BloomKidz
Book Demo
BloomKidz
Home Features Parent Partnerships Child Development Daily Logs Occupancy Staffing Pricing Blog About Contact
Start Free Trial
Legal & Compliance

Cookie & Other Policies

Our Cookie Policy, Data Processing Agreement, and the operational policies that govern how Bloom Kidz, provided by Owl Corporations Ltd, handles data, security, incidents, support and accessibility.

Last reviewed: January 2026 Owl Corporations Ltd Applies to: www.bloomkidz.net & app.bloomkidz.net
Policy 01

Cookie Policy — Public Website

Who we are. Bloom Kidz is operated by Owl Corporations Ltd, Charter Place, Uxbridge, UB8 1JG, company number 14975271. Contact info@bloomkidz.net. This policy covers www.bloomkidz.net and app.bloomkidz.net.

What these technologies do. Cookies, local storage, pixels and similar tools can store information on, or access information from, your device. We may use necessary tools for login, session continuity, security and choices you request. We may use optional analytics or advertising tools only as listed in the verified register below and in line with applicable consent rules.

CategoryPurposeConsent setting
NecessaryAuthentication, security and requested functionsActive where an applicable exception permits; explain each use
AnalyticsMeasure use and improve pagesDefault off unless a verified legal exception applies
MarketingMeasure campaigns or personalise advertisingDefault off until valid consent
PreferencesRemember optional settingsAssess whether an exception applies; otherwise seek consent

Your choice. On first visit, we offer equally clear Accept optional, Reject optional and Manage choices controls. Optional technologies remain off until you consent.

Other organisations may set technologies through embedded features only if enabled; these are identified in our register. For personal information associated with website use, see the Bloom Kidz Privacy Policy.

Update Your Preferences

Click the button below to reset your consent and show the cookie banner again.

Contact info@bloomkidz.net. Last reviewed January 2026.

Policy 02

Data Processing Agreement — Customer Contract Schedule

Parties and precedence. This DPA is between the nursery customer identified in the order form (Controller) and Owl Corporations Ltd trading as Bloom Kidz (Processor). It takes effect when the customer accepts the Bloom Kidz Terms or signs an order incorporating this DPA. For the processing covered here, it supplements and, on a conflict concerning data processing, takes precedence over general service terms. Each party remains independently responsible for its own legal duties. Processing for Owl Corporations Ltd's own accounts, billing and direct marketing is addressed in its Privacy Policy, not this processor DPA.

1. Instructions

Processor shall process Customer Personal Data only on documented Controller instructions, including this DPA, the order, configured features and subsequent written instructions, unless UK law requires otherwise; in that case it shall inform Controller first unless prohibited by law. Processor shall promptly inform Controller if it considers an instruction to infringe applicable data protection law. No secondary use for advertising, model training or unrelated product development without a separately established lawful arrangement.

2. Confidentiality and Security

Processor shall bind authorised personnel to confidentiality and restrict access to legitimate duties. It shall implement measures appropriate to risk under UK GDPR Article 32, including verified encryption at rest and in transit, individual accounts, role permissions, logging, backups, patching, incident handling and staff training. Processor maintains a current technical and organisational measures annex with implementation details, evidence and review date; planned controls are not described as live.

3. Sub-Processors

Controller grants general written authorisation for listed sub-processors at the published sub-processor register URL. Processor shall give advance notice of intended additions or replacements via email at least 3 days where practicable and allow the Controller to object on reasonable data protection grounds before appointment. Parties shall discuss mitigation; if unresolved, Controller may terminate affected services without future fees for the unused prepaid period, subject to agreed order terms. Processor shall impose equivalent data protection obligations by written contract and remains responsible for its sub-processors' performance of those obligations.

4. Transfers

Processor shall not make a restricted international transfer without a valid UK transfer mechanism and any required transfer risk assessment. Relevant details are provided to the Controller on request. Locations and mechanisms are listed in the sub-processor register; remote access from abroad is assessed too.

5. Assistance

Taking account of the processing and available information, Processor shall assist Controller with rights requests, security duties, breach assessment and notifications, DPIAs and prior regulatory consultation. Direct requests about nursery data are referred to Controller unless prohibited by law. The parties will agree reasonable costs for exceptional assistance in advance where legally permissible.

6. Breach

Processor shall notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, through email. Available facts, likely consequences, actions taken and follow-up updates are provided without waiting for a complete investigation. Controller decides whether to notify the ICO or affected individuals, unless another law independently requires Processor to act.

7. Return and Deletion

At the Controller's choice on expiry or termination, Processor shall return or delete Customer Personal Data, and delete existing copies, unless law requires storage. Controller communicates its choice using email.

  • Export format: PDF
  • Export availability: 30 days
  • Active deletion: within 5 days after the 30-day export period
  • Backup overwrite: within 5 days after the 30-day export period

Restricted backup data remains protected and inaccessible for routine processing until expiry. Confirmation of deletion is provided on request.

8. Audit

Processor shall make available information needed to demonstrate compliance and allow and contribute to audits, including inspections by Controller or an appointed auditor. The parties will arrange reasonable notice, scope and security safeguards without preventing a legally necessary audit. Other customers' confidentiality is protected. Processor may provide current independent reports first, where sufficient.

9. Processing Details

Subject matter: hosting and supporting nursery management records. Duration: subscription plus verified export/deletion periods and lawful retention. Nature: collection, recording, storage, access, communication, backup, export and deletion. Purpose: nursery administration, care records, parent communication and enabled modules on Controller instructions. Data subjects: children and applicants, parents, carers, authorised collectors, staff and contacts. Data: contact and identity records, attendance, observations, images, communications, billing and staff details; where entered, health, allergies, SEND, safeguarding and other sensitive information. Controller determines lawful bases, special category conditions, notices, accuracy, permissions and access rules. Processor may not expand processing categories through a new feature without suitable instructions and documentation.

Acceptance

This DPA is incorporated automatically by the customer's acceptance of the Bloom Kidz Terms, or may instead be signed separately as part of an Order Form.

Where signed separately, the signed record captures: the customer's legal name; the authorised signatory's name, role and signature; the date of signing; the Owl Corporations Ltd signatory and date; and the relevant order reference.

Policy 03

Data Retention and Deletion Policy

The nursery controls retention decisions for its own records while subscribed, subject to law and platform functionality. Bloom Kidz retains and processes those records as instructed; customers should configure their own schedules for childcare, safeguarding, financial and employment records with professional advice. Bloom Kidz does not promise one statutory period for all nursery records.

On account closure, an administrator may request an export via PDF within a 30-day period. Bloom Kidz will make an agreed export available in PDF format. Following an instruction to delete, live data will be removed within 5 days after the 30-day export window; backup copies expire within 5 days after the 30-day export window and remain protected, with access limited to recovery or legal necessity. If a backup is restored, the deletion instruction is reapplied. A deletion log is retained with customer ID, instruction, scope, date, operator and confirmation, without retaining unnecessary child records.

Owl Corporations Ltd controls its own contracts, billing, security and support records and keeps them for 6 years according to legal and operational need. Records subject to a legitimate legal hold are preserved, access restricted, and the hold reviewed regularly. For an early deletion or rights request, nursery records are routed to the nursery controller; requests about Bloom Kidz-controlled data are answered directly.

Policy Owner

info@bloomkidz.net. Reviewed annually and when infrastructure changes.

Policy 04

Information Security Policy — Customer Summary

Bloom Kidz protects children's, parents', staff and nursery information using security controls proportionate to the sensitivity of the information and the associated risks.

An authorised Data Protection & Security Lead maintains appropriate records of information assets, key technology suppliers, security risks and user-access reviews.

Staff are provided with individual user accounts. Access permissions are granted according to job responsibilities and the principle of least privilege. Access is reviewed at least every six months and removed promptly when a member of staff leaves the organisation or no longer requires access.

Multi-factor authentication (MFA) is required for administrative and privileged accounts and should be enabled for other accounts wherever technically available.

Connections to Bloom Kidz systems use TLS 1.2 or higher to protect information while it is being transmitted. Customer information, databases and backups should be encrypted at rest using industry-standard encryption, such as AES-256 or an equivalent recognised standard.

Encryption keys, passwords, API credentials and other secrets are stored using a secure secrets-management system or encrypted credential vault and are not stored in plain text within application code or shared documents.

Changes to production systems are reviewed, tested and logged before deployment wherever reasonably practicable.

Security updates and vulnerability findings are prioritised according to their severity. As a general target:

  • Critical vulnerabilities: addressed within 24–72 hours
  • High-risk vulnerabilities: addressed within 7 days
  • Medium-risk vulnerabilities: addressed within 30 days
  • Low-risk vulnerabilities: addressed within 90 days

Exceptions, dependencies or delays are documented internally together with the responsible owner and revised target date.

Backups are performed daily, stored in encrypted secure cloud infrastructure separate from the primary production environment, and normally retained for 30 days. Backup restoration procedures are tested at least quarterly to confirm that information can be recovered successfully.

Security and application logs are access-controlled and normally retained for 12 months, unless a shorter or longer retention period is required for security investigations, contractual requirements or legal obligations.

Employees and contractors with access to Bloom Kidz systems or confidential information receive confidentiality, data-protection and information-security training when they join the organisation, with refresher training provided at least annually.

Suppliers and sub-processors that may access or process customer information are assessed before appointment and are subject to appropriate contractual, confidentiality, data-protection and security requirements. Key suppliers are normally reviewed annually or when there is a significant change to their services.

Security incidents, suspected data breaches and vulnerabilities are handled in accordance with the Data Breach and Incident Response Policy below.

Customers are responsible for appropriately managing their own user permissions, maintaining secure devices and passwords, removing access when staff leave their organisation, and promptly reporting suspected security incidents or unauthorised access.

Security Enquiries

Requests relating to security information, security questionnaires or supporting security evidence should be sent to info@bloomkidz.net. Bloom Kidz reviews its information-security arrangements at least annually and following significant system, regulatory or operational changes.

Policy 05

Data Breach and Incident Response Policy

Scope and Owner

Any suspected or confirmed unauthorised access, disclosure, loss, alteration, destruction or unavailability of personal data must be reported immediately and, wherever possible, within one hour of discovery to the Security Contact (info@bloomkidz.net) and the Data Protection & Security Lead, who will own the incident and open an incident record.

The incident record documents and timestamps: when the incident occurred (if known); when it was discovered; when Bloom Kidz became aware personal data may be affected; who reported it; systems and information potentially affected; actions taken; risk assessments; internal and external communications; notification decisions; remediation; and closure/lessons learned.

1. Contain Safely

Immediate steps are taken to limit further loss or unauthorised access, which may include revoking or suspending compromised accounts, resetting passwords, revoking active sessions, isolating affected systems, restricting access, disabling compromised integrations, preserving logs and evidence, and preventing further disclosure. Information that may be needed for investigation is not deleted, overwritten or destroyed. Where practical, containment begins within one hour of becoming aware of a significant incident.

2. Assess the Incident

The Data Protection & Security Lead investigates as a priority, with an initial risk assessment targeted within 24 hours of awareness, identifying the affected systems and nurseries, the circumstances and likely cause, categories of data involved, whether children's or special-category data is involved, approximate numbers of individuals and records affected, the impact on confidentiality/integrity/availability, and whether notification is required.

Incidents involving children's personal information receive priority assessment, and any safeguarding concern is escalated promptly through the appropriate safeguarding procedures and, where necessary, to the appropriate authorities.

3. Customer and Regulatory Notification

Where Bloom Kidz acts as a processor: the relevant nursery, as data controller, is notified without undue delay after becoming aware of the breach — as an internal target, within 24 hours of confirmation wherever reasonably possible, sooner for serious incidents, via a secure authenticated channel. The initial notification is not delayed pending every detail, and includes the nature of the incident, dates, information and individuals potentially affected, actions taken, potential consequences and mitigation measures. For significant ongoing incidents, updates are normally provided at least every 24 hours while material information is developing.

Where Owl Corporations Ltd acts as controller: the Data Protection & Security Lead assesses whether the incident must be reported to the ICO. Where required, Owl Corporations Ltd notifies the ICO without undue delay and, where feasible, no later than 72 hours after becoming aware, with further information supplied in phases if needed. Where a breach is likely to result in a high risk to individuals, affected individuals are also informed without undue delay. All personal data breaches are recorded internally, including those not reported to the ICO.

4. Recover, Remediate and Learn

Once the immediate risk is controlled, normal operations are safely restored — which may include restoring from secure backups, resetting passwords, rotating keys and credentials, patching, removing unauthorised access, correcting configurations, testing integrity, increasing monitoring, and providing customer guidance. For significant incidents, a documented post-incident review is normally completed within 10 working days of closure, identifying root cause, response effectiveness, control failures, lessons learned, required improvements, owners and target dates. Corrective actions are tracked to completion.

Policy 06

Acceptable Use Policy — Customer Facing

Customers and authorised users may use Bloom Kidz only for their own lawful childcare operations under an active subscription. Keep credentials private, use individual accounts, assign the least access needed and remove leavers promptly. Do not attempt unauthorised access, security testing without written authorisation, scraping, malware distribution, service disruption, infringement or resale. Do not upload unlawful, abusive or harmful content or data unrelated to the nursery's legitimate purposes. Follow nursery consent and safeguarding rules when sharing children's images and sensitive records.

Report suspected misuse to info@bloomkidz.net. We may restrict harmful content or access where reasonably necessary to protect people, data or service security; where safe and practical we will tell the customer and give a chance to remedy. Serious or persistent breaches may lead to suspension or termination under the Terms. This policy does not prevent lawful reporting to regulators or emergency services.

Last reviewed January 2026.

Policy 07

Service and Support Policy — Customer Facing

Bloom Kidz provides customer support for account access and login issues, platform faults and technical problems, configuration and general usage guidance, and subscription and billing enquiries. Contact Bloom Kidz Support at info@bloomkidz.net.

Standard Support Hours

Monday to Friday, 9:00am to 5:00pm UK time, excluding UK public and bank holidays. Requests received outside standard support hours will normally be reviewed on the next working day.

Emergency Security Issues

Suspected security incidents, data breaches or unauthorised access should be reported immediately to info@bloomkidz.net with "URGENT – SECURITY INCIDENT" in the subject line so the matter can be prioritised. A dedicated security contact may be introduced as Bloom Kidz's support operations develop.

Support Priorities and Target Response Times
PriorityExampleTarget acknowledgementTarget update frequency
Critical – P1Service-wide outage, widespread inability to access Bloom Kidz, suspected serious security incident or major loss of a core serviceWithin 1 hour during support hoursApproximately every 2 hours while active
High – P2Important core functionality unavailable or significantly impaired, no reasonable workaroundWithin 4 business hoursAt least once each business day
Routine – P3General technical issue, configuration question, billing enquiry, guidance request or minor issueWithin 1 business dayNormally within 2 business days where investigation is required

These are service targets rather than guaranteed resolution times. Resolution depends on the issue's nature, complexity, third-party dependencies and whether further customer information is required. These targets do not constitute a contractual SLA, guaranteed restoration time or uptime commitment unless specifically included within an applicable Order Form, contract or Service Level Agreement.

Planned Maintenance

Where practicable, customers are given advance notice through email, an in-app notification, and/or other appropriate channels — normally at least 48 hours ahead for significant planned maintenance. Emergency maintenance may occasionally be carried out without the standard notice period where necessary to protect security, availability or service integrity.

Service Incident Communications

During a significant service incident, Bloom Kidz communicates updates through customer email and/or an in-app notification — approximately every two hours during active investigation of critical incidents, where meaningful information is available, or at a frequency appropriate to lower-priority issues. Once resolved, a closure notification may explain that service has been restored, any actions customers need to take, and a brief explanation of the incident and preventative actions.

Information Required From Customers
  • Nursery or organisation name
  • Name and contact details of the person reporting the issue
  • Description of the problem and approximate start time
  • Feature or area of Bloom Kidz affected
  • Steps that reproduce the problem, where possible
  • Relevant screenshots and error message details

Customers should not send unnecessary children's personal information, passwords, medical information, safeguarding information or other sensitive information through ordinary email. If sensitive information is genuinely required to investigate a problem, Bloom Kidz will advise on an appropriate secure method of providing it.

Backups and Recovery

Bloom Kidz backups, business continuity and recovery arrangements are managed in accordance with the company's verified information-security and backup procedures. Backup or recovery capabilities are not described as guaranteed unless technically verified and expressly included in the customer's contractual terms.

Matters Outside the Scope of Support

Bloom Kidz Support assists with the Bloom Kidz platform. Support does not provide professional legal, medical, safeguarding, tax or accounting, employment-law, or regulatory compliance advice. Information, templates or guidance available through Bloom Kidz support nursery administration and should not replace appropriate professional advice where required.

Escalations

If a customer believes an issue has not been adequately addressed, they may request escalation to the Bloom Kidz Support Manager at info@bloomkidz.net with the subject line "Support Escalation – [Nursery Name]". The Support Manager or another authorised senior representative reviews the issue and determines next steps.

Service Improvement & Policy Review

Bloom Kidz reviews customer support feedback, recurring technical problems, significant service incidents, complaints and support trends at least quarterly, assigning and tracking corrective or improvement actions where needed. This Service and Support Policy is reviewed at least annually, or sooner following significant changes to the Bloom Kidz service or customer-support arrangements.

Policy 08

Children's Privacy and Data Protection Statement

Bloom Kidz is a tool your nursery may use to organise care and learning. The nursery usually decides what information to collect and who can see it; Bloom Kidz helps store and use that information for the nursery. This can include your child's name, attendance, daily activities, photos, allergies, medication and support needs if the nursery adds them.

Only people given appropriate access by the nursery should see relevant records. Bloom Kidz staff and suppliers may access information where needed to run, support or secure the service, subject to safeguards. We do not use nursery children's records for advertising to children, and we do not use them to train AI models under this policy. We do not publish children's photos on our marketing pages just because they are stored in the platform.

To ask for a copy, correction or deletion of a nursery record, contact your nursery first: it usually makes these decisions and may have duties to keep certain records. For questions about how Bloom Kidz protects information, contact info@bloomkidz.net. For full details, including suppliers, transfers and retention, read the Bloom Kidz Privacy Policy and your nursery's own privacy notice.

Written for Parents and Carers

A separate, age-appropriate explanation will be provided if children directly use any future features.

Policy 09

Accessibility Statement

Bloom Kidz aims to make the Bloom Kidz website and application usable and accessible to people with different needs, including people who use keyboards, screen readers, screen magnification software and other assistive technologies. We aim to design and develop our digital services with the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA in mind.

Current Accessibility Assessment

As of September 2026, Bloom Kidz has not yet completed a formal independent accessibility assessment against WCAG 2.2 AA. We therefore do not currently claim that the Bloom Kidz website or application fully conforms with WCAG 2.2 AA. A formal accessibility review and testing programme will be arranged as the platform develops, and any identified issues will be recorded, prioritised and addressed according to their impact on users.

Known Accessibility Barriers

Because a formal WCAG 2.2 AA audit has not yet been completed, Bloom Kidz does not currently have a verified comprehensive list of accessibility barriers. Issues reported by customers or identified through internal testing will be logged and investigated. Until formal testing is complete, customers should contact us if they experience difficulty with:

  • Keyboard navigation
  • Screen-reader compatibility
  • Form labels or instructions
  • Colour contrast
  • Text resizing or zooming
  • Focus indicators
  • Documents or downloadable content
  • Buttons, menus or other interactive controls
  • Any other part of the Bloom Kidz website or application

Listing these areas does not mean a defect has been confirmed in them — they represent common accessibility areas we want users to be able to report.

Requesting Accessible Information or Assistance

If you are unable to access a page, feature, document or function within Bloom Kidz, email info@bloomkidz.net with your name and organisation, the page or feature you are trying to use, a brief description of the difficulty, and the format or assistance you require. Please do not include unnecessary children's personal information, health information, passwords or other sensitive information in an ordinary email.

Bloom Kidz aims to acknowledge accessibility requests within 2 working days and provide a substantive response or accessible alternative, where reasonably possible, within 5 working days. More complex requests may take longer; where this happens, we will explain the position and provide an expected update.

Reporting Accessibility Problems

We welcome feedback about the accessibility of Bloom Kidz. If you identify an accessibility issue not addressed in this statement, contact info@bloomkidz.net. Feedback is recorded and considered as part of our product-development and service-improvement process.

Technical Approach

As Bloom Kidz develops, accessibility considerations form part of the design, development and testing of new features, including keyboard-only navigation testing, screen-reader testing, colour-contrast testing, visible keyboard focus, appropriate form labels, alternative text for meaningful images, clear headings and page structure, accessible error messages, text resizing and responsive layouts, and testing against relevant WCAG 2.2 AA success criteria. Bloom Kidz will not describe the website or application as WCAG 2.2 AA compliant unless appropriate testing provides reasonable evidence to support that statement.

Preparation of This Statement

Prepared: September 2026  ·  Last reviewed: August 2026

Reviewed at least annually, and sooner following a significant accessibility audit, major redesign or substantial platform change.