Security and privacy

GDPR and HIPAA compliant. ISO 27001 and 9001 certified.

SuperChild is built and hosted in the European Union for sensitive learner data. Your DPO, municipality or local authority will have questions — we bring the documentation that answers them.

Certifications

Compliance is the gate. We built for it.

GDPR compliant

Learner practice data is special-category data under GDPR Article 9 and is handled that way: lawful basis, purpose limitation, data minimization and documented processing.

HIPAA compliant

For US-based teams, learner data is handled as protected health information under HIPAA, with business associate agreements supported.

ISO 27001 certified

Certified information security management — access control, encryption, incident response and independently audited security processes.

ISO 9001 certified

Certified quality management — documented, audited processes for how the product is built, released and supported.

Documentation pack

Everything your privacy review asks for, ready before it asks.

Provided during evaluation so legal review never blocks your rollout.

  • Data-processing agreement (verwerkersovereenkomst), ready to sign
  • Sub-processor list
  • DPIA support documentation for special-category child data
  • EU hosting and data-residency statement
  • Privacy policy and security overview for your DPO
  • Business associate agreement (BAA) for US teams
  • ISO 27001 and ISO 9001 certificates on request

Controls

Security topics for procurement and clinical leadership.

Learner profile control

Learner profiles stay controlled by the clinical team and organization administrators.

Role-based access

Separate access patterns for staff, supervisors, administrators, tutors and caregivers.

Secure practice data

Practice attempts, accuracy and target status are handled as sensitive learner data.

Organization administration

Admin workflows for clinics, telehealth teams, schools and larger organizations.

Data minimization

We capture the practice data needed for clinical review while keeping learner information purposeful.

EU data residency

All learner data is stored and processed in the European Union.

Procurement checklist

What to align before rollout.

  • Signed data-processing agreement and privacy review
  • DPIA support where your organization requires one
  • Roles, permissions and site administration
  • Hardware and network assumptions
  • Parent or guardian consent workflow where required
  • HIPAA (BAA) and FERPA context for US service models
  • Internal ownership for implementation and support

Next step

Bring your privacy and procurement questions.

The GDPR documentation pack — DPA, DPIA support, sub-processor list and EU data-residency statement — is ready for your review. US teams: SuperChild is HIPAA compliant, with BAAs and FERPA context handled during evaluation.