Privacy Policy
How we handle your data at FamiID
Last updated: May 8, 2026
1. Data controller
The controller of your personal data is Glenlake Soft, S.L. ("Glenlake Soft", "we" or "FamiID"), with registered office at Calle Haya 9, 41927 Mairena del Aljarafe, Seville (Spain), recorded in the corresponding Commercial Registry. You can contact us at privacy@famiid.com.
2. What FamiID is and how it relates to other Fami apps
FamiID is the identity and single sign-on system of the Fami ecosystem operated by Glenlake Soft. Your FamiID account lets you sign in with the same credentials to the different applications of the ecosystem, including famieduca.com, famicalendar.com, famibooks.com, famimovies.com, famitravels.com, famigame.com and famichef.com and famigastro.com, as well as future apps in the ecosystem.
Glenlake Soft acts as data controller for the identity, authentication and family-profile data managed through FamiID. Each Fami app additionally processes service-specific data under its own privacy policy, available within that app.
3. Personal data we process
- Account data: first name, last name, email address, hashed password and internal identifier.
- Authentication data: session tokens, last sign-in date and time, IP address and browser user agent.
- Family profile (optional): family name, members, preferred language, and the name and year of birth of children when you choose to add them. We do not request specially sensitive data about minors.
- Social sign-in data (if used): identifier, name, profile picture and email provided by the provider (e.g. Google).
- Subscription and billing data: subscribed plan, subscription status and data needed to issue invoices. Card numbers never go through our servers — they are processed directly by our payment provider.
- Technical and usage data: access logs, errors, security events and basic service-usage metrics.
4. Purposes and legal bases
- Create and manage your FamiID account and let you sign in to Fami ecosystem apps — performance of the contract (Art. 6.1.b GDPR).
- Ensure security of the service, prevent fraud and abuse — legitimate interest (Art. 6.1.f GDPR).
- Billing and accounting obligations — compliance with legal obligations (Art. 6.1.c GDPR).
- Personalise the family experience (age-based recommendations, child content) when you complete your family profile — consent (Art. 6.1.a GDPR), withdrawable at any time.
- Service communications (security notices, term changes) — performance of the contract.
- Commercial communications about the Fami ecosystem — only with your consent, withdrawable at any time.
5. Recipients and international transfers
We share data only with processors that provide services to us under contract and with safeguards equivalent to those required by the GDPR: infrastructure and database provider (Supabase / AWS EU), transactional email provider, payment gateway, and internal support and analytics tools.
When any of these providers process data outside the European Economic Area, we ensure an adequacy decision is in place or, failing that, the Standard Contractual Clauses approved by the European Commission, together with the necessary supplementary measures.
We also share the strictly necessary minimum data with the Fami app you choose to access via FamiID (for example, your identifier and email address), solely to authenticate you in that app.
6. Retention period
We keep your data while your FamiID account is active. If you request deletion, we erase or anonymise your data within a maximum of 30 days, except for data we must keep for legal obligations (for example, billing data for the period set out by applicable tax and commercial regulations, generally 6 years).
7. Your rights
As a data subject you can exercise at any time the rights of access, rectification, erasure, restriction of processing, objection, portability and not to be subject to automated decisions. You may also withdraw your consent at any time, without affecting the lawfulness of prior processing.
To exercise them, write to privacy@famiid.com indicating the right you wish to exercise. If you consider that we have not properly addressed your request, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Minors
FamiID is intended for adults who create and manage the family account. Minors cannot register independently. Information about children that you choose to add to your family profile is provided under your responsibility as parent or legal guardian and is limited to non-sensitive data (name and year of birth) for personalisation purposes.
9. Cookies and similar technologies
We use only technical cookies necessary to maintain your session and ensure service security. If we add analytics or marketing cookies in the future, we will request specific consent through a banner.
10. Changes to this policy
We may update this policy to reflect service improvements or regulatory changes. We will inform you with reasonable notice of any substantial change, by email or through a notice on the platform itself.