Parentica

Privacy Policy

Last updated: September 2026

1. Who we are

Parentica ("we", "us", "our") is a specialist-led B2B platform that helps companies reduce the hidden financial damage caused by employee stress, absenteeism, presenteeism, and turnover. This Privacy Policy explains, in plain language, what personal data we collect, why we collect it, where it is stored, who can access it, how long we keep it, and how you can exercise your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Swedish Data Protection Act (2018:218). Protecting your privacy and the confidentiality of your personal data is of the highest importance to us and to the Scandinavian organisations we serve.

2. What data we collect

  • Account data: name, email address, role, and company association provided when an administrator invites you or you register.
  • Usage data: courses viewed, progress, time spent, completion status, and certificates issued.
  • Communication data: chat messages with the AI assistant, questionnaire responses, topic requests, and reviews you submit.
  • Technical data: push notification subscription details (endpoint, keys, user agent) and approximate IP address for security and rate limiting.
  • Company data: company name, contact email, branding assets, and plan information managed by your employer's administrators.
  • Feedback data: ratings, comments, and optional professional background you choose to share in reviews.

We do not collect special categories of personal data (such as data revealing health, racial origin, political opinions, or religious beliefs) unless you voluntarily include such information in a free-text message to the assistant. Where you do, we process it only to the extent necessary to respond to your request and on the basis of your explicit consent, which you may withdraw at any time.

3. Why we collect it (legal basis)

  • Performance of a contract (Art. 6(1)(b)): to deliver the learning platform and related services you or your employer signed up for.
  • Legitimate interest (Art. 6(1)(f)): to secure the platform, prevent abuse, generate aggregated anonymised analytics, and improve content quality.
  • Legal obligation (Art. 6(1)(c)): to retain certain records, such as training-compliance evidence, where required by applicable law.
  • Consent (Art. 6(1)(a)): for optional communications such as push notifications, voice messages, and any special-category data you voluntarily provide.

4. Where your data is stored (EU/EEA)

Your personal data is stored and processed within the European Union / European Economic Area (EU/EEA). The Parentica platform is built and hosted on a secure cloud infrastructure operated by our data processor under a written Data Processing Agreement (DPA). Our processor provides the secure database, file storage, authentication, and application hosting that power the Service. All production data — account records, course progress, chat history, certificates, and uploaded files — resides on processor-managed infrastructure located in the EU.

We have verified, through our DPA with our processor, that personal data is not transferred to or stored in any country outside the EU/EEA for the core data-storage functions of the platform. Where any limited ancillary processing may involve a sub-processor, it is carried out only under the safeguards described in Section 6 below.

5. No sale of data and no third-party retention

We do not sell, rent, or trade your personal data to any third party. We do not allow any third party to retain your personal or confidential information for its own purposes. Third parties that assist us in operating the platform act strictly as processorson our instructions and are contractually prohibited from using your data for any other purpose, from combining it with their own data, and from retaining it after our instructions end.

Specifically, no advertising network, data broker, or analytics provider is given access to identifiable personal data. Any analytics we produce are aggregated and anonymised so that no individual can be re-identified.

6. Sub-processors and international transfers

We rely on the following categories of sub-processors, each bound by GDPR-compliant agreements:

  • Cloud hosting & database: primary storage and processing of all platform data, within the EU/EEA.
  • Email delivery: transactional and notification emails (e.g. welcome, reminders, digests).
  • AI model providers: to power the AI assistant's responses. Messages are processed to generate your reply and are not used to train third-party models.
  • Optional integrations (Google Calendar, Google Tasks, Gmail): only activated when you explicitly connect your own account, and only to perform the action you requested.

Where a sub-processor is established outside the EU/EEA, data is transferred only on the basis of Standard Contractual Clauses adopted by the European Commission, an adequacy decision, or another lawful transfer mechanism under Chapter V of the GDPR. We require all sub-processors to maintain equivalent safeguards and to process data solely on our documented instructions.

7. AI processing and your conversations

When you chat with the AI assistant, your messages and the assistant's responses are stored in your conversation history (on Base44 infrastructure within the EU) so the assistant can remember context and follow up with you across sessions. This conversation data is linked to your account and is never shared with, sold to, or retained by any third party for its own use. AI model providers process message content transiently to generate a response and are contractually prohibited from retaining your data or using it to train their models. You can delete your conversation history at any time by starting a new chat or by requesting erasure under Section 9.

8. How long we retain it

We keep personal data only as long as necessary for the purposes described above:

  • Account & usage data: for the duration of your company's subscription plus a limited wind-down period (up to 12 months) for reporting and legal compliance.
  • Chat history: retained while your account is active so the assistant can maintain context; deleted when you request erasure or when your account is terminated.
  • Questionnaire responses & certificates: kept for as long as needed to demonstrate training compliance, or until you request deletion.
  • Push notification subscriptions: removed when you uninstall the app, revoke consent, or disable notifications.
  • Anonymous, aggregated statistics: may be kept indefinitely, as they no longer identify any individual.

9. Your rights under GDPR

As a data subject in the EU/EEA, you have the right to:

  • Access (Art. 15): obtain a copy of the personal data we hold about you and information about how it is processed.
  • Rectification (Art. 16): request correction of inaccurate or incomplete data.
  • Erasure / "right to be forgotten" (Art. 17): request deletion of your personal data when it is no longer necessary or is being processed unlawfully.
  • Restriction (Art. 18): request that we limit processing of your data in certain circumstances.
  • Portability (Art. 20): receive a copy of your data in a structured, machine-readable format and transmit it to another controller.
  • Objection (Art. 21): object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent (Art. 7): withdraw consent at any time, without affecting processing already carried out.
  • Not be subject to automated decision-making (Art. 22): the assistant provides guidance, not automated legal or similarly significant decisions about you.

To exercise any of these rights, email us at info@parentica.app. We will verify your identity and respond within one month, as required by GDPR. This period may be extended by two further months for complex requests; we will inform you of any extension and the reasons within one month.

10. Security measures

We and our processor Base44 apply appropriate technical and organisational measures (Art. 32 GDPR) to ensure a level of security appropriate to the risk, including:

  • Encryption in transit: all data exchanged between your device and the platform is encrypted using TLS/HTTPS.
  • Encryption at rest: stored data and database records are encrypted on Base44-managed infrastructure.
  • Access control: strict role-based access; only authorised administrators can access user data, and only where necessary.
  • Row-level security: each user's data is isolated so that one user (or company) cannot access another's records.
  • Authentication: secure session management and password handling managed by the platform's auth backend.
  • Regular review: ongoing monitoring and review of systems, access logs, and processing activities.

No method of transmission or storage is completely secure, but we work continuously to protect your information in line with state-of-the-art practices.

11. Personal data breach notification

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights, we will also inform you directly and without undue delay, describing the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it (Art. 34 GDPR).

12. Children's data

The Service is intended for adults aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will indicate the latest revision in the "Last updated" date above and notify users of material changes where appropriate. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Data Controller, DPA & contact

Parentica is the data controller responsible for your personal data processed through this Service. Base44 acts as our data processor under a written Data Processing Agreement that meets the requirements of Art. 28 GDPR. To exercise any of your GDPR rights — including access, rectification, erasure, restriction, portability, or objection — or to lodge a complaint, contact our Data Protection team:

Data Controller: Parentica

Data Processor: our cloud hosting & storage provider (EU/EEA)

Email: info@parentica.app

Data requests: info@parentica.app

We will respond to verified requests within one month, as required by GDPR. You also have the right to complain to the Swedish supervisory authority (Integritetsskyddsmyndigheten, imy.se) or to your local EU/EEA data protection authority if you believe your data has been handled incorrectly. This B2B platform is governed by the GDPR, the Swedish Data Protection Act (2018:218), and applicable EU data protection law.