Privacy notice
Version 1.3 · Last updated 9 August 2026
This privacy notice explains how Nursery Room Ltd ("Yenlio", "we", "us", "our") handles personal data — including children's data — through the Yenlio platform and the Yenlio website. Yenlio is designed to support UK GDPR and early-years data-protection responsibilities under the UK GDPR, the Data Protection Act 2018, the ICO's Age Appropriate Design Code (the "Children's Code") and the EYFS statutory framework. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends UK data-protection law and the Privacy and Electronic Communications Regulations (PECR); we keep this notice current with those reforms.
This notice is governed by the laws of England & Wales.
Who we are and how to contact us
Yenlio is provided by Nursery Room Ltd, a company registered in England & Wales (company number 11237964).
- Registered office / contact address: 375 Bellegrove Road, Welling, Kent, DA16 3RL, United Kingdom
- Privacy / data-protection contact: privacy@yenlio.app
- ICO registration reference: ZA483656 (current; renewal due 10 February 2027)
If you have any question about how your personal data is handled, please contact us at privacy@yenlio.app.
Our roles: controller and processor
Yenlio acts in two distinct roles depending on the data involved.
Yenlio is the controller for its own business and account data — the data we decide the purposes and means of processing for. This includes:
- account registration and administration;
- billing and subscription administration;
- website, demo and sales enquiries;
- customer support;
- security and audit logs;
- product and service improvement; and
- marketing, where lawful.
Yenlio is a processor for the operational records that a nursery, childminder or other childcare provider (our "customer") enters into and runs through the platform. The customer is normally the controller for these records and determines the lawful basis for the data they enter. This processed data includes, for example: children's records; parent and guardian records; staff records entered by the setting; attendance, observations, assessments and reports; SEND and support plans; funding records; invoices and Direct Debit status; medication records; accident and incident reports; consents; parent messages; resources and policies; photo memories; and daily summaries.
When acting as a processor, we process this data only on the customer's documented instructions and under our data processing terms. See our Data Processing Agreement for the contractual detail.
Reporting a problem, and screenshots
If you report a problem from inside Yenlio you can choose to attach a screenshot. This is worth saying plainly, because a screenshot is a picture of whatever was on your screen — it may contain children's names, photographs, health, SEND or safeguarding information.
Attaching one is always your choice and never automatic. Children's photographs are removed before the picture is taken, so they are not in the image at all. Everything else starts obscured, only what you deliberately reveal is included, and you review the exact image that will be sent before it leaves your device. Nothing is sent until you confirm.
The report goes to our helpdesk provider (see Sub-processors), and any image goes with it. We keep our own copy in the United Kingdom, restrict it to Yenlio support staff, record each time one of them opens it, and delete it 30 days after your ticket is resolved or 90 days after it was sent, whichever comes first. The copy held by the helpdesk provider is governed by that provider's own terms and retention.
Categories of personal data we process
Depending on your relationship with Yenlio, we may process:
- account, profile and contact data (names, email addresses, roles, login identifiers);
- setting details (nursery/childminder name, address, registration and configuration);
- child records and care information;
- parent and guardian contact details and parental-responsibility status;
- staff user data entered by the setting;
- attendance and register data;
- observations and learning-journey entries;
- assessments and reports;
- SEND and support information where entered;
- accident and incident reports;
- medication and health records;
- consent forms and electronic signatures;
- invoices, payments and Direct Debit status;
- communications and messages;
- photos, videos and associated media metadata;
- audit logs, security logs, and device/session data; and
- AI and translation inputs and outputs where those features are enabled.
Special-category and sensitive data
Some operational childcare records contain special-category or otherwise sensitive personal data, which we process on behalf of and under the control of the customer. This may include:
- health and medication information;
- SEND and disability-related information;
- accident and incident details;
- safeguarding-adjacent notes; and
- ethnicity, language, religion and dietary information where entered by the nursery and relevant.
We apply additional safeguards to this data and process it only as instructed by the customer.
Lawful bases for processing
Where Yenlio is the controller, we rely on one or more of the following lawful bases:
- Contract — to provide and administer the service you or your setting have signed up for;
- Legitimate interests — to run, secure and improve our services and to communicate with customers and enquirers, balanced against your rights;
- Legal obligation — where the law requires us to process or retain data; and
- Consent — where appropriate, for example certain marketing communications, which you can withdraw at any time.
Because Yenlio is often a processor for operational childcare records, the customer (as controller) determines the lawful basis for the records they enter. Depending on the record, the customer may rely on bases including contract, legitimate interests, legal obligation, consent or explicit consent, and — for special-category data — bases such as substantial public interest, the provision of health or social care, or safeguarding-related conditions. These choices and controls sit with the customer.
AI and translation features
Where enabled by feature and entitlement, Yenlio offers optional AI assistance powered by Anthropic Claude via AWS Bedrock, depending on the feature.
AI features in Yenlio are assistive only. They draft, summarise or review content to save staff time. They do not make automated decisions about safeguarding, medical or medication matters, payments, invoice corrections, accidents, SEND or legal matters. Staff review and approval are always required before any AI-assisted content is relied upon or acted on. AI does not perform profiling that produces legal or similarly significant effects on individuals.
Yenlio also offers optional machine translation powered by DeepL as a convenience. Machine translation may not be perfect and is not certified human translation. If a translation appears wrong or unclear, parents and staff should contact the nursery, which can confirm the original wording.
Address lookup
To save typing and reduce mistakes, address fields in Yenlio offer suggestions as you type. When you have typed a few characters, that partial address or postcode is sent to our address provider, AutoPostcode, which returns matching UK addresses from Royal Mail's Postcode Address File.
Only what you type is sent. No name, child, parent, staff member or setting is identified in the request, and because the search is made by our servers rather than your browser or app, the provider does not receive your device's IP address. Each search carries a short random reference so the provider can tell that several keystrokes are one search rather than many; it is not derived from you, your setting or what you typed, and it is discarded the moment the search ends.
Suggestions only fill in the fields you are editing. Nothing is saved until you save the record, and the lookup never changes addresses already held on signed documents or historical records.
If you would rather not use it, simply type the address in as normal — every address field still works exactly as it did before.
Payments
Direct Debit and payment processing is handled by our payments provider, GoCardless. Yenlio does not store full bank details. We store payment status, mandate and payment identifiers, invoice status and related audit records. GoCardless processes Direct Debit and payment data as a separate provider under its own terms and safeguards.
How we share data
We share personal data only where necessary, with:
- authorised users of the customer (for example, the setting's staff) according to their roles and the customer's configuration;
- parents and guardians, as configured by the customer;
- sub-processors that help us run the service — our current list is maintained on our sub-processors page;
- regulators, law-enforcement and other authorities, where we are legally required or permitted to do so; and
- professional advisers (such as legal, accounting or security advisers) where needed.
We do not sell personal data, and we do not share personal data for advertising.
International transfers
Yenlio's primary hosting and storage is in the United Kingdom and Ireland/EU. Where a specialist sub-processor is used, Yenlio requires appropriate contractual, security and transfer safeguards and maintains an up-to-date sub-processor list at /subprocessors.
How long we keep data
- Operational customer data is retained while the account is active and is handled in line with the customer's instructions and EYFS requirements. After termination, we provide for export and deletion of customer data.
- Backups may be retained for a limited period before being overwritten or deleted.
- Audit and security logs are retained longer where required to protect the platform and meet our obligations.
- Payment and compliance records are retained for as long as legally required.
- Account deletion — you can delete your Yenlio account from within the app (Profile → Delete account). Your account is archived and can be reactivated by signing in again within 30 days, after which your login and personal contact details are permanently erased. Records a setting is legally required to keep (for example accident or medication records) are retained by the setting as controller; where a staff member authored such a record, their name is retained on that record for the required period.
Where Yenlio is a processor, retention of operational childcare records is ultimately determined by the customer as controller.
Your rights
Under UK data protection law you have rights to:
- access your personal data;
- have inaccurate data corrected;
- have data deleted in certain circumstances;
- restrict processing;
- object to processing;
- data portability; and
- complain to the Information Commissioner's Office (ICO) at ico.org.uk.
For children's data held in Yenlio, the relevant setting is the controller. Please route such requests to that setting; Yenlio will support the setting in responding. For data where Yenlio is the controller, contact us at privacy@yenlio.app. We would welcome the chance to resolve any concern before you approach the ICO.
Children's privacy
Yenlio is built for nursery and parent use — it is not a child self-service product. In line with the Children's Code, we apply high privacy defaults and data minimisation, restrict access to authorised users, and do not engage in behavioural advertising to children. We do not sell personal data. Children's operational records are processed on behalf of, and under the control of, the setting. See our children's data page for more.
Security overview
We take a layered approach to security, which includes (where implemented): encryption of data in transit and at rest; role-based access controls; audit logging; multi-factor authentication and passkeys where available; tenant isolation between settings; and continuous monitoring. This is a short overview — for more detail, see our Security page.
Complaints and contact
If you have a concern about how your personal data is handled, please contact us first at privacy@yenlio.app so we can help. You also have the right to complain to the ICO at ico.org.uk.
Related documents: Terms · Data Processing Agreement · Sub-processors · Security · Cookies · Children's data