Privacy Policy
How MBC Kids Club collects and uses personal data · GDPR-compliant
mabellacalice OÜ, trading as MBC Kids Club (“we”, “us”, “our”), operates the website mbckids.club (the “Website”) and the associated digital membership and academy (together, the “Service”). We respect your privacy and handle personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian data-protection law.
This policy explains what personal data we collect, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. It applies to the people who hold accounts with us – parents, guardians and other adult users.
1. Who is responsible for your data (the controller)
The data controller is:
mabellacalice OÜ (t/a MBC Kids Club)
Registered legal address: [UNICOUNT VIRTUAL OFFICE ADDRESS], Estonia
Estonian registry code: 16383569
Email: legals@mbckids.club
We have not appointed a Data Protection Officer, as we are not legally required to. For any data-protection question, write to us at the email above.
2. A note on children
The Service is designed for parents and guardians, not for children to sign up to. Accounts are created and held by adults. We do not knowingly collect personal data directly from children.
The educational apps and activities we provide for children to use are designed so that they do not collect, store or transmit any personal data from the child – there is no child login, no profile, no saved scores or progress tied to a child, and no tracking. Children use them under the supervision of the account-holding adult.
Because account-holders must be adults (18+), the question of a child’s consent under Article 8 GDPR (which in Estonia applies from age 13) does not arise in the normal use of our Service. If you believe a child has created an account or provided us personal data, please contact us at legals@mbckids.club and we will delete it.
3. What data we collect, and why
We collect only what we need to provide the Service. The table below summarises each category, the reason we process it, and our legal basis under Article 6 GDPR.
| Data we collect | Why we use it | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Account details: name, email address, password (stored by our platform in hashed form) | To create and run your account and give you access to the membership and courses | Performance of a contract (Art. 6(1)(b)) |
| Order and billing data: items purchased, subscription status, transaction records (card details are handled by Stripe, not stored by us) | To take payment, manage your subscription, provide receipts and handle refunds | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Marketing email address and preferences | To send our newsletter and updates, where you have asked to receive them | Consent (Art. 6(1)(a)) – you can withdraw it at any time |
| Correspondence: messages you send us and our replies | To answer your questions and provide support | Legitimate interests (Art. 6(1)(f)) – responding to people who contact us |
| Technical data strictly necessary to run the site (e.g. session and security cookies set by our hosting/membership platform) | To keep you logged in, keep the site secure and make it work | Legitimate interests (Art. 6(1)(f)) – a secure, functioning site |
| Aggregated visit statistics from our self-hosted Independent Analytics (no cookies, no third-party sharing, no directly identifying data) | To understand how the Website is used and improve it | Legitimate interests (Art. 6(1)(f)) – privacy-friendly, first-party measurement |
For website statistics we use Independent Analytics, a self-hosted tool that runs entirely within our own WordPress system. It does not set cookies, does not send data to any third party, and stores no directly identifying personal data. We do not use Google Analytics, the Meta pixel, advertising trackers or behavioural profiling, and we do not make automated decisions producing legal or similarly significant effects.
Embedded third-party content (where used). Some pages may include embedded content such as YouTube videos or an Instagram feed. Where we use these, the provider (Google/YouTube, Meta/Instagram) may set its own cookies and receive data about your visit, including your IP address, when the content loads. We load this content only where you have consented through our cookie banner, and each provider’s own privacy policy then applies. If you do not consent, the content is not loaded.
4. How we collect it
We collect personal data when you: create an account or buy a membership or course; sign up to our email list; contact us by email or through a form; or simply use the Website (limited technical and security data only).
5. Who we share it with (our processors)
We do not sell, rent or trade your personal data. We share it only with the service providers that help us run the Service, each acting as our processor under a data-processing agreement, and only as far as needed. Our main processors are:
| Provider | What they do | Where data may be processed |
|---|---|---|
| Freshlearn | Membership platform – hosts accounts, course access and the user area | Delaware USA |
| Stripe | Payment processing – handles card payments and subscriptions | EU/US (Stripe is the controller for payment/card data) |
| SendFox | Email marketing – sends our newsletter to subscribers | United States |
| Namecheap | Hosts the Website and/or domain | USA |
Some of these providers are based in, or transfer data to, the United States or other countries outside the EU/EEA. Where that happens, the transfer is protected by appropriate safeguards under Chapter V GDPR – typically the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply.
We may also disclose personal data where we are legally required to (for example to a tax authority or court), or to protect our legal rights.
6. How long we keep it
We keep personal data only as long as we need it:
- Account and membership data – for as long as your account is active, and then deleted or anonymised within a reasonable period after you close it (we aim for 90 days).
- Order and tax records – for as long as tax and accounting law requires us to keep them (commonly 7 years under Estonian accounting law), even after you close your account.
- Marketing data – until you unsubscribe or withdraw consent, after which we remove you from the active list.
- Correspondence – for as long as needed to handle your query and a reasonable period afterwards.
7. Your rights under the GDPR
You have the following rights over your personal data. To exercise any of them, email legals@mbckids.club; we will respond within one month.
- Access – ask for a copy of the personal data we hold about you.
- Rectification – ask us to correct data that is wrong or incomplete.
- Erasure – ask us to delete your data (“right to be forgotten”), subject to records we must keep by law.
- Restriction – ask us to limit how we use your data while a concern is resolved.
- Portability – receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Objection – object to processing based on our legitimate interests.
- Withdraw consent – where we rely on consent (e.g. marketing), withdraw it at any time; this does not affect processing already carried out.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). You may also complain to the authority in the EU country where you live or work.
8. Cookies and similar technologies
We use only cookies that are strictly necessary to run the Website – for example to keep you logged in and to keep the site secure. These do not require consent under EU rules. Our website-statistics tool, Independent Analytics, uses no cookies at all.
We do not currently use analytics, advertising or social-media tracking cookies. If we enable embedded third-party content such as YouTube or Instagram, those providers set their own cookies; we load that content only after you consent through our cookie banner, and you can change your choice at any time. See our Cookie Notice for detail.
9. How we keep data secure
We use reasonable technical and organisational measures to protect personal data, and we work only with reputable providers who do the same. Card payments are handled directly by Stripe over an encrypted connection; we never see or store full card numbers. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security, but we take the protection of your data seriously.
10. Changes to this policy
We may update this policy from time to time. When we make material changes, we will post the updated version here and, where appropriate, notify account-holders by email. The date below shows when it was last revised. Please check back occasionally.
11. Contact us
For any question about this policy or your personal data:
mabellacalice OÜ t/a MBC Kids Club
Email: legals@mbckids.club
Last updated: 25th June 2026
