GDPR and Data Protection
How Bloom Kidz, operated by Owl Corporations Ltd, complies with UK GDPR, the Data Protection Act 2018 and related legislation when processing personal information for nurseries and early-years providers.
Purpose of This Policy
Bloom Kidz is committed to protecting the privacy, confidentiality and security of all personal information processed through our nursery management software and associated services.
This policy explains how Bloom Kidz, operated by Owl Corporations Ltd, complies with applicable UK data protection legislation, including:
- UK General Data Protection Regulation (UK GDPR);
- Data Protection Act 2018;
- Data (Use and Access) Act 2025, where applicable;
- Privacy and Electronic Communications Regulations (PECR), where applicable; and
- Guidance issued by the Information Commissioner's Office (ICO).
Because Bloom Kidz is designed for nurseries and early-years providers, our platform may process information relating to children. We recognise that children's personal information requires particular care and a high level of protection.
About Bloom Kidz
Bloom Kidz is a nursery management software platform provided by Owl Corporations Ltd.
The platform may enable nurseries and other childcare providers to manage information relating to:
- children;
- parents and carers;
- emergency contacts;
- nursery employees;
- agency workers;
- prospective families;
- attendance;
- learning and development;
- observations and assessments;
- safeguarding information;
- medical and dietary requirements;
- invoices and payments;
- communications;
- photographs and videos;
- permissions and consents; and
- operational and administrative nursery records.
Our Role Under Data Protection Law
In most circumstances, a nursery or childcare provider using Bloom Kidz determines:
- which children, parents and staff information is collected;
- why the information is required;
- what information is entered into Bloom Kidz;
- how long that information should be retained;
- who within the nursery has access;
- when information should be corrected or deleted; and
- how requests from parents, employees or other individuals are handled.
In these circumstances, the nursery or childcare provider acts as the Data Controller.
Where Bloom Kidz stores or processes personal data on behalf of a nursery customer, Owl Corporations Ltd, trading through Bloom Kidz, acts as the Data Processor.
Bloom Kidz will process such information only:
- according to the documented instructions of the Data Controller;
- as required to provide the Bloom Kidz service;
- in accordance with the contract between Bloom Kidz and the customer; or
- where processing is otherwise required by applicable law.
Owl Corporations Ltd may act as an independent Data Controller for certain information collected for its own legitimate business purposes, for example:
- nursery customer account information;
- business contact details;
- enquiries;
- subscription and billing information;
- customer support records;
- website enquiries;
- marketing preferences;
- security logs;
- contractual records; and
- information required for legal, financial or regulatory purposes.
Data Protection Principles
Bloom Kidz will ensure that personal information is:
Personal information must be processed lawfully, fairly and in a way that individuals can reasonably understand.
Information must only be collected for clear, specified and legitimate purposes.
Only information reasonably necessary for its intended purpose should be collected.
Reasonable steps will be taken to keep information accurate and, where necessary, up to date.
Personal information will not be retained for longer than is necessary for the relevant purpose, contractual requirement or legal obligation.
Appropriate technical and organisational safeguards will be used to protect information from unauthorised access, disclosure, alteration, loss or destruction.
Bloom Kidz will maintain appropriate policies, procedures and records to demonstrate compliance with applicable data protection requirements.
Categories of Personal Data Processed Through Bloom Kidz
Depending on how a nursery configures and uses the system, Bloom Kidz may process:
This may include:
- child's name;
- date of birth;
- gender;
- address;
- photograph;
- attendance records;
- room or class information;
- learning observations;
- development records;
- assessments;
- activities;
- photographs and videos;
- meal records;
- sleep records;
- toileting information;
- accident and incident records;
- allergies;
- dietary requirements;
- medication records;
- medical information;
- additional needs information;
- SEND information;
- safeguarding records;
- funding information;
- authorised collection information; and
- emergency contact information.
This may include:
- name;
- address;
- telephone number;
- email address;
- relationship to child;
- emergency contact information;
- communication records;
- permissions and consents;
- invoices;
- payment records; and
- account information.
Where a nursery uses Bloom Kidz for workforce management, information may include:
- name;
- contact information;
- job role;
- attendance;
- rotas;
- qualifications;
- training;
- employment-related records;
- safeguarding-related information where necessary; and
- system access and activity records.
Special Category Data
Certain information processed within Bloom Kidz may qualify as special category personal data, particularly information relating to:
- physical or mental health;
- disabilities or additional needs;
- medical conditions;
- allergies;
- dietary requirements linked to religion or health;
- racial or ethnic origin;
- religious beliefs; and
- biometric information where applicable.
Nursery customers are responsible for establishing the appropriate lawful basis and, where required, special-category condition before entering such information into the Bloom Kidz platform.
Bloom Kidz will apply enhanced safeguards to sensitive information processed on behalf of customers.
Children's Personal Data
Bloom Kidz recognises that children require additional protection under UK data protection legislation.
We aim to ensure that:
- children's information is collected only where necessary;
- privacy and security are considered throughout the design of Bloom Kidz;
- access to children's information is restricted to authorised users;
- appropriate safeguards are applied by default;
- information is not used for unrelated marketing purposes;
- children's information is not sold;
- children's personal data is not used for behavioural advertising;
- data minimisation principles are applied; and
- nurseries retain appropriate control over the information entered into the system.
Where a Bloom Kidz feature is designed to be accessed directly by children, the company will undertake additional privacy and safeguarding assessments before deployment.
Lawful Basis for Processing
Where Bloom Kidz acts as a Data Processor, the nursery customer is primarily responsible for identifying the appropriate lawful basis for processing.
Depending on the circumstances, lawful bases used by nursery customers may include:
- performance of a contract;
- compliance with a legal obligation;
- legitimate interests;
- vital interests;
- public task; or
- consent where appropriate.
Consent should only be relied upon where it is freely given, specific, informed and capable of being withdrawn.
Where Owl Corporations Ltd acts as a Data Controller for its own business information, it will establish and document an appropriate lawful basis before processing personal information.
How Bloom Kidz Uses Customer Data
Personal information entered into Bloom Kidz by nursery customers may be processed for purposes including:
- delivering the Bloom Kidz service;
- hosting and storing nursery information;
- facilitating parent-nursery communication;
- recording children's attendance;
- maintaining learning and development records;
- creating observations and assessments;
- managing staff information;
- administering invoices and accounts;
- recording accidents, incidents and medication;
- maintaining safeguarding and compliance records;
- providing technical support;
- maintaining security;
- creating backups;
- diagnosing technical issues; and
- carrying out other processing instructed by the nursery customer.
Bloom Kidz will not independently use nursery-controlled children's data for advertising or unrelated commercial marketing.
Access Controls
Access to Bloom Kidz should follow the principle of least privilege.
Nursery customers are responsible for determining which members of their organisation require access and what level of access each individual should receive.
Bloom Kidz may provide different access levels for different user types.
Users must:
- keep login credentials confidential;
- use strong passwords;
- not share accounts unless specifically permitted;
- immediately report suspected unauthorised access;
- log out of shared devices; and
- only access information required for their role.
Bloom Kidz may suspend or restrict accounts where misuse or a security risk is suspected.
Data Security
Bloom Kidz will maintain appropriate technical and organisational measures designed to protect personal information.
These may include, where appropriate:
- encryption of information in transit;
- encryption of stored information;
- secure hosting;
- access controls;
- authentication controls;
- password protections;
- system logging;
- monitoring;
- firewall and infrastructure protection;
- secure backups;
- vulnerability management;
- regular software updates;
- security testing;
- staff confidentiality requirements;
- role-based access; and
- incident-management procedures.
Security measures will be reviewed periodically and updated in response to changes in technology, identified risks and regulatory guidance.
Privacy by Design and Default
Privacy and data protection will be considered throughout the development and operation of Bloom Kidz.
Where appropriate, Bloom Kidz will:
- minimise the personal information collected;
- restrict access by default;
- build privacy controls into product design;
- conduct Data Protection Impact Assessments;
- consider children's higher protection requirements;
- review new features before release;
- maintain security throughout the development lifecycle; and
- ensure personal data is not unnecessarily exposed.
Data Protection Impact Assessments
Bloom Kidz will consider conducting a Data Protection Impact Assessment (DPIA) where a proposed activity is likely to result in a high risk to individuals' rights and freedoms.
Examples may include:
- introduction of new monitoring technologies;
- large-scale use of sensitive information;
- significant new children's data-processing features;
- biometric technologies;
- artificial intelligence involving identifiable children or staff;
- large-scale profiling; or
- major changes to the way personal information is used.
Where Bloom Kidz is acting as a processor, reasonable assistance may also be provided to nursery customers conducting their own DPIAs.
Sub-Processors and Third-Party Providers
Bloom Kidz may use carefully selected service providers to support delivery of the platform.
These may include providers of:
- cloud hosting;
- data storage;
- backup services;
- email delivery;
- communications;
- payment processing;
- analytics;
- cybersecurity;
- technical support; and
- software infrastructure.
Where a service provider processes personal information on behalf of Bloom Kidz, appropriate contractual and data-protection safeguards will be required.
A list of relevant sub-processors may be maintained and made available to customers.
International Data Transfers
Where personal information is transferred outside the United Kingdom, Bloom Kidz will ensure an appropriate transfer mechanism and safeguards are in place as required by applicable data protection legislation.
This may include:
- UK adequacy regulations;
- an International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses; or
- another legally recognised transfer mechanism.
International transfers will be assessed before implementation.
Data Retention
Nursery customers are responsible for establishing retention periods for information for which they are Data Controllers.
Bloom Kidz will provide facilities, where appropriate, enabling customers to manage or delete information.
Following termination of a Bloom Kidz customer account, personal information will be returned, retained or deleted in accordance with:
- the customer contract;
- documented customer instructions;
- applicable legal requirements;
- backup retention cycles; and
- legitimate security and regulatory requirements.
Owl Corporations Ltd will maintain a documented retention schedule for personal information that it controls directly.
Data Subject Rights
Under applicable UK data protection legislation, individuals may have rights including:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability;
- the right to object;
- rights relating to automated decision-making; and
- the right to complain to the Information Commissioner's Office.
Where a request concerns personal information controlled by a nursery customer, Bloom Kidz will normally refer the request to the relevant nursery and provide reasonable technical assistance where required.
Bloom Kidz will not independently respond to requests involving nursery-controlled information unless authorised by the Data Controller or required by law.
Subject Access Requests
Where Owl Corporations Ltd receives a Subject Access Request relating to data it controls, the request will be handled in accordance with applicable legal timescales.
Where a request relates to data controlled by a nursery, Bloom Kidz will:
- notify the relevant nursery where appropriate;
- preserve relevant information where necessary;
- provide reasonable assistance in locating or exporting information; and
- follow the documented instructions of the Data Controller.
Rectification and Deletion
Bloom Kidz will provide reasonable functionality allowing authorised users to correct or update information.
Where information needs to be deleted, the relevant Data Controller may instruct Bloom Kidz to delete information subject to applicable:
- safeguarding requirements;
- statutory retention obligations;
- legal claims;
- backup procedures; or
- other lawful restrictions.
Personal Data Breaches
A personal data breach may include:
- unauthorised access;
- unauthorised disclosure;
- accidental deletion;
- loss of data;
- ransomware;
- theft of devices;
- compromised passwords;
- inappropriate sharing; or
- any event resulting in the loss of confidentiality, integrity or availability of personal information.
Bloom Kidz will maintain a personal-data-breach procedure.
Where Bloom Kidz becomes aware of a breach affecting information processed for a nursery customer, Bloom Kidz will notify the relevant Data Controller without undue delay and provide available information reasonably required to assist the controller with its obligations.
Where Owl Corporations Ltd is the Data Controller, it will assess whether the breach needs to be reported to the ICO and/or affected individuals.
Incident Reporting
All Bloom Kidz and Owl Corporations Ltd employees, contractors and authorised personnel must immediately report suspected:
- data loss;
- hacking;
- phishing;
- inappropriate access;
- accidental disclosure;
- device loss;
- password compromise; or
- other security incidents.
Incidents will be documented, investigated and managed in accordance with the company's incident-response procedures.
Staff Responsibilities
Employees and contractors with access to personal information must:
- comply with this policy;
- maintain confidentiality;
- undertake appropriate data-protection training;
- only access information necessary for their duties;
- follow security procedures;
- report suspected breaches promptly; and
- not copy, disclose or use customer information for unauthorised purposes.
Access may be revoked immediately upon termination of employment or where access is no longer required.
Training
Staff handling personal information will receive appropriate data protection and information security training.
Training may cover:
- UK GDPR principles;
- confidentiality;
- children's information;
- phishing;
- password security;
- data breaches;
- Subject Access Requests;
- secure communication; and
- handling sensitive information.
Training will be refreshed periodically.
Marketing
Bloom Kidz will comply with applicable data protection and electronic marketing requirements.
Customer marketing communications may be sent where:
- valid consent has been provided; or
- another lawful basis and applicable PECR permission exists.
Individuals will be given an appropriate method to unsubscribe from direct marketing communications.
Personal information belonging to children using nursery customer accounts will not be used by Bloom Kidz for direct marketing to children.
Cookies and Analytics
Bloom Kidz websites and online services may use cookies or similar technologies for purposes including:
- essential functionality;
- authentication;
- security;
- remembering preferences;
- measuring performance; and
- analytics.
Where consent is legally required for non-essential cookies, such cookies will not be activated until appropriate consent has been obtained.
Further information should be provided within the Bloom Kidz Cookie Policy.
Automated Decision-Making and Artificial Intelligence
Bloom Kidz will assess any features involving automated decision-making or artificial intelligence before implementation.
Where such technology processes personal information, consideration will be given to:
- lawful basis;
- transparency;
- fairness;
- accuracy;
- discrimination risks;
- children's rights;
- human oversight;
- security; and
- whether a DPIA is required.
Bloom Kidz will not make significant decisions about children solely through automated processing unless legally permitted and appropriate safeguards are in place.
Data Sharing
Bloom Kidz will not sell customer personal information.
Information may only be disclosed where:
- instructed by the Data Controller;
- required to deliver the Bloom Kidz service;
- necessary for authorised sub-processors;
- required by law;
- necessary to establish or defend legal claims; or
- necessary to protect individuals in exceptional circumstances permitted by law.
Any disclosure will be limited to what is reasonably necessary.
Law Enforcement and Regulatory Requests
Bloom Kidz may receive lawful requests from courts, regulators, law-enforcement agencies or other public authorities.
Requests will be reviewed before information is disclosed.
Where legally permitted and where Bloom Kidz is acting as a processor, the relevant nursery customer may be informed of the request.
Data Processing Agreements
Bloom Kidz will maintain appropriate contractual provisions with nursery customers addressing data processing requirements.
These may cover:
- the subject matter of processing;
- duration;
- nature and purpose;
- categories of personal information;
- categories of data subjects;
- confidentiality;
- security requirements;
- sub-processors;
- data-subject requests;
- personal-data breaches;
- audits;
- deletion and return of data;
- international transfers; and
- responsibilities of the Data Controller and Data Processor.
See also our Data Processing Terms in Schedule 1 of the Terms and Conditions.
Record Keeping
Bloom Kidz will maintain appropriate records of processing and compliance activities where required.
Records may include:
- processing activities;
- contracts;
- processor agreements;
- sub-processors;
- security controls;
- data breaches;
- DPIAs;
- training;
- retention schedules; and
- data-subject requests.
Complaints
Questions or complaints regarding the processing of personal information should initially be raised with the organisation responsible for the relevant information.
Where a nursery controls the information, individuals should ordinarily contact the nursery first.
Where Owl Corporations Ltd controls the information, enquiries may be made directly to Bloom Kidz/Owl Corporations Ltd.
Individuals also have the right to raise concerns with the:
UK data protection supervisory authority.
Contact Details
For questions relating to this policy or Bloom Kidz data protection practices, please contact:
Data Protection Team — Owl Corporations Ltd / Bloom Kidz
Related Policies
This policy should be read alongside the following Bloom Kidz documents:
- Privacy Notice;
- Customer Data Processing Agreement;
- Cookie Policy;
- Information Security Policy;
- Data Retention and Deletion Policy;
- Personal Data Breach Response Policy;
- Acceptable Use Policy;
- Business Continuity and Disaster Recovery Policy;
- Sub-Processor List;
- Children's Data and Privacy Policy;
- Terms and Conditions; and
- Data Subject Rights Procedure.
Relevant published pages: Privacy Policy, Terms and Conditions, Cookie Policy.
Review of This Policy
This policy will be reviewed:
- at least annually;
- following significant changes to Bloom Kidz;
- following relevant legislative or regulatory changes;
- following a significant data-protection incident; or
- where changes to processing activities require an earlier review.
Any material updates will be appropriately communicated to relevant employees, contractors and customers.
Product: Bloom Kidz
Effective Date: January 2026
Next Review: January 2027