← back to home

Data Compliance

Last updated: June 16, 2026

CodeQuest Arcade is built for children aged 10–14. Because our audience is young, we hold ourselves to a higher data-protection standard than a generic adult product. This page summarises the frameworks we follow and the safeguards we apply.

Regulatory frameworks

Lawful basis for processing

Child-safety design choices

Sub-processors

We use trusted infrastructure providers for hosting, database, authentication, email delivery, payment processing and AI features. Each provider is bound by a data processing agreement and may only use data to deliver the contracted service. A current list is available on request to privacy@aurahacks.com.

International data transfers

Where personal data is transferred outside the EU/UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical safeguards (encryption in transit and at rest).

Security program

Data subject & parental requests

To exercise any right (access, rectification, deletion, portability, withdrawal of consent, opt-out of "sale/sharing"), email privacy@aurahacks.com from the address on the account. We verify identity before acting and respond within 30 days.

Schools & districts

For classroom deployments we can sign a Data Processing Agreement (DPA) and, where applicable in the U.S., a Student Data Privacy Agreement based on the SDPC standard template. Contact schools@aurahacks.com.

Reporting concerns

If you believe a child's data has been misused, or you spot a security issue, contact security@aurahacks.com. EU/UK users also have the right to lodge a complaint with their local Data Protection Authority.