Skip to content
Minsa
PricingPrivacyContact
FRENIDSV
See pricing

Privacy

Privacy policy

Version: Draft — 24 July 2026. This policy describes how Minsa processes personal data through its application and this website.

Draft document. This text describes how the service actually works, but it must be reviewed and validated by a data protection officer (DPO) or legal counsel, and completed with each school's own notices, before final publication.

1. Controllers and roles

Minsa is a management application for preschools and the families they invite to it.

For children's and families' data, the school determines the purposes and means of processing: it is the data controller. Minsa acts as a processor (Art. 28 GDPR), meaning it processes this data on behalf of the school and according to its instructions.

For data strictly related to running the service (accounts, the school's subscription, platform security), Minsa is the controller.

Contact: confidentialite@minsa.example.

2. Who this policy is for

It concerns everyone whose data is processed through Minsa: enrolled children, their parents and legal guardians, designated emergency contacts, school staff, and families applying for admission.

3. Data we process

Depending on how the school uses the service, the following categories may be processed:

  • Child identity and schooling: name, date of birth, class, enrolments, attendance, activities.
  • Health data (special category, Art. 9): allergies and medical notes, recorded for the child's safety.
  • Photographs and videos of the child, within the class album or the school's publications, where consent has been obtained.
  • Contacts: parents' and emergency contacts' details (name, phone, email) and relationship.
  • Exchanges: messages with the teaching team, absence or pick-up declarations.
  • Account and connection data: phone number, email, trusted devices, technical logs.
  • Admission data (applicant families) and staff data managed by the school.

The children concerned are minors (Art. 8 GDPR): their data receives heightened care, and rights are exercised by the holder of parental responsibility.

4. Purposes and legal bases

  • Supporting school life (records, attendance, communication): performance of the school's mission and legitimate interest in running the service.
  • Ensuring the child's safety (allergies, emergency contacts, check-in/out): protection of vital interests and voluntary provision of information by parents.
  • Publishing photographs (album, blog): on the basis of consent, which can be withdrawn at any time and per purpose.
  • Managing the school's subscription: performance of the contract and compliance with legal, notably accounting, obligations.
  • Ensuring the platform's security and preventing abuse: legitimate interest.

5. Who can access the data

Access is isolated per school and limited by role: school staff access the data needed for their duties, and each parent accesses their own child's data. Data is never sold, nor used for advertising or commercial profiling.

To deliver the service, Minsa relies on a small number of contractually bound sub-processors.

6. Transfers outside the European Union

The database, authentication and files (photos, documents) are hosted in the European Union. Some ancillary services — delivery of push notifications and subscription payment — may involve a transfer to providers located outside the EU. These transfers are framed by appropriate safeguards (standard contractual clauses or adequacy frameworks).

7. Retention periods

  • Child record: kept for the duration of the child's schooling at the school. Periods applicable after departure are being formalised by category.
  • Billing data: kept for the applicable legal accounting periods.
  • Unsuccessful admission applications: kept for a limited period, then deleted.
  • End of the relationship with a school: data enters a 30-day grace period, then is permanently deleted, files included.

8. Security

Minsa implements technical and organisational measures suited to the sensitivity of the data: per-school access isolation, EU data hosting, encryption of messaging, access to files only through temporary links issued after an authorisation check, and one-time-code authentication.

9. Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time for processing that relies on it (such as photographs).

As the child's data is the school's responsibility, send your request to your school, or write to us at confidentialite@minsa.example: we will forward it. You will receive a reply within one month. You may also lodge a complaint with the relevant supervisory authority (in France, the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07).

10. Children's data

Minsa processes data of minors under 15. This data is entered by the school or the parents, and the associated rights are exercised by the holder(s) of parental responsibility. Publishing a child's image requires consent, which can be withdrawn at any time.

11. Automated decisions

Minsa makes no decision producing legal effects based solely on automated processing, and does not carry out profiling of individuals.

12. Cookies

This website sets no analytics cookies or advertising trackers. Only cookies strictly necessary for its operation may be used, without requiring consent.

13. Changes

This policy may be updated to reflect changes to the service or regulations. The version in force is dated at the top of the page.

View the list of sub-processors.

Minsa

The platform for preschools — built around the protection of children's data.

Navigation

HomePricingSubscriptionContact

Legal

Privacy policySub-processorsTerms of useLegal notice
© 2026 Minsa. Data hosted in the European Union.