Privacy Policy
Last updated 5 October 2026
In short: nurseries own the information they keep in ChildHive about children, families and staff. We look after it for them, only use it to run the service, never sell it and never use it for advertising. Database records are stored in Ireland, and you can ask us about your data at any time.
1. Who we are
ChildHive is nursery management software provided by Forest Village Kindergarten Ltd, trading as ChildHive, registered in England and Wales with company number 11187620, whose registered office is at 25a Faversham Road, Morden, England, SM4 6RE. We are registered with the Information Commissioner's Office (ICO) under number ZA189925.
If you have any question about this policy or your data, message us on WhatsApp on +44 7445 396443 or write to us at the address above.
2. Who this policy covers
- Nurseries using ChildHive (our customers) and the people who run them.
- Nursery staff who sign in to ChildHive.
- Parents and carers who use the parent app, view invoices or fill in forms sent by their nursery.
- Children whose records their nursery keeps in ChildHive.
- Visitors to our website and people who ask us for a demo.
3. Our role: the nursery is in charge of its data
When a nursery records information about children, families and staff in ChildHive, the nursery is the data controller: it decides what is collected and why. We are its data processor: we store and process that information only to provide the service, on the nursery's instructions, under our Data Processing Agreement. If you are a parent or a member of staff and want to access, correct or delete information a nursery holds about you or your child, please contact the nursery first. We will help them respond.
We are the data controller for a smaller set of information: our customers' account and billing details, demo requests, and messages sent to us.
4. What information is in ChildHive
About children (entered by the nursery)
- Name, date of birth, photo, room and attendance.
- Observations, photographs, learning and development records, progress checks and reports.
- Health information such as allergies, dietary needs, medication, accidents and incidents, and special educational needs. This is special category data and is given extra protection.
- Funding entitlements and session patterns used for invoicing.
About parents and carers
- Name, contact details, relationship to the child and emergency contacts.
- Invoices, payments and funding information.
- Signatures on accident reports, medication forms and agreements.
- Forms returned to the nursery, such as consent forms. Some, like health programme consent forms, ask for a child's ethnic origin, which is special category data and is given extra protection.
About staff
- Name, email, role, rota, attendance, leave and certifications.
- A record of actions taken in ChildHive (the audit log).
About website visitors and prospective customers
- What you tell us when you request a demo or contact us, such as your name, nursery and email address.
- Basic technical information our hosting provider logs to keep the site secure, such as IP address.
5. Why we use it, and our lawful basis
- To provide ChildHive to nurseries (records, invoicing, the parent app, emails and notifications). For nursery data we act on the nursery's instructions; for our customers' account details our basis is performing our contract with them.
- To keep ChildHive secure and working, including fixing problems and preventing misuse. Our basis is our legitimate interest in running a safe service.
- To reply to demo requests and messages. Our basis is our legitimate interest in responding to people who contact us.
- To meet legal obligations, such as keeping financial records.
We do not sell personal data, use it for advertising or build marketing profiles.
6. How AI is used
Some ChildHive features use Google's Gemini AI to draft text: for example, an observation written from a photo, a newsletter written from staff notes, or allergen information read from a food label. The photo or notes are sent to Google to produce the draft.
- Every AI draft is reviewed by a member of nursery staff before it is shared with a parent. This cannot be turned off.
- We use Google's paid Gemini API, under whose terms Google does not use this content to train its models.
- AI is never used to make decisions about a child or family on its own.
7. Who we share it with
We use the following trusted providers to run ChildHive. Each only receives what it needs for its job and is bound by a contract to protect the data.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and file storage (records, photos, documents) | Ireland (EU) |
| Vercel | Hosting and running the ChildHive website and app | United States and global edge network |
| Clerk | Sign-in, accounts and two-factor authentication | United States |
| Google (Gemini API) | AI drafting of observations, reports, newsletters and label reading | United States |
| Resend | Sending emails (invoices, reminders, notifications) | United States |
| Calendly | Booking nursery viewings, where a nursery connects it | United States |
| Browser push services (Google, Apple, Mozilla) | Delivering push notifications to staff devices | United States |
We may also share information if the law requires it, or with a nursery's permission. If you message us on WhatsApp, WhatsApp (Meta) handles that conversation under its own privacy policy.
8. Data stored outside the UK
Our main database and file storage are in Ireland, which the UK recognises as providing adequate protection. Some providers above are based in the United States. Where data leaves the UK, we rely on the UK-US data bridge or the UK International Data Transfer Addendum to make sure it stays protected to UK standards.
9. How long we keep it
Nurseries can delete records at any time. By default, ChildHive keeps:
- Accident, incident and medication records until the child turns 21.
- Observations for 3 years after a child leaves the nursery.
- Invoices for 6 years after a child leaves, in line with HMRC record-keeping rules.
- Deleted items in a recoverable bin for 60 days before they are permanently removed.
If a nursery stops using ChildHive, we can export its data and will then delete it, as set out in our Data Processing Agreement.
10. How we keep it safe
- Each nursery's data is kept separate, and staff only see what their role allows.
- Admins must sign in with two-factor authentication.
- Sensitive actions are recorded in an audit log.
- Data is encrypted in transit and at rest.
- Forms filled in offline are stored on the device only until they sync.
11. Cookies
ChildHive only uses cookies that are strictly necessary: to keep you signed in, protect your account and remember security choices. We do not use analytics, advertising or tracking cookies, so we do not need to ask for your consent and there is no cookie banner. If we ever add optional cookies, we will ask first and update this policy.
12. Your rights
Under UK data protection law you have the right to:
- ask for a copy of your personal data;
- have inaccurate data corrected;
- have data deleted where there is no reason to keep it;
- object to or restrict how it is used;
- receive your data in a portable format.
For records a nursery holds, contact the nursery and we will help them respond. For anything else, message us on WhatsApp on +44 7445 396443 or write to our registered office. We reply within one month.
13. Children
Children do not use ChildHive themselves. Their records are created and managed by their nursery, and parents and carers see them through the parent app.
14. Complaints
If you are unhappy with how we have handled your data, please tell us first on WhatsApp on +44 7445 396443. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
15. Changes to this policy
If we make important changes, we will tell nurseries by email before they take effect. The date at the top shows when this policy was last updated.