The kiddos.games website (the “Website”) is operated by Dr. Szávuly Miklós István E.V. and Pócsik Emese E.V. as joint controllers (together, the “Controllers”). The Controllers respect the rights of visitors in relation to their personal data and process data in accordance with the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679, “GDPR”) and applicable Hungarian law.
The Website primarily offers free skill-development games for children aged 4–10. This policy therefore addresses separately what data we process about children — and what we do not.
Complete safety — what we guarantee
The operating principles of the Website that serve to protect children:
- Zero advertising. No advertisement of any kind appears on the Website or in the games.
- No personalised advertising to children. We do not build interest profiles and do not target advertising at players.
- No in-game purchases. The full content of the games is available without purchasable items.
- No chat and no messaging between players. The Website contains no social features; players cannot contact one another.
- No foreign embedded content during play. There is no external video, advertising frame or third-party embed on the game interface.
- Only an adult can create an account, and we do not request personal data about a child during registration.
- All visuals and content are child-friendly.
For completeness: no advertising appears on the Website, but we do use measurement codes (Meta and TikTok pixels) to measure the effectiveness of our own marketing activity. These do not display advertising on the Website and are not used to profile players. Their use can be controlled through the cookie consent banner.
Children’s data
- An account may only be created by a person aged 18 or over. The data provided at registration is that of the adult (parent, guardian or teacher).
- We do not request or store any identifying data about a child: no name, no age, no photograph and no voice recording.
- The games can be played without registration. In that case only data necessary for technical operation and traffic measurement is generated.
- Game progress linked to an account (levels solved, badges collected) is attached to the adult’s account and is not suitable for identifying a child.
- Under Article 8 GDPR the age at which a child may consent to information society services is between 13 and 16, depending on the member state (for example 16 in Germany, Poland, Romania and Hungary; 14 in Spain). Because our service is designed so that only adults hold accounts, we do not rely on children’s consent as a legal basis.
- If we become aware that a person below the applicable age limit has provided personal data without the required consent, we will delete it without delay. Such cases can be reported to hello@kiddos.hu.
Details of the Controllers
Data processing on the Website is carried out in joint controllership under Article 26 GDPR by the following two undertakings:
- Dr. Szávuly Miklós István E.V. — Seat: 8440 Herend, Tölgyfa utca 18., Hungary. Tax number: 91299587-1-39
- Pócsik Emese E.V. — Seat: 8248 Nemesvámos, Kossuth Lajos u. 256., Hungary. Tax number: 79299376-1-39
Joint point of contact: hello@kiddos.hu. The Controllers can be contacted at this e-mail address in all data protection matters.
Joint controllership
Under Article 26 GDPR the Controllers have agreed on the allocation of responsibilities as follows:
| Controller | Area of responsibility |
|---|---|
| Dr. Szávuly Miklós István E.V. | provision of the service, contractual and financial matters |
| Pócsik Emese E.V. | development and operation of the Website, management of accounts, handling of data subject requests |
Irrespective of this allocation, the data subject may exercise their rights against either controller; an e-mail to hello@kiddos.hu is sufficient.
Recipients
The following service providers receive personal data in the course of operating the Website. All other systems process data exclusively on our own server.
| Recipient | Purpose |
|---|---|
| Google Ireland Ltd. (Google Analytics) | traffic measurement |
| Hotjar Ltd. (Malta) | analysis of Website usage |
| Meta Platforms Ireland Ltd. | measuring the effectiveness of our own advertising |
| TikTok Technology Ltd. (Ireland) | measuring the effectiveness of our own advertising |
| UAB MailerLite (Lithuania) | newsletter delivery |
| Stripe Payments Europe Ltd. (Ireland) | card payment processing |
Processors
The Controllers use the following processors. Processors handle data exclusively in accordance with their contract with the Controllers, for a specified purpose and for the necessary period.
- Versanus Informatikai és Szolgáltató Kft. — hosting of the Website, operation of the web server.
- Google Ireland Ltd. — analysis of traffic and performance data (Google Analytics 4).
- Hotjar Ltd. — recording and storage of session recordings and heatmaps.
- Meta Platforms Ireland Ltd. and TikTok Technology Ltd. — measuring the effectiveness of our own advertising campaigns.
- UAB MailerLite — management of the e-mail list, newsletter delivery.
- Stripe Payments Europe Ltd. — processing of online card payments.
Categories and purposes of data processed
Use of the Website, cookies
Data processed: IP address, browser type, time of visit, pages visited, cookie identifiers.
Purpose: technical operation and security of the Website, troubleshooting, and traffic measurement.
Account creation and game progress
Data processed: the adult user’s e-mail address, password hash, time of registration, progress achieved in the games.
Purpose: operation of the account, preservation of progress, management of premium entitlement.
Newsletter and free materials
Data processed: name, e-mail address, time of subscription, IP address.
Purpose: sending newsletters and free materials on the basis of consent, through the MailerLite system. Unsubscribing is available with one click in every message.
Contact
Data processed: name, e-mail address, content of the message, IP address, time.
Purpose: answering enquiries, complaint handling.
Premium subscription
Data processed: name, e-mail address, billing details, order data, subscription status and billing period.
Purpose: performance of the contract, invoicing, management of the recurring subscription, and compliance with legal obligations. Card details are handled directly by Stripe; the Controllers have no access to them.
Cookies and measurement tools
The Website uses the following types of cookies and measurement tools:
- Technical (functional) cookies — for login, session handling and basic operation. The Website cannot be used without these, so they do not require consent.
- Analytics cookies — Google Analytics 4, for measuring traffic and game usage.
- Usability measurement — analysis of Website usage for development purposes.
- Marketing measurement — Meta and TikTok pixels, for measuring the effectiveness of our own campaigns. These do not display advertising on the Website.
Cookie settings can be changed at any time through the cookie banner at the bottom of the Website. Visitors may also delete or block cookies in their browser at any time; this may affect the operation of certain Website functions.
Legal bases and retention periods
| Processing | Legal basis | Retention period |
|---|---|---|
| Technical operation, logging, security cookies | legitimate interest — Art. 6(1)(f) | max. 1 year |
| Account and game progress | performance of contract — Art. 6(1)(b) | until the account is deleted |
| Traffic measurement (GA4) | consent — Art. 6(1)(a) | max. 14 months |
| Session recording (Hotjar) | legitimate interest — Art. 6(1)(f) | max. 365 days |
| Marketing measurement (Meta, TikTok pixel) | consent — Art. 6(1)(a) | per the provider’s rules, max. 13 months |
| Newsletter | consent — Art. 6(1)(a) | until consent is withdrawn |
| Contact | legitimate interest / pre-contractual steps — Art. 6(1)(b) and (f) | 1–2 years |
| Invoicing | legal obligation — Art. 6(1)(c) | 8 years |
Data subject rights
Under Articles 15–21 GDPR the data subject is entitled in particular to request access to their personal data, to request its rectification or erasure, to request restriction of processing, to request data portability, and — in the case of processing based on legitimate interest — to object to the processing. Where processing is based on consent, that consent may be withdrawn at any time without giving reasons.
Requests can be submitted to hello@kiddos.hu. The Controllers will respond without undue delay and within 30 days at the latest.
Remedies
If the data subject considers that the processing of their personal data is unlawful, they may lodge a complaint with the Hungarian supervisory authority:
NAIH — Hungarian National Authority for Data Protection and Freedom of Information
1055 Budapest, Falk Miksa utca 9–11., Hungary
Telephone: +36 1 391 1400
E-mail: ugyfelszolgalat@naih.hu
Web: naih.hu
Under Article 77 GDPR the data subject may also lodge a complaint with the supervisory authority of the member state of their habitual residence or place of work. The data subject is further entitled to bring proceedings before the court competent at their place of residence or stay.
Legal background of the processing
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on informational self-determination and freedom of information (Hungary);
- Act CVIII of 2001 on electronic commerce services (Hungary);
- applicable accounting and tax rules.
This Privacy Policy is effective from 1 September 2026 until revoked. The Controllers reserve the right to amend this policy; the version in force at any time is available on the Website.















