Back to Privacy Policy

Privacy Policy Changes

This page shows the changes made to our Privacy Policy on 30 November 2025

Summary of Changes

Key Updates

New Section Added
Section 13: GDPR Compliance - Comprehensive GDPR-specific information
Enhanced Content
Introduction, Contact Information, Data Breach Notification sections updated
Additions
Data Protection Officer contact details, GDPR legal basis explanations, enhanced rights information, data processor details, comprehensive child protection and parental consent requirements
Added content
Removed content
Introduction Section - Enhanced Compliance Statement
<div className="govuk-inset-text">
<p className="govuk-body">
AKAERE NETWORKS TECHNOLOGY LTD is committed to protecting your privacy and
ensuring your personal data is handled responsibly and in accordance with UK data protection laws.
AKAERE NETWORKS TECHNOLOGY LTD is committed to protecting your privacy and
ensuring your personal data is handled responsibly and in accordance with:
</p>
<ul className="govuk-list govuk-list--bullet">
<li>General Data Protection Regulation (GDPR) (EU) 2016/679</li>
<li>UK GDPR as incorporated into the Data Protection Act 2018</li>
<li>Privacy and Electronic Communications Regulations (PECR)</li>
<li>All applicable UK and EU data protection legislation</li>
</ul>
</div>
New GDPR Reference Notice
ADDED
<div className="govuk-warning-text">
This policy complies with GDPR Articles 13 and 14 transparency requirements.
For GDPR-specific information, see Section 13.
</div>
Section 10: Contact Us - Enhanced DPO Information
<div className="govuk-inset-text">
<strong>Data Protection Officer</strong>
<strong>Data Controller:</strong>
AKAERE NETWORKS TECHNOLOGY LTD
Company Number: 16382257
...
<strong>Data Protection Officer (DPO):</strong>
Email: dpo@akae.re (for GDPR rights requests)
<strong>General Privacy Enquiries:</strong>
Email: privacy@akae.re
NEW SECTION 13: GDPR Compliance
ADDED - MAJOR UPDATE
<h2>13. GDPR Compliance</h2>
GDPR Statement: Full compliance with GDPR (EU) 2016/679 and UK GDPR
<h3>Legal grounds for processing (Article 6 GDPR)</h3>
- Article 6(1)(a) - Consent (marketing, analytics)
- Article 6(1)(b) - Contract (service delivery)
- Article 6(1)(c) - Legal obligation (compliance)
- Article 6(1)(f) - Legitimate interests (security, business operations)
<h3>Your rights under GDPR</h3>
Enhanced rights including:
- Right to be informed (Articles 13-14)
- Right of access (Article 15) - free first request
- Right to rectification (Article 16) - within 72 hours
- Right to erasure (Article 17)
- Right to restriction (Article 18)
- Right to data portability (Article 20) - JSON/CSV format
- Right to object (Article 21)
- Rights related to automated decision-making (Article 22)
<h3>Response timeframes</h3>
- One month standard (may extend by 2 months for complex requests)
- 72 hours for urgent rectification
- Immediate for consent withdrawal
<h3>Cross-border data transfers</h3>
- Standard Contractual Clauses (SCCs) - EU Commission approved 2021
- Adequacy decisions for approved countries
- Transfer Impact Assessments (TIAs) for international transfers
<h3>Data Protection Officer (DPO)</h3>
Dedicated DPO contact: dpo@akae.re
<h3>Data Protection Impact Assessments (DPIA)</h3>
Conducted for high-risk processing activities
<h3>Records of processing activities (Article 30)</h3>
Maintained detailed records available to supervisory authorities
<h3>Data processors and sub-processors</h3>
- Cloudflare, Inc. (Infrastructure, USA with SCCs)
- Resend (Email delivery, EU/USA with SCCs)
- Stripe, Inc. (Payment processing, USA with SCCs)
All under GDPR-compliant Data Processing Agreements
<h3>Supervisory authority</h3>
UK Information Commissioner's Office (ICO) - lead authority
Right to lodge complaint with ICO or local supervisory authority
Section Renumbering
<h2>13. Additional information</h2>
<h2>14. Additional information</h2>
...
(Section moved from 13 to 14 due to new GDPR section insertion)
Section 14: Data Breach Notification - Enhanced GDPR Reference
In the event of a data breach... we will notify you and the ICO within 72 hours
as required by law.
In the event of a data breach... we will notify you and the ICO within 72 hours
as required by GDPR Article 33 and 34.
Our breach notification will include:
- Nature of the breach and categories of data affected
- Likely consequences and measures we're taking
- Contact point for further information
- Recommendations for protecting yourself
Sidebar - Enhanced GDPR Information
<h3>Data Protection</h3>
We are committed to protecting your privacy and complying with GDPR, CCPA,
and UK data protection laws.
<h3>GDPR Compliance</h3>
We are fully compliant with GDPR (EU) 2016/679, UK GDPR, and the Data
Protection Act 2018. Your personal data is processed lawfully, fairly,
and transparently.
<h3>Your Rights</h3>
Contact us at privacy@akae.re to exercise your rights.
<h3>Your GDPR Rights</h3>
Contact our DPO at dpo@akae.re to exercise your rights.
<h3>Data Protection Officer</h3>
For GDPR enquiries: dpo@akae.re - Response within one month
<h3>Child Safety</h3>
Users under 18 require parental consent. Contact: child-safety@akae.re
Section 11: Children and Young Persons' Privacy - MAJOR ENHANCEMENT
SIGNIFICANTLY ENHANCED
<h2>11. Children's privacy</h2>
Our services are not intended for children under the age of 18.
We do not knowingly collect personal data from children.
<h2>11. Children and young persons' privacy</h2>
IMPORTANT: Minimum age set at 14 years (aligning with Italy/Spain GDPR standards,
exceeding UK/US minimum requirements of 13 years)
WARNING: Users under 18 years must have parental or guardian consent.
<h3>Age restrictions and requirements</h3>
- Under 14 years: Services strictly prohibited
- 14 to 17 years: Requires verifiable parental/guardian consent
- 18 years and over: Full access without parental consent
<h3>Parental consent requirements</h3>
- Provided by parent/legal guardian with parental responsibility
- Verified through secure authentication (email, identity, signed form)
- Documented and stored securely per GDPR
- Revocable at any time
<h3>Consent verification process</h3>
- Email verification to parent/guardian
- Document upload (signed consent form)
- Identity verification (Stripe Identity)
- Payment card verification (refunded)
<h3>Parental rights and controls (GDPR Article 8)</h3>
- Right to access child's data
- Right to rectification
- Right to erasure (immediate deletion)
- Right to withdraw consent
- Right to monitor account activity
Contact: child-safety@akae.re or dpo@akae.re
<h3>Limited data collection for minors</h3>
- Only essential information collected
- No marketing or profiling
- Enhanced privacy by default
- Restricted third-party sharing
- No sale of minor's data
<h3>Age verification mechanisms</h3>
- Date of birth declaration
- Age-gate for under 18
- Automatic parental consent workflow
- Account suspension pending verification
<h3>Child safety measures</h3>
- Enhanced monitoring of minor accounts
- Easy reporting mechanisms
- Age-appropriate content controls
- Privacy education resources
- 24-hour incident response team
<h3>Compliance</h3>
- GDPR Article 8 (14+ aligns with Italy/Spain, exceeds UK's 13+ minimum)
- Note: GDPR default is 16, member states can set 13-16 years
- UK Age Appropriate Design Code
- COPPA principles (14+ exceeds 13+ requirement)
- Online Safety Act 2023 (UK)
- UN Convention on Rights of the Child

Impact Assessment

These updates do not materially change how we collect, use, or protect your data. They provide enhanced transparency about our existing GDPR compliance practices and make it easier for you to understand and exercise your data protection rights.

Important No action is required from you. These updates enhance transparency and do not affect your existing service or data processing.