Privacy Policy
We are committed to protecting your personal data. This policy explains what we collect, why we collect it, and how you can control it.
Introduction
BloomKidz is a digital platform that helps nurseries manage children, staff, and administrative tasks efficiently. We take your privacy seriously and are committed to protecting the personal data of everyone who uses our platform — including nursery owners, managers, educators, and the families of the children in your care.
This Privacy Policy applies to all users of www.bloomkidz.net and the BloomKidz application. By using our services, you agree to the collection and use of information in accordance with this policy.
BloomKidz operates in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have dedicated policies in place covering privacy, access control, data retention, individual rights, security, and breach notification.
Who We Are
BloomKidz Ltd is the data controller for personal data collected through www.bloomkidz.net and the BloomKidz platform. As data controller, we determine the purposes and means of processing your personal data.
Where BloomKidz processes data on behalf of a nursery (for example, data relating to children and families), the nursery acts as the data controller and BloomKidz acts as the data processor under a Data Processing Agreement.
BloomKidz Ltd · Registered in England & Wales · privacy@bloomkidz.net
Data We Collect
Depending on how you use BloomKidz, we may collect the following categories of personal data:
- Identity data: name, date of birth, gender, job title
- Contact data: email address, phone number, postal address
- Account data: username, password (hashed), account preferences
- Financial data: billing information, payment history (processed via secure third-party providers)
- Child data: name, date of birth, medical information, learning records, observations, photos (collected on behalf of nurseries)
- Technical data: IP address, browser type, operating system, device identifiers, website activity
- Usage data: how you interact with the platform, features used, session duration
- Marketing data: communication preferences and consent records
Child health data and special educational needs information is treated as special category data under UK GDPR and is subject to additional safeguards, including explicit consent and restricted access controls.
How We Collect Data
We collect personal data through the following means:
- Directly from you: when you register for an account, contact us, complete enquiry forms, respond to surveys, or opt in to marketing communications
- From nurseries: when nursery staff enter data about children, families, and staff members into the BloomKidz platform on behalf of their nursery
- Automatically: through cookies, server logs, and analytics tools when you visit our website or use the platform
- From third parties: such as identity verification services or marketing partners (where you have given consent)
How We Use Your Data
We use your personal data for the following purposes, always with a valid lawful basis under UK GDPR:
- To provide, operate, and improve the BloomKidz platform and services
- To create and manage your account and authenticate your identity
- To process payments and send billing communications
- To send service-related notifications (security alerts, product updates)
- To send marketing communications where you have given consent
- To conduct market research and analyse usage patterns to improve our product
- To comply with legal obligations and regulatory requirements
- To detect and prevent fraud, abuse, or security incidents
Data Security
We take the security of your data seriously and have implemented robust technical and organisational measures to protect it:
- AES-256 encryption for all data at rest on our servers
- TLS 1.3 encryption for all data in transit
- Role-based access control — staff can only access the data they need
- Two-factor authentication (2FA) available for all accounts
- Automated daily backups to geographically separate UK data centres
- Full audit logging of all data access and changes
- Regular internal security reviews and vulnerability assessments
- Formal procedures to detect, investigate, and notify data breaches
Despite our best efforts, no method of transmission over the internet is 100% secure. If you suspect any unauthorised access to your account, please contact us immediately at security@bloomkidz.net.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law, regulatory guidance, or contractual obligations.
- Account data: retained for the duration of your subscription plus 12 months after termination
- Child records: retained in line with Ofsted and statutory guidance — typically until the child reaches age 25 for safeguarding records
- Financial records: retained for 7 years in line with HMRC requirements
- Marketing data: retained until you withdraw consent or unsubscribe
- Technical logs: retained for up to 12 months for security and audit purposes
When data is no longer required, it is securely deleted or anonymised so it can no longer be linked to an individual.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@bloomkidz.net. We will respond within 30 days.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Cookies
BloomKidz uses cookies and similar technologies to improve your experience, analyse how the site is used, and personalise content. You can control your cookie preferences through our cookie consent banner or your browser settings.
- Essential cookies: required for the platform to function correctly — cannot be disabled
- Analytics cookies: help us understand how visitors interact with our website (e.g. Google Analytics)
- Functionality cookies: remember your preferences and settings across visits
- Marketing cookies: used to show you relevant adverts and measure campaign effectiveness
For full details, see our Cookie Policy.
Refund & Cancellation
- Annual contracts are billed monthly by direct debit. Early cancellation requires payment of the remaining months on the contract term.
- No refunds are provided for promotional offers, work already completed, administrative fees, or delays caused by third parties.
- To cancel your subscription, contact us at billing@bloomkidz.net with at least 30 days' notice.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will notify you by email or by displaying a prominent notice on the platform.
The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to raise a concern, please get in touch: