← Back to Idinu

Privacy Policy

Last updated 26 August 2026

Family building involves some of the most sensitive information a person can share. This policy explains exactly what we collect, why, how long we keep it, and the controls you have over it.

1. Who we are

Idinu operates a coordination platform connecting intended parents with pre-screened surrogates and donors. For the purposes of the UK GDPR and EU GDPR, Idinu is the data controller for the information described in this policy. You can reach our privacy team at privacy@idinu.com.

2. What we collect

  • Access request details — your name, email address, the role you identify with (intended parent, surrogate, donor, partner), your region, and anything you choose to write in the notes field.
  • Technical signals — a one-way hashed version of your IP address used solely to prevent abuse and spam. We do not store raw IP addresses with your record.
  • Product analytics — pseudonymised usage events (pages viewed, form interactions) used to understand how the site performs.

We do not collect medical records, genetic data, or clinical history through this website.

3. Why we use it (lawful bases)

  • Consent — to contact you about access to Idinu after you submit the access form. You may withdraw consent at any time.
  • Legitimate interests — to keep the service secure, prevent fraudulent or automated submissions, and improve the product through aggregate analytics.
  • Legal obligation — to retain limited records where regulation requires it.

4. Who can see your data

Access requests are stored in a locked database that is not readable from the public web. Only authorised Idinu team members with an authenticated admin account can review them. We never sell personal data, and we do not share your details with clinics, agencies, or matched parties without a separate, explicit opt-in from you.

We use a small number of processors under data processing agreements: our cloud database and hosting provider, and our product analytics provider.

5. International transfers

Data may be processed outside your country of residence. Where that happens, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

6. How long we keep it

Access requests are kept for up to 24 months from your last interaction with us, then deleted or irreversibly anonymised. Records tied to a completed erasure request are redacted immediately, retaining only a non-identifying audit entry.

7. Your rights

Wherever you live, we honour the full set of GDPR rights:

  • Access — get a copy of everything we hold about you.
  • Erasure — have your record deleted.
  • Rectification — correct anything inaccurate.
  • Restriction and objection — limit or object to how we use your data.
  • Portability — receive your data in a machine-readable format.
  • Withdraw consent — at any time, without affecting prior processing.

Use the data request page to exercise any of these. We respond within 30 days. If you are unhappy with our response, you have the right to complain to your local supervisory authority.

8. Security

Data is encrypted in transit and at rest. Direct public access to our database is fully revoked; every read and write passes through authenticated, rate-limited server code with origin verification. Admin access requires an individual account with an explicitly granted admin role.

9. Changes

If we make a material change to this policy we will update the date above and, where the change affects how we use data you have already given us, contact you directly.