GDPR statement
Your data, your rules.
KindNest is fully compliant with UK GDPR and the Data Protection Act 2018.
Who we are
KindNest is the data controller for the information you give us. Contact our Data Protection Officer at dpo@kindnest.me.
What we collect
- Parent name, email and (optionally) phone number — to run your account.
- Child's first name and age band — no surnames, no photos, no videos, no addresses, no school details.
- Sort code and account number you publish on your milestone page so family and friends can pay you directly. Stored encrypted.
- Gift records that you or senders add (amount, category, sender name, optional note).
- Account security data: hashed password, 2FA secret, sign-in history.
- Basic device, browser and IP signals used only for fraud and abuse prevention.
- Support correspondence you send us.
KindNest never holds your money. Payments are made by the sender, in their own bank app, directly to your bank account. We never see or store card numbers, CVVs, bank passwords or one-time codes.
Why we use it (lawful basis)
- Contract — to run your gifting page and move money you've asked us to move.
- Legal obligation — anti-fraud, anti-money-laundering and tax (HMRC) records.
- Legitimate interest — security, abuse prevention and service improvement.
We never use your data for advertising and we never sell it.
How long we keep it
Account data is kept while your account is active. Financial records are retained for 6 years to meet HMRC and FCA rules. Everything else is deleted within 30 days of account closure.
Where it's stored
All personal data is hosted within the UK and EEA, encrypted in transit (TLS) and at rest (AES-256). Where a subprocessor (e.g. our payments partner) is involved, they are bound by a signed Data Processing Agreement and equivalent safeguards.
Your rights
- Access — get a copy of everything we hold on you.
- Rectification — correct anything that's wrong.
- Erasure — ask us to delete your account and data.
- Portability — export your data in a machine-readable format.
- Restriction & objection — limit or object to specific processing.
- Withdraw consent at any time without affecting prior use.
You can exercise any right from your dashboard or by emailing dpo@kindnest.me. We respond within 30 days.
Children's data
Accounts are held by parents and guardians aged 18 or over. The only child data on the platform is a first name and age band, chosen and entered by the parent. Surnames, addresses, school details and contact information for children are not collected.
Cookies and similar technologies
We use a small number of strictly necessary cookies to keep you signed in and to protect against fraud and abuse. We do not use advertising cookies or third-party tracking pixels, and we do not share data with ad networks. A short cookie banner is shown on your first visit so you can review and accept.
Who we share it with (subprocessors)
We use a small number of trusted suppliers to run the service — cloud hosting, transactional email delivery, error and uptime monitoring, and SMS for two-factor authentication. We do not share data with payment processors because we don't take payments: senders pay you directly from their own bank. Every subprocessor is bound by a signed Data Processing Agreement, processes data only on our written instructions, and is reviewed before onboarding and at least annually. A current list is available on request from dpo@kindnest.me.
International transfers
Personal data is stored in the UK and EEA. Where a subprocessor processes data outside this area, we rely on UK and EU adequacy decisions or the UK International Data Transfer Agreement / EU Standard Contractual Clauses, together with technical safeguards such as encryption and access controls.
Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Bank details are additionally encrypted with a separate key. We enforce two-factor authentication on parent and admin accounts, least-privilege access, audit logging, and regular penetration and abuse testing aligned to OWASP ASVS.
Automated decisions and profiling
We use automated scoring to flag suspicious account activity (e.g. unusual sign-ins, repeated bank-detail changes, abusive senders). This does not produce a legal or similarly significant effect on you on its own — anything flagged as high risk is reviewed by a human before any action is taken. You can ask for human review and contest any decision by emailing dpo@kindnest.me.
Marketing
By default we only send essential service messages — account and security notices, replies to your support messages, and (if you provide a mobile) a one-off SMS confirming a gift you've just recorded. We do not send marketing emails or texts.
Breach notification
In the unlikely event of a personal data breach affecting you, we will notify the UK Information Commissioner's Office within 72 hours of becoming aware and contact you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
Complaints
If you're not happy with how we've handled your data, please contact us first — we'll always try to put things right. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this statement
We will update this page when our practices change and, for material changes, notify you by email or in-app before they take effect. The “last updated” date below shows the current version.
Last updated: 14 June 2026.