Legal

Children's data & safeguarding

Version 1.0 · Last updated 30 June 2026

Yenlio is a nursery management platform provided by Nursery Room Ltd, trading as Yenlio. This statement explains how we look after children's data, the high privacy defaults we build in, and our deliberately limited, assistive-only use of AI. It is designed to support UK GDPR, the ICO Children's Code (Age Appropriate Design Code), the Early Years Foundation Stage (EYFS) framework and early-years safeguarding responsibilities.

For the full detail of how personal data is handled, please read it alongside our Privacy notice and our list of Sub-processors.

Who Yenlio is for

Yenlio is built for early-years settings and for parents and guardians — not for children to use directly. Children do not log in, do not hold accounts and are not asked to manage anything themselves. Records about a child are created and managed by the nursery or childminder, with parents and guardians given controlled access by their setting. This is a deliberate design choice: it keeps children out of any account-management surface and keeps responsibility with the adults who care for them.

Who controls children's data

Your nursery or childminder is the controller of the children's data held in Yenlio. They decide what information is recorded, what is shared and who can see it. Yenlio acts as their data processor — we provide the platform and process data on their instructions, on their behalf.

Because the setting is the controller, parent and guardian access is configured and controlled by the setting, not by Yenlio.

What children's data Yenlio may hold

On behalf of a setting, Yenlio may store the kinds of records an early-years provider needs to care for a child and meet its statutory duties, including:

  • Observations and learning notes that build a child's EYFS journey
  • Attendance records (check-in and check-out)
  • Care logs — meals, sleep, nappies and toileting
  • Medications and administration records
  • Accidents and incidents
  • SEND and support information (special educational needs and disabilities)
  • Photos and videos
  • Consents recorded by parents and the setting
  • Reports and assessments shared with parents
  • Invoices and billing information

We only hold what the setting needs to provide care and meet its responsibilities. We do not collect children's data for our own purposes.

Privacy by design and high privacy defaults

We build Yenlio with privacy as the default rather than an option:

  • Data minimisation — settings record only the information needed for care and statutory duties.
  • High privacy defaults — features that share or publish information are off until a setting deliberately turns them on, and consent is never assumed.
  • Tenant isolation — each setting's data is kept separate, and access is scoped so staff only see the children at their own setting.
  • Auditability — sensitive actions are recorded so a setting can see who did what and when.

Photos, videos and media consent

Photos and videos are treated with particular care. Consent is recorded per purpose — for example, internal records, sharing with a child's own parents, group posts, or wider promotional use — and is never assumed. The setting controls publication and sharing, and where parents or guardians disagree, the most restrictive answer applies: one person's "yes" never overrides another's "no".

Accidents, medication and other sensitive records

Accident, incident and medication records carry extra weight because they concern a child's health and welfare. They are handled with additional care, clear authorship and audit trails, so a setting can rely on them as accurate, accountable records.

AI and translation safeguards

Some Yenlio features use AI to assist staff. This is strictly assistive and the rules are firm:

  • AI never makes decisions about safeguarding, medication or medical care, SEND, accidents or child welfare. It may help draft, summarise or suggest, but a person always decides.
  • Staff and the nursery retain professional judgement and review or approve anything AI helps produce before it is relied upon or shared.
  • Translation is convenience machine translation. It helps families read updates in their own language but may not be perfect, and it is never the authoritative version of a legal, signed or safety-critical document.

Children's data is used only to provide the feature a setting has enabled. We do not use children's data to train third-party models beyond delivering that enabled feature.

What we never do

  • We do not sell children's data.
  • We do not show behavioural or targeted advertising to children — Yenlio carries no advertising of this kind at all.
  • We do not use children's data to train third-party AI models beyond providing the feature a setting has switched on.

Where data is stored

Children's data has its primary hosting and storage in the UK and Ireland/EU. Some specialist sub-processors (for example, for messaging, email or translation) may process limited data, and only under appropriate safeguards. Our Sub-processors page lists who they are and what they do.

If a record looks wrong

If you believe a record about your child is inaccurate or out of date, please contact your nursery or childminder — they are the controller and can correct it. Yenlio supports settings in keeping records accurate, but we do not change a setting's records on our own initiative.

If you have a concern

  • Speak to your nursery or childminder first. As the controller, they can answer most questions about what is recorded and shared, and act on requests about your child's data.
  • Contact Yenlio for questions about the platform itself at privacy@yenlio.app.
  • Complain to the ICO. You can contact the Information Commissioner's Office (the UK data protection regulator) at ico.org.uk if you are not satisfied with how a concern has been handled.

Nursery Room Ltd trading as Yenlio · privacy@yenlio.app