Security is at the heart of Amadoo.

Amadoo handles sensitive information about children, families and staff every day. Protecting that information is one of our core responsibilities, from infrastructure to application, storage and access control.

Certified & compliant

Independently certified against UK government-backed security standards and registered with the Information Commissioner’s Office.

Certified
Cyber Essentials

UK government-backed scheme, assessed by IASME. Verifies protection against common cyber threats.

Certificate No.:
9762700f-1097-43c0-b601-cf2592b6e2d3
Profile:
3.3 (Danzell)
Scope:
Whole organisation
Certified:
7 July 2026
Renewal due:
7 July 2027
Certifying body:
Fortify (IASME partner)
Registered
ICO Registered

Registered with the UK Information Commissioner’s Office for data protection under UK GDPR.

Registered entity:
Amadoo Ltd
Address:
14 Wanstead Lane, Ilford IG1 3SB, United Kingdom
Governance:
UK GDPR · Data Protection Act 2018

How we protect your data

Every layer of Amadoo is designed with security in mind, from the network edge to individual database rows.

Encryption everywhere

All customer data is encrypted at rest with AES-256 and in transit with TLS 1.2+. Authentication tokens are stored securely and rotated on every session.

UK & EU hosting

Amadoo runs on managed cloud infrastructure in secure UK and EU regions. Personal data is never transferred outside without appropriate safeguards.

Continuous backups

Encrypted PostgreSQL databases with automated daily backups and point-in-time recovery so nothing important is ever lost.

Role-based access

Row-level security at the database layer. Staff see only what their role allows, and parents only see records for their own children.

GDPR by design

Built to comply with UK GDPR and the Data Protection Act 2018. Each setting stays the Data Controller, and Amadoo processes data only on instruction.

Incident response

Continuous monitoring and a documented breach response plan. Affected customers and the ICO are notified within 72 hours where required.

Secure engineering

Peer-reviewed code, dependency scanning, input validation and OWASP-aligned protections shipped with every release.

Minimum access

Amadoo employee access to customer data is strictly limited, logged, and only granted for support or investigation with customer consent.

Payments powered by Stripe

Amadoo never stores card details on our servers. All payments and payouts are processed by Stripe, which is certified to PCI DSS Level 1, the highest level of certification available in the payments industry.

You stay in control of your data

Each setting using Amadoo remains the Data Controller for the child, parent and staff information they enter. We are the Data Processor, and we handle that information only in accordance with your documented instructions.

Questions about security?

Get in touch if you want to report a vulnerability, request a copy of our certification, or discuss anything security related. We aim to respond within 24 hours.

Email info@amadooapp.com

Amadoo Ltd · 14 Wanstead Lane, Ilford IG1 3SB · United Kingdom