Last updated: 1 April 2026
This statement explains how TaleBuzzer complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is intended for parents, guardians, schools, and professionals who want to understand our data governance in detail.
TaleBuzzer Ltd is the data controller for all personal data processed through the TaleBuzzer platform. As data controller, we determine the purposes and means of processing personal data.
Contact: hello@talebuzzer.com
We are registered with the Information Commissioner's Office (ICO). Our ICO registration number will be published here upon completion of registration.
Under UK GDPR Article 6, we rely on the following legal bases for processing personal data:
Article 6(1)(b) — Contract
Processing necessary to provide the TaleBuzzer service under our Terms of Use. This covers account management, story generation, subscription billing, and reading progress tracking.
Article 6(1)(c) — Legal obligation
Processing required to comply with applicable law, including financial record-keeping obligations under UK tax law and responding to lawful requests from competent authorities.
Article 6(1)(f) — Legitimate interests
Processing necessary for our legitimate interests in operating a secure, reliable platform, preventing fraud and abuse, and improving our service using aggregated anonymised data. We have conducted a Legitimate Interests Assessment (LIA) for each purpose and confirmed that our interests do not override the rights of data subjects.
We do not rely on consent as a legal basis for any processing activity, except where required for non-essential cookies (PECR). This means you do not need to withdraw consent to stop us processing your data — you can exercise your rights under UK GDPR directly.
We do not intentionally collect special category data as defined by UK GDPR Article 9, including health data, biometric data, or data revealing racial or ethnic origin.
Parents may optionally enable SEN reading preferences for a child profile. These preferences are stored locally on the user's device in localStorage and are not transmitted to our servers or shared with any third party. We do not use these preferences to infer or record a child's medical condition.
We apply data minimisation by design. We collect only the data strictly necessary for each processing purpose. We do not collect:
— Children's email addresses or contact information
— Photographs or biometric data
— Location data beyond IP address (used for security only)
— Sensitive personal data about children's health, religion, ethnicity, or family circumstances
Personal data is not used for any purpose other than that for which it was collected. Reading data collected to provide personalised stories is not used for advertising, third-party profiling, or AI model training for external purposes.
Under UK GDPR, data subjects have the following rights:
Right of access (Article 15)
Request a copy of all personal data we hold. We will provide this within 30 days of a verified request at no charge.
Right to rectification (Article 16)
Request correction of inaccurate or incomplete personal data.
Right to erasure (Article 17)
Request deletion of personal data where it is no longer necessary, where processing is unlawful, or where you withdraw consent. Deletion is completed within 30 days.
Right to restriction (Article 18)
Request restriction of processing while accuracy is contested or an objection is considered.
Right to data portability (Article 20)
Receive personal data in a structured, commonly used, machine-readable format.
Right to object (Article 21)
Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
Rights relating to children
Parents and guardians may exercise all rights on behalf of a child in their care. We will verify the relationship before disclosing or deleting a child's data.
To exercise any right, contact us at hello@talebuzzer.com with the subject line "Data Rights Request". We will acknowledge within 5 working days and respond fully within 30 days.
| Processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Supabase Inc | USA (EU servers — Frankfurt) | Database, authentication | IDTA / EU SCCs |
| Stripe Inc | USA | Payment processing | IDTA / EU SCCs |
| OpenAI LP | USA | AI story generation | IDTA / EU SCCs |
| Vercel Inc | USA | Hosting and deployment | IDTA / EU SCCs |
Where personal data is transferred to countries outside the UK, we ensure appropriate safeguards are in place under UK GDPR Article 46, including the ICO's International Data Transfer Agreement (IDTA).
| Data type | Retention period |
|---|---|
| Parent account data | Duration of account + 30 days after closure |
| Child profile data | Duration of account + 30 days after closure |
| Generated stories | Duration of account + 30 days after closure |
| Payment records | 7 years (UK tax law requirement) |
| Server access logs | 90 days |
| Security incident records | 3 years |
TaleBuzzer implements data protection by design and by default in accordance with UK GDPR Article 25. This includes encrypting all data in transit (TLS 1.3) and at rest, hashing all passwords, implementing role-based access controls, and applying automatic session timeouts on child-facing screens.
In the event of a personal data breach that poses a risk to the rights and freedoms of data subjects, we will notify the ICO within 72 hours of discovery as required by UK GDPR Article 33. To report a potential security vulnerability, contact hello@talebuzzer.com immediately.
If you believe we have not handled your personal data in accordance with UK GDPR, you have the right to lodge a complaint with the ICO:
Website: ico.org.uk/make-a-complaint · Telephone: 0303 123 1113
We encourage you to contact us at hello@talebuzzer.com in the first instance.