LEGAL & POLICIES
Privacy and Cookie Policy
Privacy & Cookie Policy
How we collect and use your personal data
Version 1.0
Effective date: 5.10.2026
Who we are
DIOUM LTD (“Dioum”, “we”, “us” or “our”) respects your privacy and takes the protection of your personal data seriously. This policy explains how we collect and use your personal data when you use our digital marketplace and community platform for parents and families, and the rights you have. It should be read alongside our User Terms and Conditions, Provider Terms and Conditions, Online Shop Terms and Conditions, Offline Shop Terms and Conditions, Services and Events Terms and Conditions, Community Guidelines, Acceptable Use Policy and Refunds, Returns and Cancellation Policy, as applicable. We are the controller of the personal data we hold about you, except where this policy explains that another organisation acts as a controller, for example a payment provider or a provider using the platform for its own services.
We operate a digital marketplace and community platform for parents and families in England and the wider UK. The platform may include a product marketplace, services and bookings, children’s activities, classes and clubs, events and ticketing, local discovery and map features, user profiles, child profiles, messaging, reviews, provider dashboards and community interactions. We are a company registered in England and Wales under company number 17094552, with our registered office at 124-128 City Road, London, England, EC1V 2NX.
ICO registration number: CSN8873517. You can contact us using the details in section 16.
What this policy covers
This policy applies to adult account holders, including parents, carers and other users of Dioum, to children whose details are managed by a parent or carer, to providers, sellers, activity organisers and businesses who use the platform, to people who contact us, and to visitors to our website, app or online services. Dioum accounts are for people aged 18 or over. Separate contractual terms may also apply to your use of Dioum, including the User Terms and Conditions for users and the Provider Terms and Conditions for providers, sellers and organisers. Our platform may link to other websites or services. We are not responsible for how those organisations handle your data, so please read their own privacy policies.
The personal data we collect
Depending on how you use Dioum, we may collect:
account, identity and contact details, such as your name, email address, telephone number, login details and account preferences;
parent and user profile information, such as household preferences, interests, saved places, favourites, reviews, messages, community posts and other content you choose to add;
limited child profile information that a parent or carer chooses to provide through supported fields, such as a child’s name and age or date of birth. Please do not put health, medical, allergy, safeguarding or other special category data in general free-text fields, ordinary messages or public content. Where such information is necessary for a drop-off activity, provide it directly to the provider through its approved registration process;
provider, seller and business information, such as business names, contact details, dashboard users, listings, availability, pricing, booking information, verification information and payment or payout details;
We may also collect booking, order and payment information, payment-provider identifiers, messages and communications, reviews and user-generated content, photos, videos, audio or voice recordings that you upload, location or map information including approximate or precise geolocation where you enable it, technical data such as device, browser, IP address and usage data, and cookie or similar technology data, including information needed to administer refunds, returns, cancellations, disputes and related support under our Refunds, Returns and Cancellation Policy. For providers, sellers and organisers, we may also collect onboarding information where required, such as identity documents, DBS check information, safeguarding policies, qualifications, licences, training, insurance and product safety documentation. We minimise the information we hold. Providers are responsible for obtaining their own registration information, parental authority or consent, safeguarding and emergency details and any necessary health information for drop-off activities through their own appropriate forms and privacy arrangements. We may exceptionally process health or other special category data where reasonably necessary and lawful to manage an incident, dispute or safeguarding concern.
How we collect your data
We collect most of your data directly from you, for example when you create an account, add a parent or child profile, make a booking or order, request or receive a refund, return or cancellation, list a product or service, message another user, leave a review, upload content, enable location features, use cookies or contact us. We may also receive data from providers, sellers, payment providers, verification providers, analytics providers, support tools, or another user who makes a booking, order, refund, return, cancellation or enquiry involving you or a child profile you manage.
How we use your data and our lawful basis
The law requires us to have a lawful basis for using your personal data. The table below explains how we use it and the basis we rely on. Where we process special category data, we identify and rely on an applicable condition under Article 9 of the UK GDPR, which may include explicit consent or, where relevant, conditions concerning legal claims, vital interests or substantial public interest as provided by law.
What we do
Data we use
Our lawful basis
Creating and managing your Dioum account, profiles and dashboard
Identity, contact, account, parent/user profile, provider and business data
Performing our contract with you under the applicable User Terms and Conditions or Provider Terms and Conditions, and our legitimate interests in operating the platform
Processing bookings, orders, event tickets, payments, payouts, refunds, returns and cancellations, including through payment providers and in accordance with our Refunds, Returns and Cancellation Policy
Identity, contact, booking, order, payment, payout, refund, return, cancellation, dispute and transaction information. Full card details are handled by the relevant payment provider where it processes the payment
Performing our contract with you under the applicable User Terms and Conditions or Provider Terms and Conditions, complying with legal obligations, and our legitimate interests. A payment provider may act as an independent controller for some payment processing
Managing limited child profiles and relevant booking information
Child name and age or date of birth provided by a parent or carer through supported fields; exceptional incident, dispute or safeguarding information where necessary
Performing our contract under the applicable User Terms and Conditions, our legitimate interests in administering bookings and safety matters, and, for any special category data, an applicable Article 9 condition such as explicit consent, legal claims, vital interests or substantial public interest as provided by law
Providing messaging, reviews, community features, local discovery, maps and user-generated content
Account data, messages, reviews, content, photos, videos, audio, location data and technical data
Performing our contract under the applicable User Terms and Conditions or Provider Terms and Conditions, our legitimate interests in operating and improving the platform, and consent for optional location or promotional features where required
Keeping the platform secure, carrying out provider onboarding checks where applicable, preventing misuse, complying with law, safeguarding users and responding to complaints or legal claims
Account, technical, usage, verification, communications, safety, transaction and support information
Complying with legal obligations and our legitimate interests; where special category data is involved, legal claims, vital interests or substantial public interest conditions as applicable
Where we rely on legitimate interests, we have considered your interests and rights and are satisfied that our use of your data does not override them. You can ask us for more information about this. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. We may use limited profiling or preferences to support matching, local discovery, moderation, administration, quality assurance and to show relevant listings, local results, reminders, recommendations or safety prompts, but you can contact us if you have questions about this.
Children’s data and sensitive information
Dioum is designed for parents and families, but accounts must be created and managed by adults aged 18 or over. A parent or carer may manage limited child information and must only provide information where they have authority to do so. We limit routine child-profile data collected through Dioum to the child’s name and age or date of birth. Do not put health, medical, allergy, safeguarding or other special category data in general free-text fields, ordinary messages or public content. For parent-and-child activities, the responsible adult remains with the child. For drop-off activities, the provider must obtain its own registration information, parental authority or consent, safeguarding and emergency details and any necessary health information through its approved forms and under its own privacy arrangements. The provider acts as an independent controller of information it collects or receives for its service. Parents and carers can update or remove supported child profile information in their account or by contacting us. We may exceptionally receive or process sensitive information where reasonably necessary and lawful to handle an incident, dispute, legal claim or safeguarding concern, applying an appropriate Article 9 condition and data-minimisation measures.
Dioum operates as a platform that connects parents and families with providers, sellers and organisers; it is not itself the provider of the underlying activities, classes, clubs, events, products or services. You are responsible for the information you choose to share through Dioum. To the fullest extent permitted by law, Dioum is not responsible or liable for any health, medical, allergy, safeguarding or other special category or sensitive information that a user chooses to submit through general free-text or additional information fields, ordinary messages or public content contrary to this policy, and any such information is provided at the user’s own risk.
Marketing and promotional content
We may contact you with information about Dioum, family activities, providers, offers, events, product updates or services that may interest you. We will follow the rules on electronic marketing in the Privacy and Electronic Communications Regulations 2003. Where consent is required, including for certain promotional content, email marketing, SMS, push notifications or marketing cookies, we will ask for it first. Separately, we will only use photographs, video or voice recordings that feature you or, where you have parental responsibility, your child (Media Content) for external advertising, marketing or promotional purposes where you have given your express, informed and freely-given consent, which you can withdraw at any time. You can ask us to stop at any time by using the unsubscribe link, changing your settings or contacting us. We will not pass your details to other organisations for their own marketing without your consent.
Who we share your data with
We share your data only where we need to operate Dioum, keep people safe, comply with the law or provide services you request. This may include sharing:
with providers, sellers, activity organisers, venues and businesses where needed to handle enquiries, bookings, orders, attendance, customer support, safety, cancellations, refunds, returns, disputes or service delivery under the applicable User Terms and Conditions, Provider Terms and Conditions and Refunds, Returns and Cancellation Policy; these recipients ordinarily act as independent controllers of the information they receive and are responsible for their own lawful basis, privacy information, retention and handling of data for the relevant booking, order or service;
with service providers who help us run the platform, host data, provide analytics, customer support, email, messaging, maps, notifications, security, verification, payments and other operational services, who process your data under appropriate data protection terms and our instructions as processors acting on our behalf;
with payment and verification providers used to process payments, payouts, refunds, returns, cancellations, fraud checks, onboarding and provider checks, including where needed under our Refunds, Returns and Cancellation Policy. Those providers may act as our processors or as independent controllers, depending on the service and applicable law;
where necessary for safeguarding, safety, fraud prevention, platform integrity, emergency support, law enforcement requests, regulatory requirements, legal claims, or with a buyer if we sell or reorganise our business, who may continue to use your data as described in this policy.
We do not sell your personal data. Public or community features, such as reviews, profile information, listings, photos, videos, audio, posts or comments, may be visible to other users depending on your settings and the feature you use. Copies of messages and community content may be stored. We do not routinely conduct unrestricted monitoring of private messages. Authorised personnel may access messages only where reasonably necessary and proportionate to handle complaints or disputes, safeguarding concerns, fraud or security issues, reported-content moderation, legal compliance or claims. We apply role-based access controls and logging where appropriate, and will provide transparency or notification unless doing so would be inappropriate, prejudice the relevant purpose or be legally restricted.
Sending data outside the UK
We and our service providers may store or process personal data in the United Kingdom or other countries. Where personal data is transferred outside the United Kingdom to a country not covered by UK adequacy regulations, we use an appropriate safeguard recognised under UK data protection law, such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with supplementary measures where required. You can ask us for more detail about relevant transfers and safeguards.
How long we keep your data
We keep personal data only for as long as necessary for the purpose for which it was collected, taking account of legal, regulatory, tax, accounting, safety, fraud-prevention and claims requirements. Account and profile data is generally kept while the account is active and for a reasonable period afterwards to close the account and address queries or claims. Booking, order, refund, return, cancellation and support records are kept for the relevant transaction and an appropriate period afterwards. Messages, reviews and community content are kept according to operational, safety, moderation and dispute needs, including whether content remains published. Provider onboarding and verification records are kept while relevant to the provider relationship and for an appropriate period afterwards. Financial, tax and transaction records are generally kept for six years where required. Limited child profile information is kept only while needed for the account or relevant booking, while incident or safeguarding records may be kept longer where necessary and lawful. We securely delete or anonymise data when it is no longer required. You can ask us for more detail about our retention criteria.
Your rights
Under data protection law you have the following rights, which we will always work to uphold:
the right to be informed about how we use your data;
the right to access the data we hold about you;
the right to have inaccurate data corrected;
the right to have your data erased in certain circumstances;
the right to restrict how we use your data;
the right to object to our use of your data;
the right to data portability; and
the right to withdraw your consent at any time, where we rely on consent.
These rights may be limited in some situations, for example where we need to keep information for legal, safety, safeguarding, fraud prevention, refunds, returns, cancellations or dispute reasons. To exercise any of your rights, withdraw consent or ask a question about a child profile, please contact us using the details in section 16.
How to access your data
You can ask us for a copy of the personal data we hold about you. This is called a subject access request. There is normally no charge. We will respond within one month. We may ask you to confirm your identity, or to help us understand what you are looking for, in which case the time may be paused until you reply. If your request is complex, we may extend the time by up to two further months, and we will tell you if we do.
Complaints
If you are unhappy with how we have handled your personal data, please contact us first, using the details in section 16, so that we can try to put things right. You also have the right to complain to the Information Commissioner’s Office. Its website is ico.org.uk and its helpline is 0303 123 1113. We would, though, welcome the chance to resolve your concerns ourselves first.
Cookies and similar technologies
Our website, app and online services may use cookies and similar technologies, such as local storage, pixels, SDKs and device identifiers. Strictly necessary technologies make Dioum work, keep accounts secure, remember basket, booking, order, refund, return, cancellation, login or consent choices, process payments and provide core platform features. Preference technologies remember choices such as region, map settings or saved preferences. Analytics technologies help us understand how people use Dioum and improve the platform. Marketing technologies may measure campaigns or support relevant promotional content. We use strictly necessary technologies, and any preference technology that is exempt because it is necessary to provide a feature you request, without consent where the law permits. We use non-essential preference, analytics and marketing technologies only where allowed by law and, where required, after obtaining consent through the cookie prompt or settings. You can withdraw consent or object where applicable at any time by changing your settings, and can also control cookies through your browser settings, though Dioum may not work fully if you block necessary technologies.
Changes to this policy
We may update this policy from time to time, for example if the law changes or we change how Dioum works. Any changes will be posted on our website, app or online services, and we recommend that you check the policy from time to time. This policy was last updated on 5.10.26.
How to contact us
For anything to do with your personal data, including to make a request or a complaint, please contact:
DIOUM LTD
124-128 City Road, London, England, EC1V 2NX
Email: support@dioumapp.com
© 2026 DIOUM. All rights reserved.