Last updated: 11 May 2026
1. Introduction and Our Roles
KINDERSTART LTD ("we", "our", or "us") is committed to protecting your privacy and ensuring the highest standards of data security for early years settings.
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, our legal role depends on the data being processed:
- As a Data Controller: We are the Data Controller for your direct account information (e.g., your name, subscription billing details, and your business contact info).
- As a Data Processor: When you use the KinderStart app to log information about the children in your care (e.g., attendance, EYFS observations, parent details, and safeguarding logs), you are the Data Controller. We act strictly as your Data Processor, processing this highly sensitive information solely on your instructions to provide the Service to you.
1.2 Data Processing Agreement (DPA)
By creating a KinderStart account and using our Services to process personal data relating to children and parents, you are entering into a legally binding Data Processing Agreement with us. This Privacy Policy, combined with our Terms of Service, forms the complete DPA required by Article 28 of the UK GDPR, legally binding us to protect your data.
2. Information We Collect
2.1 Information You Provide
We collect information that you provide directly to us, including:
- Account Information: Name, email address, password
- Profile Information: Target launch date, registration progress
- Application Data: Certificate numbers, expiry dates, training records, DBS check details
- Documents: Uploaded policies, certificates, and other registration documents
- Communications: Messages you send us via email or contact forms
- Client Data (Processed on your behalf): To provide our childcare management tools, we host data entered by you regarding the children in your care. This includes children's names, dates of birth, EYFS developmental progress, dietary/medical requirements, attendance records, safeguarding logs, parent/carer contact details, and photographs taken within the setting.
2.2 Automatically Collected Information
When you use our Service, we automatically collect:
- Usage Data: Pages visited, features used, time spent on pages
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, referring URLs
- Cookies: See our Cookie Policy for details
3. How We Use Your Information
3.1 Artificial Intelligence (AI) Processing
KinderStart provides AI-assisted tools (such as the receipt scanner or observation assistant) to reduce your administrative burden.
- All AI processing is conducted via secure, enterprise-level APIs.
- Zero Training Policy: We have strict contractual guarantees in place ensuring that no personal data, child data, or photographs entered into KinderStart are ever used to train public or third-party AI models. Data processed by our AI tools is not retained by the AI provider after the immediate request is fulfilled.
3.2 General Data Use
We use your information for the following purposes:
- Provide Services: To create and manage your account, track your registration progress, and provide guidance
- Communication: To send you service updates, daily inspection questions, and important notifications
- Improvement: To analyse usage patterns and improve our Service
- Security: To protect against fraud, unauthorized access, and security threats
- Legal Compliance: To comply with legal obligations and enforce our Terms of Service
Legal Basis (UK GDPR):
- Contract Performance: Processing necessary to provide our services
- Legitimate Interests: Improving our services, security, and fraud prevention
- Consent: Marketing communications (where applicable)
- Legal Obligation: Compliance with laws and regulations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Service Providers: AWS (hosting), Cloudflare (CDN), authentication services
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, sale, or acquisition
All third-party service providers are required to maintain appropriate security measures and use your data only as instructed.
5. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations:
- Account Data: Until you delete your account, plus 30 days
- Documents: Until you delete them or close your account
- Usage Logs: 90 days
- Legal Records: As required by law (typically 6-7 years)
- Children's and Parents' Data: Because you (the childminder) are the Data Controller, you determine the retention periods for the children in your care (e.g., retaining safeguarding records until a child reaches 21, as per your own setting's policies). KinderStart provides you with the tools to securely export this data for your archives and permanently delete child profiles from our active servers at your discretion. If you cancel your KinderStart subscription, all Client Data is securely and permanently wiped from our systems after 30 days.
6. Your Rights (UK GDPR)
Under UK GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for marketing communications
To exercise these rights, including requesting a full data dump (Data Access Request) or the permanent deletion of your account and all associated information (Right to Erasure), please contact us at [email protected]
For security purposes, we will verify your identity before fulfilling any data-related requests.
7. Data Security and Safeguarding Compliance
We implement enterprise-grade technical and organisational measures to protect your data, specifically designed to help you meet Ofsted and EYFS safeguarding requirements:
- Secure Infrastructure: All data and files are hosted securely on Amazon Web Services (AWS) using S3 and DynamoDB, which hold rigorous ISO 27001 security certifications.
- Encryption: All data is encrypted in transit (HTTPS/TLS) and at rest.
- Two-Factor Authentication (2FA): Access to the app is secured using your device's hardware-level security (e.g., FaceID, TouchID, or passcode).
- EYFS Device Compliance (In-App Camera): To comply with strict EYFS regulations regarding personal devices, any photographs taken using the KinderStart app are uploaded directly to our secure cloud and are never saved to your personal device's local camera roll.
- Breach Protocol: In the highly unlikely event of a data breach, we have a strict incident response protocol and will notify you (the Data Controller) without undue delay, well within the ICO's 72-hour mandate, allowing you to fulfill your own regulatory obligations.
8. Data Hosting and Location
All personal data, including child records and photographs, is stored on secure AWS servers physically located within the United Kingdom. Your data does not leave the UK regulatory zone, ensuring full compliance with UK data sovereignty laws.
9. Children's Privacy
Our Service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service. Continued use after changes constitutes acceptance.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):