Security and privacy
GDPR and HIPAA compliant. ISO 27001 and 9001 certified.
SuperChild is built and hosted in the European Union for sensitive learner data. Your DPO, municipality or local authority will have questions — we bring the documentation that answers them.
Certifications
Compliance is the gate. We built for it.
GDPR compliant
Learner practice data is special-category data under GDPR Article 9 and is handled that way: lawful basis, purpose limitation, data minimization and documented processing.
HIPAA compliant
For US-based teams, learner data is handled as protected health information under HIPAA, with business associate agreements supported.
ISO 27001 certified
Certified information security management — access control, encryption, incident response and independently audited security processes.
ISO 9001 certified
Certified quality management — documented, audited processes for how the product is built, released and supported.
Documentation pack
Everything your privacy review asks for, ready before it asks.
Provided during evaluation so legal review never blocks your rollout.
- Data-processing agreement (verwerkersovereenkomst), ready to sign
- Sub-processor list
- DPIA support documentation for special-category child data
- EU hosting and data-residency statement
- Privacy policy and security overview for your DPO
- Business associate agreement (BAA) for US teams
- ISO 27001 and ISO 9001 certificates on request
Controls
Security topics for procurement and clinical leadership.
Learner profile control
Learner profiles stay controlled by the clinical team and organization administrators.
Role-based access
Separate access patterns for staff, supervisors, administrators, tutors and caregivers.
Secure practice data
Practice attempts, accuracy and target status are handled as sensitive learner data.
Organization administration
Admin workflows for clinics, telehealth teams, schools and larger organizations.
Data minimization
We capture the practice data needed for clinical review while keeping learner information purposeful.
EU data residency
All learner data is stored and processed in the European Union.
Procurement checklist
What to align before rollout.
- Signed data-processing agreement and privacy review
- DPIA support where your organization requires one
- Roles, permissions and site administration
- Hardware and network assumptions
- Parent or guardian consent workflow where required
- HIPAA (BAA) and FERPA context for US service models
- Internal ownership for implementation and support
Next step
Bring your privacy and procurement questions.
The GDPR documentation pack — DPA, DPIA support, sub-processor list and EU data-residency statement — is ready for your review. US teams: SuperChild is HIPAA compliant, with BAAs and FERPA context handled during evaluation.