Privacy and consent questions for family-communication platforms
8 min read · Last reviewed July 25, 2026
If a platform will hold everyday information about people who are supported — often people who cannot always advocate for themselves — the privacy questions are not a formality. This guide is a checklist of what to ask, whether you are evaluating KinDock or anything else.
None of this is legal advice. Treat it as a starting point for the conversation you should have with your own privacy and legal advisors.
Who can see what?
Ask how the tool separates home-wide content from one person's private content, and whether a family connected to one person can ever see another person's information. The answer should be a firm no, enforced by the system rather than left to staff diligence.
How is staff access controlled?
Employment should not grant universal access. Ask whether staff access to a person's private information depends on an explicit assignment, whether it can be time-limited for relief cover, and whether it ends promptly when an assignment does.
How is consent handled?
- Can consent be recorded per person and per type of sharing?
- Can it be changed or withdrawn, and does withdrawal take effect immediately?
- Can you record that formal consent is held in your own process, with a reference?
- Is the person supported treated as a participant in their own consent?
What about photos and exports?
Ask how group photos are handled and whether home-wide sharing respects each person's consent. Ask how data can be exported or removed if you leave, and in what form.
The ability to get your organization's data out, cleanly, is part of good stewardship — not a sign you plan to leave.
Is there an audit trail?
For accountability, sensitive actions — invitations, access changes, consent decisions, content changes — should be recorded in a history that cannot be edited. Ask who can see it and whether it is genuinely tamper-evident.
Where does the data live, and for how long?
Ask where data is hosted and which subprocessors are involved, especially whether anything is processed outside your country if that matters to you. Ask about retention and deletion — whether they are configurable, and whether deletion preserves audit integrity.
KinDock's answers to these questions are set out on our Security & Privacy page, including our subprocessors and Canadian hosting for the database. We aim to state what is true and label what is planned, rather than overclaim.
Key takeaways
- Person-to-person privacy should be enforced by the system, not staff memory.
- Staff access should follow explicit, time-boundable assignments.
- Consent should be recordable, changeable, and immediate on withdrawal.
- Look for an uneditable audit trail, clear data residency, and clean export.
