COPPA Compliance Disclosure — Last updated: April 7, 2026
Graventis (Pvt) Ltd operates Genius Club(k12.graventis.org), an adaptive K-12 learning platform. We comply with the Children's Online Privacy Protection Act (COPPA), as amended effective April 22, 2026, and equivalent international regulations including GDPR Article 8, UK Age Appropriate Design Code, and Sri Lanka's Personal Data Protection Act (2022).
Operator: Graventis (Pvt) Ltd
Product: Genius Club (k12.graventis.org)
Privacy Contact: [email protected]
Mailing Address: Graventis (Pvt) Ltd, Colombo, Sri Lanka
For urgent child safety concerns, email [email protected] with subject line "URGENT: Child Safety".
Children under 18 cannot create accounts independently. A parent or legal guardian must:
No data is collected from a child until verifiable parental consent is obtained.
Parents may withdraw consent at any time via the Parent Dashboard → Settings → "Delete Child Data". Upon withdrawal, all child data is queued for deletion with a 48-hour cooling-off period, after which deletion is permanent and irreversible.
We practice strict data minimization. We collect only what is necessary for educational services:
Children's data is used exclusively for:
We NEVER use children's data for:
COPPA requires us to disclose every third party that receives children's personal information. Below is the complete list:
| Service | Purpose | Data Shared | COPPA Compliant |
|---|---|---|---|
| Microsoft Azure (Hosting) | Database hosting, application servers | All child data (encrypted at rest with TDE, encrypted in transit with TLS 1.3) | Yes — Azure COPPA DPA available |
| Cloudflare (Security) | DDoS protection, WAF, DNS | IP address (transient, not logged by Graventis), request headers | Yes — Cloudflare processes but does not store PII |
| Bunny CDN (Content) | Lesson images, educational media delivery | No PII — only serves static educational content files | N/A — no child data shared |
| Sentry (Error Monitoring) | Application error tracking (K12 instance isolated) | Error stack traces, device type, browser version. NO session replay, NO user identifiers, NO PII. | Yes — K12 Sentry project has session replay disabled |
| PayHere (Payments) | Parental consent verification (micro-charge) | Parent payment info only — NO child data is sent to PayHere | N/A — only parent data, not child data |
| Vercel (Deployment) | Frontend hosting and delivery | IP address (transient, server logs auto-deleted). No child PII in frontend code. | Yes — Vercel DPA available |
Services we do NOT use in Genius Club:
AI features in Genius Club are processed through our own AI Security Gateway, which strips PII before sending requests to AI providers. No identifiable child data reaches third-party AI services.
Parents and legal guardians have the right to:
Exercise these rights at: Parent Dashboard → Settings or email [email protected]
Genius Club follows WHO child screen time guidelines:
We will notify parents via email and in-app notification before making material changes to this privacy policy. Changes that expand data collection or sharing require renewed parental consent. Minor clarifications take effect upon posting.
For questions about children's privacy practices, data deletion requests, or to exercise parental rights:
Graventis (Pvt) Ltd
Email: [email protected]
Subject: "Children's Privacy — [Your Request]"
We respond to all privacy inquiries within 5 business days.