Privacy FAQ
Common questions about how BiziKid handles personal data — especially data relating to children. Full details are in our Privacy Policy.
Children's data
Does BiziKid collect data about my child?
Only what is strictly necessary. When you add a student to your account, we store their full name. In the app, only their first name and surname initial are displayed (e.g. "Emma J.") — this allows parents to distinguish between students who share the same first name.
We do not collect photos of students, health information, location data, school records, or any other information about them.
Why do you store the full name if only the initial is shown?
The full name is needed so the app can correctly display the surname initial. It also allows the class administrator to identify students unambiguously when setting up the class — often a parent knows their child's classmates by name, not by their parents' names.
The full name is never shown to other users in the app. Only the first name and surname initial are displayed.
Does my child need an account or need to consent to anything?
No. Students are not users of BiziKid. They have no accounts, they do not log in, and they are never asked to provide data or consent to anything.
The app is for parents and guardians only.
Is this legal under GDPR? What about rules for children's data?
Yes. The processing is lawful under GDPR Article 6(1)(b) — it is necessary to perform the contract you entered into when you created an account.
The provision most people associate with "children and GDPR" is GDPR Article 8, which sets age thresholds for children's consent to digital services. That article does not apply here for two reasons:
- Article 8 only applies to services offered directly to a child. BiziKid is offered to parents.
- Article 8 only activates when consent is the legal basis. Our legal basis is contract performance, not consent.
The same logic applies to Norway's Personopplysningsloven § 5, which mirrors Article 8 and is equally inapplicable.
Is this compliant with Norwegian data protection law (Datatilsynet)?
Yes. Norwegian data protection law (Personopplysningsloven 2018) implements the GDPR and adds a small number of national provisions — none of which change the analysis for BiziKid.
Datatilsynet has in previous enforcement cases found fault with school-related apps that collected health data through unstructured free-text fields, or that had inadequate security. BiziKid's design avoids both: student data is a structured, minimal set of fields, and the app uses secure authenticated access.
The key principle Datatilsynet applies is data minimisation — only collect what is strictly necessary for the stated purpose. Storing a student name for class-membership identification is a direct application of this principle.
Can other parents in the class see my child's name?
Yes — other parents in the same class group can see your student's first name and surname initial. This is necessary for the app to work: parents typically know each other's children by name but may not know each other, so the class list is the shared reference that makes the group meaningful.
This mirrors how any class parent group works in practice — a WhatsApp group, a school newsletter, or a class meeting would reveal the same information. BiziKid limits the display to first name and surname initial; the full surname is not shown to other users.
Student names are only visible to members of the same class group. They are not publicly searchable, not visible to users outside the group, and not shared with any third party.
What happens to my child's data if I delete my account?
It is deleted along with the rest of your account data within 30 days of your deletion request.
Your own data
What personal data do you hold about me?
When you register, we collect:
- Your name and email address
- An optional profile photo
- A push notification token (issued by Apple) so we can deliver notifications to your device
We also store the messages, posts, and comments you create within the app, as these are the core content of the service.
Do you sell my data or use it for advertising?
No. We do not sell your data, share it with advertisers, or use it for any form of profiling or targeted advertising. BiziKid has no advertising business model.
Who else can see my data?
Your name, photo, messages, and posts are visible to other members of the class groups you join — that is the nature of a group communication app. Outside of that:
- Firebase (Google) — receives your device token to deliver push notifications.
- Microsoft Azure — hosts our API and database in the EU.
- Resend — sends transactional emails (e.g. account verification).
These providers act as data processors and are contractually required to protect your data. We do not share your data with anyone else.
Where is my data stored?
On Microsoft Azure servers located in the European Union. All data in transit is encrypted using HTTPS.
What are my rights under GDPR?
You have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Email us at support@bizikid.net and we will respond within 30 days.
If you are in Norway, you can also contact Datatilsynet: datatilsynet.no.
Still have questions? Email us at support@bizikid.net — we'll get back to you within a few days.