GDPR Compliance & Consent Management
Consents recorded per child, an organisation-wide audit log, and strict data scoping — built for European data protection rather than retrofitted to it.
Most childcare software on the market was built for the United States, where children's data operates under a different regime entirely. Those platforms handle European customers through standard contractual clauses — a legal mechanism for moving data out, not a product designed to keep it protected.
KinderConnect was built the other way round. Consent is a first-class record, every organisation's data is strictly scoped, and material changes are written to an audit log — because in the EU those aren't features, they're the baseline for operating legally.
What is included
Per-child consent register
Create, assign, and track consents per child — image use, trips, medical permissions — so the permission behind an action is documented rather than assumed.
Organisation-wide audit log
Material changes are recorded with the actor and the time, giving you the accountability trail GDPR expects you to be able to produce.
Strict organisation scoping
All data is scoped to your organisation. There is no shared pool and no cross-tenant surface for records to leak across.
Granular access control
Roles and permissions govern who reaches what, with health and specialist records held behind tighter boundaries than general information.
Account security
Multi-factor authentication, recovery codes, and active session management — the practical half of protecting personal data.
Why it matters
The distinction that actually matters
'GDPR compliant' is claimed by nearly every vendor. The useful question is narrower: where does the data live, who can reach it, and can you produce a record of consent when asked? A platform relying on standard contractual clauses to move European children's data to another jurisdiction is answering those questions differently from one that never moves it.
Consent as data, not as paperwork
A signed form in a filing cabinet is not a usable consent record — you cannot query it, and you cannot connect it to the action it authorises. Holding consent as structured data against the child means the permission is available at the moment it's relied upon, which is the difference between having consent and being able to demonstrate it.
Frequently asked questions
Where is our data stored?
Within the EU. This is the question that actually separates vendors: a platform relying on standard contractual clauses to move European children's data to another jurisdiction is answering it differently from one that never moves it.
Is KinderConnect GDPR compliant?
The platform is built for GDPR — EU data residency, per-child consent records, an audit log, strict organisation scoping, and granular access control. Compliance is a shared responsibility: we provide the mechanisms, you remain the data controller for how you use them.
How are consents recorded?
As structured data against each child, covering image use, trips, and medical permissions. A signed form in a filing cabinet cannot be queried or connected to the action it authorises; a consent record can, which is the difference between having consent and being able to demonstrate it.
Can another organisation see our data?
No. All data is scoped to your organisation. There is no shared pool and no cross-tenant surface for records to leak across.
Is there an audit log?
Yes, organisation-wide, recording material changes with the actor and timestamp — the accountability trail GDPR expects you to be able to produce on request.
Can we export or delete a child's data?
Child records are exportable through the reports screen, and accounts and records can be removed. If you receive a formal access or erasure request, contact us and we will support it.
What security does the platform have?
Multi-factor authentication, recovery codes, active session management, and role-based access control, with health and specialist records behind tighter boundaries than general information.
Do you hold a SOC 2 or ISO 27001 certification?
Not currently. We would rather tell you that plainly than imply an audit we have not completed. What we can describe is the actual architecture: EU residency, organisation scoping, audit logging, and consent as first-class data.
How is this different from US childcare platforms on GDPR?
They were built for a market with a different regime for children's data, and handle European customers through standard contractual clauses — a legal mechanism for transferring data out, not a product designed around keeping it protected.
Who can see which records?
Access follows roles and relationships: parents see their own children, staff see what their permissions allow, and health and specialist journals sit behind narrower boundaries than general records.
Do parents have their own privacy controls?
Yes. Parents manage their own notification preferences, sessions, and account settings, and can see the data held about their children.
Related features
Child Health Log & Medical Records
A timeline of symptoms, medication administered, allergic reactions, and staff notes for each child — visible to that child's guardians, and to nobody else.
Learn more→Incident & Accident Reports
A staff-only register of incidents with severity grading, parent-notification tracking, and PDF export for inspections and insurers.
Learn more→Authorised Pickup & Collection Records
Maintain the list of adults allowed to collect each child, and record which one actually did — a custody trail a signature sheet can't produce.
Learn more→Attendance Tracking for Kindergartens & Nurseries
Digital check-in and check-out, parent-reported absences, and one-click attendance exports — replacing paper sign-in sheets without losing the human moment at the door.
Learn more→Parent Communication & Messaging
Direct messaging between staff and parents with attachments, reactions, search, and an SMS fallback that only fires when a parent won't see the notification otherwise.
Learn more→Announcements & Notice Board
Broadcast notices to the whole facility or a single group, schedule them in advance, reuse templates, and see exactly which parents have received them.
Learn more→