TreeTipi helps families build a shared family tree online. Doing that means handling personal data: yours, and often that of the relatives you add. This policy explains what we collect, why, who receives it, how long we keep it and which rights you have. It applies to the website treetipi.com and to the TreeTipi application, including the emails we send.
We process personal data in line with the EU General Data Protection Regulation (GDPR), the UK GDPR where it applies, and the Australian Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs).
1. Who is responsible
The controller (the company responsible for your personal data) is:
Done Digital Pty Ltd
Level 6, 123 Eagle Street
Brisbane QLD 4000, Australia
ACN 683 177 282 · ABN 84 683 177 282
Email: hello@donedigital.au
Phone: +61 7 4429 3663
For any question about this policy or your data, write to hello@donedigital.au or use our contact form. Full company details are in the imprint.
2. Who this policy is for
- Visitors who read the website without an account.
- Members who create an account and build or join a family tree.
- Invited people who receive an invitation or share link from a member.
- People in a tree whose details a member has added, whether or not they use TreeTipi themselves.
If you are in a tree but have no account, the member who added you decides what is recorded. You can nevertheless exercise every right in section 11 directly with us.
3. Data we process, and why
3.1 Visiting the website
When you open a page, our servers automatically receive technical data: your IP address, the date and time, the page requested, the referring page, and your browser and operating system. This is needed to deliver the page, to keep the service secure and to diagnose faults. Server logs are kept for a limited period for security purposes and are then deleted or anonymised.
Legal basis: Art. 6 (1) (f) GDPR – our legitimate interest in providing a secure, working website.
3.2 Your account
To use TreeTipi you create an account with your first name, last name and email address and set a password. Passwords are stored only as a salted hash. We record when you registered and activated your account, and you may add a profile photo. Your name is shown to the other members of the trees you belong to.
Legal basis: Art. 6 (1) (b) GDPR – performing our agreement with you.
3.3 Family tree content
Members add people to a tree together with details such as names, gender, dates and places of birth and death, places lived, occupations, biographies, photos, relationships between people, and optionally contact details and private notes. Much of this concerns other people: living relatives who may or may not have an account, and people who have died. We store and display this content so that the members of the tree can see and edit it, keep a history of changes, and show recent activity to members.
We do not check or verify this content and do not use it for any purpose of our own, such as advertising, profiling or training models. Members are responsible for what they add. Please only add information about living people that they would reasonably expect to be shared within the family, and do not record particularly sensitive information (for example health, religion, ethnic origin or sexual orientation) about a living person without that person's clear agreement. Private notes are visible only to the member who wrote them.
Legal basis: Art. 6 (1) (b) GDPR for the member's own data; Art. 6 (1) (f) GDPR for data about other people – the legitimate interest of the family in documenting its own history, weighed against the interests of the people concerned. Where a member obtains consent from a relative, Art. 6 (1) (a) GDPR applies. Data about deceased persons is not personal data under the GDPR but we treat it with the same care.
3.4 Invitations and share links
A member can invite someone to a tree by email. We store the invitee's email address, the intended role and a token until the invitation is accepted or expires, and we send one invitation email. A member can also create a share link; anyone who has that link can view the tree with the permissions the member chose. Members should share links only with people they trust and can revoke them at any time.
Legal basis: Art. 6 (1) (b) GDPR towards the member; Art. 6 (1) (f) GDPR towards the invitee – the member's interest in inviting their family.
3.5 Notifications
Members see recent changes to their trees inside TreeTipi and may receive a summary of that activity by email (for example when a new person is added or a relative joins). You can ask us to stop these emails at any time; emails needed to run your account, such as password resets, are still sent.
Legal basis: Art. 6 (1) (b) and (f) GDPR.
3.6 Contact form and email
When you use the contact form or write to us, we process your name, email address, the subject and your message, together with the time it was sent, in order to answer you. The message is delivered to our mailbox through the email service described in section 5. We keep the correspondence for as long as it is needed to deal with your request and for any follow-up, unless a legal retention obligation requires longer.
Legal basis: Art. 6 (1) (b) GDPR where your message relates to an agreement with us, otherwise Art. 6 (1) (f) GDPR – our interest in answering enquiries.
4. Cookies
TreeTipi uses only cookies that are strictly necessary to run the service. We do not use analytics, advertising or tracking cookies, and we do not embed social media plugins. Because only essential cookies are set, no consent banner is shown.
| Cookie | Purpose | Duration |
|---|---|---|
wordpress_test_cookie | Checks whether your browser accepts cookies when you sign in. | Session |
wordpress_sec_*, wordpress_logged_in_* | Keep you signed in and protect your session. | Session, or up to 14 days when you choose to stay signed in |
wp-settings-*, wp-settings-time-* | Remember interface preferences for signed-in members. | 1 year |
You can delete or block cookies in your browser settings. Blocking the cookies above means you cannot stay signed in.
Legal basis: Art. 6 (1) (b) and (f) GDPR; section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) for strictly necessary storage.
5. Service providers and other recipients
We share personal data only with the providers we need to run TreeTipi, and only to the extent necessary:
- Hosting and content delivery. The website and application, including all family tree content and photos, are hosted by Done Digital Pty Ltd on servers located in Singapore. Static files are delivered through a content delivery network (CDN) that caches them at locations close to you and processes your IP address for that purpose and to defend against attacks.
- Transactional email. Emails such as account activation, password resets, invitations, notifications and contact form messages are sent either directly from our server or through Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France), which processes the recipient address, name, message content and delivery data on our behalf under a data processing agreement.
- Web fonts. The site loads the "Fraunces" typeface from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). When a page is displayed your browser connects to Google's servers and transmits your IP address. Google's privacy policy: policies.google.com/privacy. Legal basis: Art. 6 (1) (f) GDPR – a consistent, fast display of the website.
- Professional advisers and authorities. Where required by law, to protect our rights or to respond to lawful requests from public authorities.
We do not sell personal data and we do not show advertising.
6. International transfers
Done Digital Pty Ltd is based in Australia and our servers are in Singapore. Neither country is covered by an EU adequacy decision. When personal data of people in the EU/EEA, the United Kingdom or Switzerland is transferred to us or to our providers outside those areas, we rely on the standard contractual clauses approved by the European Commission (Art. 46 (2) (c) GDPR) and equivalent UK and Swiss instruments, together with additional technical measures such as encryption in transit and at rest. Where a transfer is necessary to perform our agreement with you, Art. 49 (1) (b) GDPR also applies. You can request a copy of the safeguards we use at the address above.
7. How long we keep data
- Account data is kept while your account exists. When you delete your account, or ask us to, we delete it within 30 days; copies in encrypted backups are overwritten within a further 30 days.
- Family tree content is kept while the tree exists. Content that was removed can be restored from the change history by members for a limited time and is then deleted. When the last member leaves a tree or asks us to delete it, the tree and its photos are deleted in the same way as account data.
- Invitations are deleted when accepted, declined or expired.
- Server logs are kept for a limited period for security purposes.
- Correspondence is kept as long as needed to deal with your request and any follow-up.
Where the law requires us to keep records for longer (for example tax and accounting records), we keep them for that period only.
8. Children
TreeTipi is intended for adults. Accounts may not be created by anyone under 16 years of age (or the age of digital consent in your country, if different) without the permission of a parent or guardian. Members may add children to a tree as part of the family, but should think carefully about what they record. If you believe a child has created an account without permission, please contact us and we will remove it.
9. Security
All traffic between your browser and TreeTipi is encrypted (TLS). Passwords are hashed, access to trees is limited to their members and to holders of a share link, and our systems are kept up to date and monitored. Rate limits and server-side checks protect the sign-up, login and contact forms against abuse. No online service can be completely secure, so please choose a strong, unique password and keep share links private.
10. Automated decisions
We make no decisions about you based solely on automated processing, and we do not profile you.
11. Your rights
Under the GDPR and comparable laws you can, at any time and free of charge:
- Access the personal data we hold about you and receive a copy (Art. 15 GDPR).
- Correct inaccurate or incomplete data (Art. 16 GDPR). Members can edit most of their data directly in TreeTipi.
- Delete your data (Art. 17 GDPR), including your account and, subject to the rights of other members, content about you in a tree.
- Restrict processing (Art. 18 GDPR).
- Receive your data in a portable, machine-readable format (Art. 20 GDPR).
- Object to processing based on legitimate interests, in particular to being recorded in a family tree (Art. 21 GDPR). We will then stop unless we can show compelling legitimate grounds.
- Withdraw consent you have given, with effect for the future (Art. 7 (3) GDPR).
- Complain to a data protection authority, in particular in the EU member state where you live or work. A list of EU authorities is published at edpb.europa.eu.
If you are in Australia, you may access and correct the personal information we hold about you under the Australian Privacy Principles, and complain to us first and then to the Office of the Australian Information Commissioner (oaic.gov.au) if you are not satisfied with our response. We answer every request within 30 days.
To exercise any right, email hello@donedigital.au. We may ask you to confirm your identity so that we do not disclose data to the wrong person.
12. Changes to this policy
We update this policy when the service or the law changes. The date at the top shows the current version. For significant changes we notify members by email or inside TreeTipi.
