindergarten admin. Edko staff only see who changed which kind of record and when, not the values, the content of reports or the names of children.
- Retention: records of changes 2 years, system events 1 year, then they are deleted automatically. Nobody can edit or delete a record.
- If the kindergarten deletes a child, the child’s data in the change history remains for 2 years. At your request for erasure, we replace it with the text “deleted”, and only the record of who made the change and when remains.
3.6 Edko support access
Edko staff do not look into a kindergarten’s data. The exception is when the kindergarten admin temporarily allows support access themselves (for at most 7 days, read only, can be withdrawn at any time). Every such access is recorded in the kindergarten’s change history.
3.7 Error reports from the app
When the app, the admin web or the server runs into an error, a technical error report is sent to the Sentry service
in the EU (de.sentry.io). Error reports are wired into Edko, but they are turned on only by setting the Sentry access
key at deployment; without it, nothing is sent. They are used only to fix errors.
- An error in the code of the app, the admin web or the server (JavaScript): the type of error, a shortened error text, the place in the code where it happened, the app version, the type of device and system, the browser and the page or screen without the address parameters. Before sending, email addresses, sign-in tokens, the content of requests to and responses from the server, headers, cookies, user data and values from the database are removed from the report (the server sends only the database error code).
- A crash in the native part of the app (Android, iOS) is reported by the native Sentry component, usually at the next start of the app. It does not pass through this filter, so it contains only what the native component collects: the device model, the system and app versions, the technical state of the device (for example free memory) and the place of the crash in the native code. It does not attach a screenshot, the content of the screen or the app’s memory. [TO BE VERIFIED once turned on: the content of a native report in Sentry]
Error reports do not contain the content of reports, announcements or data about children and do not send user
data or the IP address (sendDefaultPii: false; storing the IP address is also turned off in the Sentry project
settings). Legal basis: our legitimate interest in a working and secure app (Art. 6(1)(f) GDPR). We keep error reports
in Sentry for at most 90 days.
3.8 Kindergarten applications
If your kindergarten uses the applications module, you fill in the application on the web without an account. The controller of this data is the kindergarten, Edko processes it as a processor and stores it in the EU. You receive only an email confirming receipt, without the content of the application. Applications and attachments are seen only by the kindergarten admins. Edko does not delete applications automatically; the kindergarten decides how long they are kept. To protect the form against misuse, we remember a fingerprint (not the address itself) of the IP address and the email for 7 days. When you submit the application, we also check with Cloudflare Turnstile that a person is filling it in; the service processes technical browser data, does not use tracking cookies, and Edko stores nothing from it. Our legal basis is our legitimate interest in protecting the form against misuse.
3.9 Calendar on your phone
You can add a kindergarten event to the calendar on your phone with one tap in the app (as a parent and as a teacher). Only then does the app ask for permission to access the calendar. On an iPhone this is full access to the calendar, because the app has to find the entry it added again, to update it when the event changes and delete it when it is cancelled.
- The app writes only the events you added yourself. It does not read or change other entries in your calendar.
- The app loads the list of calendars (name and account) only on the phone, so that you can choose where to add the event.
- Which calendar entry belongs to which event is remembered by the app only on the phone. Nothing from your calendar is sent to us or to the kindergarten. When you delete your account, this list is deleted from the phone, the entries in your calendar remain.
- The calendar entry is then managed by your calendar (for example synchronised with your Google or iCloud account according to your settings). The entry is written in the language the app showed the event in.
- You can withdraw the permission at any time in your phone’s settings. The app then no longer updates or deletes the entries.
3.10 Camera, photos and files on your phone
- The app asks for access to the camera or photos only from a teacher who is uploading a kindergarten document, and only when she chooses Take a photo or Choose a photo. The app uses only the photo the teacher chooses or takes; it does not read other photos. The photo is made smaller and stripped of metadata, including location, on the phone before it is sent. No sound is recorded.
- The teacher chooses a PDF in the system file picker; the app receives only the chosen file.
- When you save or share a document (Save or share), the app downloads it to its temporary storage on the phone and opens the system menu. The file stays there until the next save or share or until you sign out, then the app deletes it. A copy you save to your phone or send on is then in your own care.
- You can withdraw the permission at any time in your phone’s settings.
3.11 Dictating answers
When a teacher writes an answer in a report, the app reminds her that she can dictate it with the microphone on the phone’s keyboard. Dictation is a feature of the phone’s keyboard, not of Edko:
- The app does not record sound, does not ask for microphone access and does not receive any sound. It receives only the finished text, as when typing, and saves it as the answer in the report.
- Speech is processed by the maker of the phone or keyboard (for example Apple or Google) under their own policies and the phone’s settings; some phones process it on the device. Edko has no influence on this.
- Whether to dictate is up to the teacher. The tip under the field disappears after tapping Got it and does not show again on that phone; this choice is stored on the phone only.
3.12 Class tablet
A kindergarten can have one tablet in a class, paired with the class. The tablet has no email or password and is not a person; it signs in with a one-time code from the kindergarten admin.
- A locked tablet shows only the class name, today’s date, the number of reports still to fill and the first names with an initial of the teachers who teach the class that day. Nothing about children.
- A teacher unlocks the tablet with her PIN (4 to 6 digits). We store the PIN only as a hash; nobody can see it, neither the kindergarten admin nor Edko. It works only on her kindergarten’s tablets, never to sign in to her account. We delete the PIN when she stops being a teacher of the kindergarten.
- Once unlocked, the tablet shows only the class’s reports and the data the teacher sees for the class (absences, who can pick up a child, events, the lunch menu, documents). Every change is recorded as the teacher’s change, noting that it was made on the tablet.
- We record each unlock (as the teacher’s sign-in), when the tablet was last used and wrong PIN attempts (without the PIN) to protect the tablet from guessing. Attempts are deleted after 7 days. An unlock works only on the tablet where the teacher entered her PIN, and at most until midnight.
- The tablet locks itself after 2 minutes without use and stores no reports or photos of children. The kindergarten admin can remove it at any time; it then stops working at once.
3.13 A Year at Kindergarten (PDF of reports)
A parent can create in the app a PDF of their child’s sent reports for a school year, optionally with a list of the kindergarten’s events (name and date).
- The app creates the PDF on your phone; Edko does not store it or send it anywhere. It contains only what you see in the app: the child’s first name, the name of the kindergarten and, where known, of the class, and the sent reports. It has no teacher names, absences or reading records.
- The PDF stays in the app’s temporary storage on the phone until you create the next one or sign out (the system may also delete it sooner). A copy you save or send on is under your control.
- Creating the PDF records nothing: the reports are not marked as read.
3.14 Consent for an event
For an event, for example a trip, the kindergarten can ask for a parent’s consent and set a deadline for giving it.
- What we store: for each child the answer Agree or Disagree, who gave it (a parent of the child, or the kindergarten if it recorded it for you, for example after a phone call) and when. An answer in the app is not a signature or any other legal act; it is a record from your signed-in account. Without an answer nothing is stored.
- Who sees it: the kindergarten admin, with the name of the parent who answered; the child’s other parent, with only the parent’s first name and the date of the answer; the class teacher and the unlocked class tablet, only the answer for each child, without the parent’s name. Edko support sees it read-only, and only when the kindergarten admin temporarily allows support access.
- Changing an answer: a parent can change it until the deadline; after it only the kindergarten can record it. If the kindergarten changes the day or place of the event, the answers are cleared and the parent gives them again. If the kindergarten removes a parent from a child, that parent’s answers for events that are still open for answers are deleted and the child is without an answer again.
- Notifications: the event invitation and the notice of a change of the event include a sentence about consent and its deadline. If the kindergarten asks for consent only after the event was sent, we send parents a notification asking for consent to their phone, or an email to a parent without the app. On the deadline day at 9:00 we send a notification to a parent who has the app and has not yet answered for some child. Edko sends no email with a consent link; a parent without the app gives consent directly at the kindergarten.
3.15 Filling in reports without a connection (teachers)
So that a teacher can fill in reports even on weak Wi-Fi, the app on her phone keeps the reports it loaded last and the answers that have not been sent yet.
- What is on the phone: the child’s first and last name, the class, the report template and questions, the answers, the report status (filled in, absent), whether a parent signed the child out for that day (without the parent’s note), and the “EN” label on a child whose parent uses English. There are no parent contacts, no older reports and no overview of the day in the class. For answers the server refused, also the text of the answer and the reason.
- How long: loaded reports until the round’s deadline and at most 24 hours from the last load (the app deletes them the next time it starts after that, in any role; if the phone’s clock is set back, at once); unsent answers until they are sent, at most 7 days after the report’s deadline; answers that could not be sent, until the teacher confirms them with Got it, at most 7 days (the same for answers a newer version of the app cannot read and sets aside). Everything is also deleted on sign-out (if answers are still unsent, the app asks first) and when the account is deleted. The data belongs to the account: another teacher on the same phone does not see it and it is never sent under her account.
- Protection: the data is in the app’s storage on the phone, protected by the phone’s lock and its device encryption, if you have them turned on. Edko does not encrypt it further. We recommend protecting the phone with a code or fingerprint.
- Who decides: the server decides whether an answer is saved when it is sent (the teacher teaches the class that day, the deadline has not passed); the time on the phone is not taken into account. The class tablet does not fill in reports without a connection.
- What the server stores: for an answer it remembers who changed it last, so that on sending it can tell that another teacher changed the answer in the meantime. It is the same kind of data as who filled in the report: everyone who can see the answer can see it, but a parent cannot find out the teacher’s name from it. The server remembers the changes it accepted for 7 days as a random identifier of the change together with the teacher’s account and the time it was accepted, without the content of the change, so that sending again does not save anything twice and one account cannot send more than 5,000 changes in 24 hours.
- Signing out without a connection (any account): the sign-out takes effect on the phone at once. Until the phone is connected again, the app keeps only what is needed to finish the sign-out on the server (the leaving account’s sign-in token and the phone’s notification identifier). Once connected, before anyone signs in again, it ends the account’s sign-in on the server, turns off its notifications on this phone and deletes these data. Meanwhile the signed-out account is not signed in again on the phone.
4. Where data is stored and who we share it with
We do not sell data and do not use it for advertising. The app contains no advertising and no tools for tracking users.
| Provider | For what | Location and safeguards |
|---|---|---|
| Supabase, Inc. | database, sign-in, files (for example photos and PDFs of the lunch menu and kindergarten documents), server functions | data centre in the EU (Frankfurt); data processing agreement with standard contractual clauses |
| Resend, Inc. | sending emails | transfer to the USA based on standard contractual clauses |
| Amazon Web Services (Amazon SES) | sending emails, planned instead of Resend | EU region (Frankfurt) [TO BE VERIFIED at the switch] |
| 650 Industries, Inc. (Expo) | delivering notifications | [TO BE VERIFIED: location and safeguards] |
| Apple Inc., Google LLC | delivering the notification to the phone | transfer to the USA based on the EU-U.S. Data Privacy Framework |
| Functional Software, Inc. (Sentry) | error reports (wired in, active once the key is set at deployment) | EU region (de.sentry.io) [TO BE VERIFIED: data processing agreement and safeguards] |
| Cloudflare, Inc. | hosting the admin web, checking that a person fills in the application (Cloudflare Turnstile) | transfer to the USA based on the EU-U.S. Data Privacy Framework and standard contractual clauses |
No translation service is used: Edko does not machine-translate.
On your device, the app stores your sign-in so that you do not have to sign in every time you open it. It is deleted when you sign out. The app also remembers the last language it was shown in, so that it starts in that language.
5. How long we keep data
- Account: until you delete it. You can delete your account at any time in the app (My account → Delete account, confirmed with your password). We delete your sign-in, name, email, access to children, classes and kindergartens, the devices for notifications, the notification settings and the chosen app language. Children, reports, announcements and the change history belong to the kindergarten and remain with it, without access to your account; records in the change history are deleted after 2 years. The only admin of a kindergarten can delete their account only once the kindergarten has another admin. If the kindergarten removes you and you do not belong to any other kindergarten, the account remains without access to any kindergarten data and the app shows that you are not invited to any kindergarten. You can delete it at any time as described above.
- Data in the kindergarten: as decided by the kindergarten, at most for the duration of the kindergarten’s contract with Edko. After the contract ends, the kindergarten’s data is deleted (before that, 10 days read only and 30 days blocked). We keep an encrypted backup for 90 days, stored encrypted in the EU, and then destroy it.
- Lunch menu: we delete it together with its photos and PDF a week after the menu’s period ends, regardless of the kindergarten’s settings.
- Kindergarten documents: we delete a document with a validity period, together with its file, after the end of the school year in which its validity ended (after 31 August). A document without a validity period remains until the kindergarten deletes it or for as long as the kindergarten’s contract lasts. The kindergarten can delete it at any time.
- Who can pick up a child: we delete a person with a “valid until” date from the list the day after it; the list of a child who has left the kindergarten is deleted on the day they leave. Otherwise it stays until the kindergarten or a parent removes the person, at most for as long as the kindergarten’s contract lasts. The record of adding, changing and removing a person (name, relation, note) stays in the change history for 2 years like any other change (3.5); at a request to erase the child’s data, we replace it with the text “deleted”.
- Consent for an event: stays with the event, as the kindergarten decides, at most for as long as the kindergarten’s contract with Edko lasts; when a child’s data is erased after they leave the kindergarten, we delete it from the change record too. The record of changing an answer stays in the change history for 2 years (3.5).
- Reports on a teacher’s phone (filling in without a connection): loaded reports until the round’s deadline and at most 24 hours from the last load, unsent answers until they are sent (at most 7 days after the deadline), refused ones at most 7 days or until the teacher confirms them; deleted on sign-out and when the account is deleted (3.15). The server remembers the accepted changes for 7 days with the account and the time, without the content of the change. Data needed to finish a sign-out made without a connection, until the next connection.
- Change history: 2 years, system events: 1 year.
- Push token: until you sign out or until the device no longer accepts notifications.
- Password reset requests: 24 hours.
- Database backups: daily backups at the hosting provider, kept for 7 days and then overwritten.
6. How we protect data
Data is stored in the EU, transfers are encrypted (HTTPS). Each kindergarten sees only its own data, a parent only their own children and a teacher only the classes she teaches; this rule is enforced directly by the database. Edko staff always sign in to the operations console with a second authentication factor. Invitations contain a one-time link, which we do not store in readable form.
7. Your rights
You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability and the right to object to processing based on legitimate interest.
- Data in the kindergarten (the child, reports, absences, announcements, applications): contact the kindergarten. We help it with anything it cannot do itself, for example erasing a child’s data from the change history.
- Your account: you can delete it yourself in the app (My account → Delete account); section 5 describes what is deleted. For other requests, write to us at ahoj@edko.digital. We will reply within one month at the latest.
If you believe that we process data in breach of the law, you can lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk.
8. Children
The app is used by adults: parents and kindergarten staff. Children do not use the app and have no account in it. Data about children is entered by the kindergarten.
9. Changes to this policy
We may update this policy, for example when we add a new feature or change a service provider. The current version is always published at https://edko.digital/en/privacy (in Slovak at https://edko.digital/zasady-aplikacie) with its effective date. If the Slovak and English versions differ, the Slovak version applies [TO BE VERIFIED: lawyer]. We will let you know about a significant change in the app or by email.