Privacy Policy

Data protection and privacy

PRIVACY POLICY

This Privacy Policy establishes the terms under which No More Bullying uses and protects the information provided by its users when using our services. This platform is committed to the security of its users' data.

Effective date: January 27, 2025

Last update: July 28, 2025

Data controller: KO Bully - Child Protection Platform

1. INFORMATION WE COLLECT

1.1. Communication Data

a) Conversation content: We record all messages exchanged between the user and our artificial intelligence system.

b) Session metadata: Date, start and end time, duration of conversations.

c) Generated responses: All responses provided by our AI system.

SPECIAL PROTECTION: When names of minors are mentioned, our system automatically proceeds to anonymize them, replacing them with generic terms in all our records.

1.2. Technical Data

a) Connection information: IP address, browser type, operating system.

b) Device data: Type of device used to access the service.

c) Technical cookies: Only those strictly necessary for the functioning of the service.

1.3. Information We DO NOT Collect

No More Bullying does not collect or store:

  • Full names or personal identification data
  • Physical addresses, phone numbers, or contact information
  • Financial or payment method information
  • Tracking, analytics, or advertising cookies
  • Access to camera, microphone, or device files

2. PURPOSE OF PROCESSING

2.1. Main Purposes

a)

Provide personalized and contextually relevant responses through our AI system.

b)

Maintain continuity and coherence in conversations during a session.

c)

Improve the quality and accuracy of the artificial intelligence system's responses.

d)

Ensure service security and prevent malicious use.

2.2. Secondary Purposes

a)

Conduct aggregated and anonymized statistical analysis for research.

b)

Comply with legal obligations and requirements from competent authorities.

c)

Exercise or defend rights in legal proceedings.

3. LEGAL BASIS FOR PROCESSING

a)
Consent: The voluntary use of our services constitutes consent for data processing as described in this policy.
b)
Legitimate interest: The improvement of our child protection services and prevention of school bullying.
c)
Legal compliance: Obligations arising from applicable regulations on child protection.

4. SPECIAL PROTECTION OF MINORS

Given the nature of our services, we apply enhanced protection measures for any information that may relate to minors:

4.1. Automatic Anonymization

Any reference to minors' proper names is automatically replaced with generic terms in our storage systems.

4.2. Restricted Access

Access to conversations involving minors is limited exclusively to authorized personnel with specific training in child protection.

4.3. Reduced Retention

Conversations involving minors are automatically deleted within a maximum period of 90 days, less than the general retention period.

5. SECURITY MEASURES

5.1. Technical Measures

End-to-end encryption of all communications using TLS 1.3 protocols.

Data-at-rest encryption using AES-256 algorithms.

Intrusion detection and prevention systems (IDS/IPS).

Continuous monitoring of access and suspicious activities.

5.2. Organizational Measures

Multi-factor authentication for all personnel with data access.

Principle of least privilege access.

Regular security audits conducted by independent third parties.

Continuous staff training on data protection.

6. USER RIGHTS

In accordance with the General Data Protection Regulation (GDPR) and applicable national legislation, users have the following rights:

6.1. Right of Access

Obtain confirmation about whether we are processing your personal data and, if so, access to such data.

6.2. Right to Rectification

Request the rectification of inaccurate data or the completion of incomplete data.

6.3. Right to Erasure

Request the deletion of your personal data when certain circumstances apply.

6.4. Right to Restriction

Request the suspension of processing of your data in certain circumstances.

6.5. Right to Data Portability

Receive your data in a structured, commonly used and machine-readable format.

6.6. Right to Object

Object to the processing of your data for reasons related to your particular situation.

Exercising Rights

To exercise any of these rights, users can contact us through:

Email: hello@kobully.com

Response time: Maximum 30 calendar days from receipt of the request.

7. RETENTION PERIODS

Data CategoryRetention PeriodLegal Basis
General conversations6 monthsService improvement
Conversations with minors90 daysSpecial protection
Technical data12 monthsSecurity and prevention
Security logs24 monthsLegal compliance
Anonymized dataIndefiniteResearch

8. CONTACT AND INQUIRIES

For any inquiries related to this Privacy Policy or the processing of your personal data, you can contact us:

General Contact

Email: hello@kobully.com

Response: Maximum 48 hours

Data Protection Officer

Email: dpo@kobully.com

Response: Maximum 30 days