Privacy policy

Version 2026-09-11 — updated on 11 September 2026.

Who is responsible, and who to talk to

The data controller is the publisher of Kalan, identified in the legal notice. The data protection officer can be reached at dpo@kalan.ci. This processing falls under Regulation (EU) 2016/679 (GDPR) and Ivorian law no. 2013-450; the competent supervisory authority in Côte d’Ivoire is ARTCI.

What we process, why, and on what basis

Every piece of data is tied to a purpose and a legal basis. We collect nothing “just in case”.

  • Adult account (email address, name, optional phone) — opening and running the account. Basis: performance of the contract (art. 6.1.b).
  • Child profile (first name, birth year, school system, year group) — personalising tutoring and picking the right curriculum. Basis: consent of the holder of parental responsibility (art. 6.1.a and 8), or the school’s mandate for a pupil enrolled by their school.
  • Tutor conversation, exercise answers, placement and tier tests — pedagogical continuity and mastery measurement. Basis: the same parental consent.
  • Progress, mastery, reviews, alerts — the parent and teacher dashboards. Basis: the same parental consent, or the contract with the school.
  • Event log and audit log (actor, action, IP address, browser agent) — security, traceability of access to a minor’s data, tutor quality. Basis: legitimate interest and security obligation (art. 6.1.f and 32).
  • Subscriptions, payments and invoices — billing and accounting. Basis: contract and legal obligation (art. 6.1.b and 6.1.c).
  • Notifications, device push subscriptions, time window — reaching you at the right moment. Basis: consent, withdrawable at any time from the settings.
  • Child-protection reports — alerting an adult when a child writes distress. Basis: vital interest and legitimate interest (art. 6.1.d and 6.1.f).
  • Website forms and newsletter — replying to a call-back request (legitimate interest); sending the newsletter only after a ticked box (consent, art. 6.1.a).

What we do not collect

No child surname, no full date of birth, no postal address, no photo, no child phone number, no location data, no health data. The child has no account: they open a session with a code chosen by their parent. No advertising tracker, no analytics and no non-essential cookie is set on this site or in the app.

How long we keep each thing

One duration per table, applied by an automatic sweep every night at 3 a.m. (Abidjan) and recorded — except for billing records, kept until their statutory deadline and never purged by the sweep. This table is an exact copy of the service configuration.

  • Tutor conversation: rolling 12 months, then deletion.
  • Audit log: 24 months, then anonymisation — the line stays (the action, the time), the author, the child concerned, the IP address, the browser agent and the path visited are erased.
  • Event log: the payload is emptied after 12 months; only the counter, without content, remains.
  • Sending log (subject and recipient address): 12 months.
  • Message in a child-protection report: erased 6 months after the case is closed; the reviewer’s decision is kept. A case still open — under review or escalated — keeps the message until it is closed.
  • Failed sign-in attempts: 90 days.
  • Uploaded photos and audio: 90 days (no product feature uploads any today).
  • Copy of data produced at your request: 30 days after delivery, then the file is deleted.
  • Raw payload received from the payment operator: reduced after 90 days to the reconciliation fields only.
  • Billing records (subscriptions, payments, invoices): kept until the statutory ten-year accounting deadline. These records are not purged by the nightly sweep: removing an accounting entry calls for a human check, never an automatism.
  • Contact details of a prospect (call-back form or newsletter): erased 3 years after the last update to your record (exchange, call-back, unsubscribe). Unsubscribing stops every send immediately; the row itself remains until that deadline, so that an import cannot sign you up again without your knowledge.
  • Account with no activity for 24 months: email notice, then erasure 30 days later if nothing happens.

Who the data is shared with

Only with processors acting on our behalf, on instruction, and for the stated purpose alone. No data is sold, rented, or used for advertising.

  • Anthropic (United States) — tutoring engine. Receives the child’s first name, age band, year group, and all messages of the current session, replayed on every turn so the tutor keeps the thread. Receives neither the parent’s address nor any payment data.
  • Supabase (European region) — database, authentication and file storage.
  • Resend (United States) — email delivery. Receives the recipient address and the message content.
  • ElevenLabs (United States) — speech synthesis. Receives an exercise sentence designated by identifier, never text written by a child.
  • Sentry (United States) — technical error reports. Configured to transmit no request body, no cookies and no user identifier.
  • KkiaPay (Benin / Côte d’Ivoire) — payments. Receives the amount, the currency and the plan label; our servers send it no name, address or phone number.
  • Vercel and Railway — application hosting.

Transfers outside the European Union

Anthropic, Resend, ElevenLabs and Sentry are established in the United States; KkiaPay operates in West Africa. These transfers rely, or will rely, on the European Commission’s standard contractual clauses, supplemented where applicable by the EU—US Data Privacy Framework when the processor is certified under it; they will be formalised with each processor before commercial launch. A copy of the applicable safeguards is available on request at dpo@kalan.ci.

Children

Kalan is meant for minors, and no child profile is opened without the agreement of the holder of parental responsibility (art. 8 GDPR) — or, for a pupil enrolled by their school, without the school’s mandate, the family being able to take the consent back in its own name. The adult records that agreement when creating the profile; the version of this text and the timestamp are kept as proof. The agreement can be withdrawn at any time, as easily as it was given: processing then stops, and erasure is offered.

When the child speaks

They can dictate an answer instead of typing it. The recording goes to the transcription service, comes back as text the child reads and corrects before sending, and is kept nowhere: not on our servers, not in a file, not in a backup. The microphone never opens on its own — it takes a tap, and the screen shows when it is listening.

What the parent sees, and what they do not

Parents and teachers receive summaries — progress, mastery, alerts — not the transcript of the child’s exchanges with the tutor. That is a design choice: a child must be able to get things wrong without being read word for word.

Your rights

Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time. They are exercised from the parent area, under “My data”, or by email to dpo@kalan.ci. We answer within one month (art. 12.3). You may at any time lodge a complaint with ARTCI in Côte d’Ivoire, or with the supervisory authority of your country of residence in the European Union.

Backups

The database will be backed up every night, encrypted, from commercial launch onwards; the service is not open to the public yet, so automatic backups have not started. An erasure request applies immediately to the live database; backups already produced are not rewritten — they expire on their own and are never used for anything other than recovery after an incident.

Security

Encryption in transit, isolation per family and per school at the database level, mandatory second factor for internal accounts, logging of every access to a child’s data. In the event of a data breach, the supervisory authority is notified within 72 hours and the people concerned are told whenever the risk requires it.