← back to homeData Compliance
Last updated: June 16, 2026
CodeQuest Arcade is built for children aged 10–14. Because our audience is young, we hold ourselves to a higher data-protection standard than a generic adult product. This page summarises the frameworks we follow and the safeguards we apply.
Regulatory frameworks
- COPPA (USA) — Children's Online Privacy Protection Act. We obtain verifiable parental consent before collecting personal information from children under 13, and we provide parents with the ability to review, delete, and refuse further collection.
- GDPR & "GDPR-K" (EU/EEA) — Article 8 sets the digital age of consent (13–16, depending on member state). For users below that age we rely on parent/guardian consent. We honour the rights of access, rectification, erasure, restriction, portability, and objection.
- UK Age Appropriate Design Code (Children's Code) — We apply the 15 standards, including data minimisation, high-privacy defaults, no nudge techniques, and no profiling by default for child accounts.
- CCPA / CPRA (California) — California residents have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information. We do not sell or share children's personal information.
- FERPA (USA, where applicable) — When CodeQuest is used through a school, we act as a "school official" under FERPA and process student records only at the school's direction.
- LGPD (Brazil), PIPEDA (Canada), Australia Privacy Act, India DPDP Act — We follow equivalent principles of lawful basis, consent, transparency, and security.
Lawful basis for processing
- Consent — from the parent/guardian for under-age users.
- Contract — to deliver the learning service the account holder signed up for.
- Legitimate interest — limited to security, fraud prevention and aggregate analytics; balanced against children's interests.
- Legal obligation — to respond to lawful requests and keep required records.
Child-safety design choices
- No behavioural advertising and no third-party ad SDKs on child accounts.
- No precise geolocation collection.
- High-privacy defaults: profiles are private; friend connections are opt-in.
- No public chat. Limited, structured in-app interactions only.
- Plain-language explanations of data use, sized for a 10–14 reader.
- Parental dashboard on request: review progress, export data, delete account.
- Content moderation and profanity filtering on any user-submitted text shown to others.
Sub-processors
We use trusted infrastructure providers for hosting, database, authentication, email delivery, payment processing and AI features. Each provider is bound by a data processing agreement and may only use data to deliver the contracted service. A current list is available on request to privacy@aurahacks.com.
International data transfers
Where personal data is transferred outside the EU/UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical safeguards (encryption in transit and at rest).
Security program
- TLS 1.2+ for all traffic.
- Encrypted database storage and encrypted backups.
- Principle of least privilege for staff access; access is logged.
- Passwords hashed with industry-standard algorithms — never stored in clear text.
- Regular dependency scanning and security reviews.
- Incident response: in the event of a personal data breach we notify regulators within 72 hours and affected parents/guardians without undue delay, as required.
Data subject & parental requests
To exercise any right (access, rectification, deletion, portability, withdrawal of consent, opt-out of "sale/sharing"), email privacy@aurahacks.com from the address on the account. We verify identity before acting and respond within 30 days.
Schools & districts
For classroom deployments we can sign a Data Processing Agreement (DPA) and, where applicable in the U.S., a Student Data Privacy Agreement based on the SDPC standard template. Contact schools@aurahacks.com.
Reporting concerns
If you believe a child's data has been misused, or you spot a security issue, contact security@aurahacks.com. EU/UK users also have the right to lodge a complaint with their local Data Protection Authority.