Privacy Policy
Last updated 9 September 2026
This policy explains what personal information Kidshive collects about children, their families, and staff; why we hold it; how long we keep it; and the rights you have over it. It covers both the Kidshive website and the Kidshive mobile app.
Who we are
Kidshive is an Ofsted-registered childcare setting (URN EY540826) and is the data controller for the information described in this policy. We are registered with the Information Commissioner's Office under registration number ZB524163.
For any question about this policy, or to exercise any of the rights described below, contact Shilpa Kheria at kidshive@outlook.com. Parents and carers already registered with the setting can also raise anything in person at handover.
The Kidshive app is a tool for childcare staff and for parents and guardians. It is not designed for or directed at children, and children do not hold accounts on it.
What information we hold
About children in our care
- Name, any name they are known by, date of birth, and a profile photograph.
- Home address, who the child lives with, and any school or other nursery they attend.
- Allergies, medical notes, immunisation status, dietary needs, and the details of their GP and health visitor.
- Emergency contacts — the name, phone number and address of people you nominate.
- Daily records of attendance, including check-in and check-out times and who collected the child.
- Daily care records: meals, naps, nappy changes and activities.
- Learning and development records: observations, EYFS progress reports, and the statutory progress check at age two.
- Records of accidents, incidents, existing injuries, and any medication administered.
- Photographs and videos taken during sessions, where consent has been given.
About parents, guardians and carers
- Name, email address, telephone number and postal address.
- Which children you are the guardian of, and your relationship to them.
- Whether you are the billing contact, together with invoices, payments and any funded-hours entitlement.
- Consents you have given or withdrawn, including the date and method they were recorded.
- Messages you exchange with the setting through the app.
- Signatures captured in the app for enrolment agreements, incident records and medication authorisations.
About staff
- Name, email address, telephone number, postal address and employment start date.
- DBS certificate number, application and clearance dates, and Ofsted suitability correspondence.
- Qualifications, including certificate details and expiry dates.
- Duty rota, hours worked, and records of unsupervised periods.
Technical information
- A description of the device you sign in from, so you can see and revoke your own active sessions.
- An audit log of changes made to records, showing who changed what and when. Where a record is edited, the previous value is retained in that log.
Health and other sensitive information
Information about a child's health — allergies, medical conditions, medication, immunisations, and details of their GP and health visitor — is 'special category data' under UK GDPR and is treated with additional care.
We hold it because we cannot safely care for a child without it: staff need to know about an allergy before offering food, and about a medical condition before responding to an emergency. Our lawful bases are Article 6(1)(c) and Article 9(2)(b) and (h) — compliance with our legal obligations under the Early Years Foundation Stage statutory framework, and the provision of care.
Access to this information within the app is limited to staff who need it for their role, and every access route is controlled by the permissions your setting configures.
Facial recognition
Kidshive is built to support an optional feature that would automatically recognise which children appear in a photograph, so that faces of children without photo consent can be blurred before the photo is shared.
This feature is currently switched off, and no facial recognition of any kind is performed. No biometric data is created, stored, or sent to any third party.
Facial recognition is biometric data under UK GDPR and would require your explicit, separate, opt-in consent for each child. We will not enable it without first asking you, and consent can be refused or withdrawn at any time without affecting your child’s place or care.
Photographs and video
Photographs are taken to record learning and to share moments of your child’s day with you. We rely on your consent, recorded per child, and you can change or withdraw it at any time through the app or by telling us.
Where a child does not have photo consent, the app is designed so their image is not shared beyond the record of their own care. Withdrawing consent stops future sharing; it does not by itself delete photographs already taken, though you can ask us to delete those too.
We do not publish photographs of children on social media or in marketing without asking you separately and specifically.
Why we hold it, and our lawful basis
- Legal obligation — the Early Years Foundation Stage statutory framework and Ofsted registration require us to keep records of attendance, safeguarding, accidents, medication and children’s development.
- Contract — to provide the childcare place you have agreed with us, to invoice you, and to administer funded hours.
- Legitimate interests — to run the setting safely and to communicate with you about your child’s day. We balance this against your rights and only rely on it where the processing is what you would reasonably expect.
- Consent — for photographs, and for any optional feature we ask you about separately. Where we rely on consent, you may withdraw it at any time.
- Vital interests — in a medical emergency, to protect someone’s life.
How we protect it
- All traffic between your device and our servers is encrypted in transit.
- Passwords are stored only as a strong one-way hash and can never be read back, by us or anyone else.
- Sign-in sessions can be revoked individually, so a lost or stolen device can be cut off immediately without changing your password.
- The mobile app locks itself after a period of inactivity and can be unlocked with a PIN or biometric, so records are not left open on an unattended phone.
- Photographs are stored in private cloud storage that is not publicly reachable; each request is authorised individually.
- What each member of staff can see and do is controlled by role-based permissions the setting configures.
- Changes to records are written to an audit log showing who made them and when.
How long we keep it
We keep records only as long as we need them, or as long as the law requires — which for a childcare setting is often well beyond the point a child leaves us. The periods below follow the recommended retention schedule for early years and childcare providers.
- Attendance registers, daily diaries, parental permission forms, contracts and funded-hours records: six years after the child leaves the setting.
- Accident and incident records, and any record of a reportable injury or dangerous occurrence: until the child reaches 25 years of age, as required by RIDDOR.
- Safeguarding and welfare records — including where a child was seriously injured, was on regular medication, had severe allergies or a serious illness: until the child reaches 25 years of age. This reflects the Limitation Act 1980, which allows someone to bring a claim up to three years after their 18th birthday, with a margin beyond that.
- Learning and development records: normally passed to you, or to the child’s next setting, when they leave.
- Invoices, payments and funding claims: six years plus the current financial year, for tax purposes.
- Staff records: for the duration of employment and a limited period afterwards. For DBS we record only the essential details — name, date of birth, certificate number, date of issue, and who obtained it — never a copy of the certificate itself, in line with the DBS code of practice.
- Photographs: while your consent stands, and deleted on request or when no longer needed.
When a retention period ends, records are deleted or securely destroyed. Because some of these periods are long, a record may still exist after your child has left us — that is a legal obligation on the setting, not a choice, and it is the reason some deletion requests cannot be met in full.
Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the personal information we hold about you or your child.
- Ask us to correct anything that is inaccurate or incomplete.
- Ask us to delete information, where we are not required to keep it.
- Ask us to restrict how we use it, or object to our using it.
- Ask for a copy in a portable, machine-readable format.
- Withdraw consent at any time, where we relied on consent.
Parents and guardians normally exercise these rights on behalf of a young child. Some rights are limited where we have a legal duty to keep a record — we cannot, for example, delete a safeguarding record on request.
To make a request, contact Shilpa Kheria at kidshive@outlook.com. We will respond within one month. There is normally no charge.
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113.
Changes to this policy
If we change how we use personal information — for example, if we ever switch on the facial recognition feature described above — we will update this policy and tell you directly rather than relying on you to notice.
This version took effect on 2026-09-09.