Skip to main content

Children's privacy: which rules apply where

Last reviewed: 19 August 2026

This page has been drawn up in English. Translations are provided for convenience only; in the event of any inconsistency, the English version prevails.

  • Controller: Que?! Communicatie (Debby Grooteman)
  • Address: Gran Via de les Corts Catalanes, 672, 08010 Barcelona, Spain
  • VAT / NIF: Y1701744B
  • Email: privacy@getmathmax.com
  • Website: https://www.getmathmax.com

1. How to read this page

MathMax is played by children in many countries, and those countries protect children online in different ways and to different degrees. This page sets out the regimes we operate under, organised by continent and country, and states what we do about each.

It describes controls, not certificates. Every row below says what a regime asks for and what the product does; none of them claims a seal, an audit or an accreditation. Where a protection depends on a document rather than on code — a data processing agreement with a school, for instance — the page says what the product does and leaves the document to be requested, rather than asserting one.

This page explains our Privacy Policy and does not replace it. Where the two would differ, the Privacy Policy governs.

One posture applies everywhere. We do not run a different, weaker product for children in permissive jurisdictions: the protections are a single most-protective set applied globally, and a visitor's country is never used to unlock anything. A child in a country with no children's privacy statute at all is protected exactly as one in the strictest jurisdiction we serve.

2. What applies everywhere, regardless of country

These hold for every child using MathMax anywhere in the world. The regional sections that follow add local names and local ages; they never subtract from this list.

ProtectionWhat we do
No advertising or tracking of childrenNo advertising, analytics, session recording or behavioural tracker exists on any page a child can reach. A child's sign-in page loads nothing from any third party; the only third party in the product is the spam protection on the adult sign-up and password forms.
No sale of children's dataThere is no sale of personal data and no path — with or without consent — by which children's or students' data could be sold or used to target advertising.
No public exposureThere is no public ranking. No public surface names a player alongside a result.
No stranger contactA child is not discoverable by search, is never placed in open matching, and can be reached only by approved friends, family members and classmates — their own class, or their school where the school has chosen that. There is no chat.
Guardian-gated connectionsEvery friend connection for a child under 13 requires a guardian's approval before it is active, and for a teenager every connection outside their own family and class. A guardian can view and revoke any connection at any time.
Age is never asked of a childA child's protection level is derived from the grade an adult entered and clamped so it can never resolve to "adult". A child account that submits an adult age is refused, and its level is unchanged.
Data minimisationA child's account holds a first name, a grade, a generated username and their maths results. No email, no date of birth, no phone number, no photograph. Only a coarse age band is stored — never a date of birth.
Lawful basis before processingA known minor's results are neither recorded nor shown to a supervisor unless a lawful basis is on record for them. When the basis ends, the record freezes rather than continuing to be readable.
Access loggingEvery time a supervisor opens an identifiable child's report, a record of who looked, at whom, when, in which role and under which filter is written.
Bounded retentionRetention windows are enforced daily by a scheduled job, not left to a policy nobody runs.
Rights for the responsible adultA guardian can review, correct, export and erase their child's data. Erasure erases, overriding the ordinary retain-on-lapse behaviour.

3. Europe

The GDPR sets the frame across the EEA. Article 8 governs the age at which a child can consent for themselves to an online service — but it is not the mechanism MathMax relies on, because a child never opens an account here. An adult creates the account and holds the relationship, and a school authorises processing for its pupils under an educational purpose.

Article 8 leaves each country to set its own age of digital consent between 13 and 16, which is the fact parents and schools most often arrive looking for. It varies.

WhereRegimeWhat it asks forWhat we do
EEA — age 16GDPR Art. 8 (Germany, Ireland, Netherlands, Luxembourg, Croatia, Slovakia, Slovenia, Liechtenstein and others)Below the national age, a child cannot consent for themselves to an online service; the holder of parental responsibility must.A child never consents here. An adult creates the account and the basis is recorded against that adult, or against the school under its authorisation.
EEA — age 15GDPR Art. 8 (France, Czechia, Greece, Slovenia and others)As above, at 15.As above. The threshold is a configured value, not a number written into the product, so it can be recalibrated per jurisdiction.
Spain — age 14GDPR Art. 8 as implemented by LOPDGDD (Organic Law 3/2018)A child under 14 cannot validly consent to processing for an online service; a parent or guardian must. Spain is our own place of establishment.Our model — an adult subscriber or a school granting a child access — is designed around exactly this.
EEA — age 13GDPR Art. 8 (Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal, Sweden and others)As above, at 13.As above.
All EEAGDPR Arts. 12–22 (transparency and data-subject rights)Clear notice before collection; access, rectification, erasure, portability and objection.Notice is published in 23 languages before collection. A guardian can review, correct, export and erase their child's record; a school can do so within its relationship.
All EEAGDPR Art. 22 (automated decisions and profiling)A child should not be subject to an automated decision producing legal or similarly significant effects, and profiling of children needs particular care.The teaching indicator is decision-support with a human in the loop. It produces no consequence outside the game and is used only in the child's interest.
All EEAGDPR Art. 28 (processors) and Art. 32 (security)A school-facing service processes pupil data on the school's documented instructions, under a written agreement, with appropriate security.We process pupil data on the school's instructions for its educational purpose, and the school's authority ends automatically when a pupil's membership ends. A school needing the written agreement should ask us for it at privacy@getmathmax.com.
All EEAGDPR Arts. 44–49 (international transfers)A transfer outside the EEA needs an appropriate safeguard.We aim to process within the EEA. Our payment provider and our form-protection provider may process outside it; those transfers and their safeguards are described in the Privacy Policy.
United KingdomUK GDPR and the Age Appropriate Design Code (Children's Code)Privacy by default for under-18s, no nudging children toward weaker settings, data minimisation, no detrimental use of children's data, transparency in language a child understands.Minors are locked to protective defaults and cannot lower them; no control invites them to. The child's own progress page carries a notice written for a child, not for a lawyer.

The ages above are the national implementations as we understand them and are given so a reader can find their own country. They are not legal advice, and where a country has changed its threshold, the more protective treatment applies to that child regardless.

4. North America

WhereRegimeWhat it asks forWhat we do
United StatesCOPPA (Children's Online Privacy Protection Act), under 13Notice and verifiable parental consent before collecting personal information from a child under 13; no conditioning play on unnecessary collection; parental access and deletion; no unnecessary retention.No child opens an account here — an adult creates it, or a school provisions it. We collect no email, no date of birth and no contact detail from a child. The maths is playable with no account at all, so nothing is conditioned on collection. A parent can access and delete. A school needing our consent documentation should contact privacy@getmathmax.com.
United StatesCOPPA — school authorisationA school may authorise collection for an educational purpose in place of individual parental consent, within limits.A school's authorisation is recorded as the lawful basis for its pupils and is withdrawn automatically when the pupil's membership ends.
United StatesFERPA (Family Educational Rights and Privacy Act)Education records stay under the school's control; a service acting as a school official uses them only for the authorised purpose and does not redisclose.Pupil data is processed on the school's instructions for its educational purpose only. A teacher sees a narrower field set than a parent, sees only play that happened under the school, and can neither erase nor alter a pupil's record — erasure belongs to the parent or to the school as an entity, and a correction is made by the guardian or by us.
United States — CaliforniaCCPA / CPRARights of access, deletion, correction and opt-out of sale or sharing; heightened treatment of minors' data.There is no sale and no targeted advertising, so there is nothing to opt out of. For children's and students' data there is no opt-in path to either.
United States — statesStudent privacy statutes modelled on SOPIPA (California) — including Colorado, Connecticut, Utah, Virginia and othersNo targeted advertising to students, no profiling for non-educational purposes, no sale of student data, deletion at the school's request, reasonable security.All four prohibitions hold globally, not only in the states that require them. Deletion at a school's request is supported, and access to student data is logged.
United States — all statesOne protective set, applied globallyRequirements differ by state and by regime.We apply a single most-protective superset of the teacher field and rights limitations across COPPA, FERPA, SOPIPA and the Age Appropriate Design Code, everywhere. A less restrictive jurisdiction never unlocks additional fields for a supervisor.
CanadaPIPEDA and provincial equivalentsMeaningful consent, with heightened sensitivity for children's information; access and correction.The global set above already meets or exceeds these; the adult-creates-the-account model supplies the consent.

5. South America

WhereRegimeWhat it asks forWhat we do
BrazilLGPD (Lei Geral de Proteção de Dados), Art. 14Processing of children's data in their best interest, with specific parental consent, and no conditioning a game on collecting more data than needed.The account is created by the responsible adult, the whole curriculum is playable with no account, and children's data is used only to run the game and report to the adults responsible.
Argentina, Chile, Colombia, Peru and othersNational data protection lawsConsent from the holder of parental responsibility; access, correction and deletion.The global set above applies unchanged. Rights are exercised through the guardian or the school at privacy@getmathmax.com.

6. Oceania

WhereRegimeWhat it asks forWhat we do
AustraliaPrivacy Act 1988 and the Australian Privacy PrinciplesCollect only what is needed, be open about it, allow access and correction, keep it secure.The global set above applies unchanged.
AustraliaChildren's Online Privacy Code (in development by the OAIC)Services likely to be accessed by children to be designed in the best interests of the child, with privacy-protective defaults.Protective defaults are not a setting here — a child cannot lower their own privacy, and no surface nudges them to.
New ZealandPrivacy Act 2020Purpose limitation, transparency, access and correction.The global set above applies unchanged.

7. Asia, Africa, and everywhere else

We do not maintain a separate treatment for each remaining jurisdiction, and we do not need one: the protections in section 2 are already the most protective set we apply anywhere, and they apply to every child using MathMax regardless of where they are.

So if your country is not named on this page, the answer is not that fewer rules apply. It is that the same protections apply — no tracking, no advertising, no sale, no public exposure, no stranger contact, a guardian in control, and rights you can exercise by writing to us.

Where a national law gives you a right this page does not name, you keep it. Nothing here limits a right you hold under your own law.

8. Schools, and what to ask us for

If you are evaluating MathMax for a school or a district, the practical questions are usually these: on whose authority is pupil data processed, what can a teacher see, what happens when a pupil leaves, and what is on paper.

Pupil data is processed on the school's instructions for its educational purpose. A teacher sees a narrower field set than a parent and only play that happened under the school. When a pupil's membership ends, the school's authority over their data ends with it automatically — the record is frozen, not left readable to a school that no longer has a relationship with the child, and not silently destroyed either.

For the written agreement, our current sub-processor list, or anything else your procurement process needs, write to privacy@getmathmax.com and say what you need. We would rather answer a specific question than publish a badge.

Reviewed 19 August 2026. This page explains the Privacy Policy and does not replace it. Questions: privacy@getmathmax.com