Security measures
Version 1.0 · Last updated 30 June 2026
This schedule describes the technical and organisational security measures that Nursery Room Ltd (trading as "Yenlio", "we", "us", "our") applies to protect personal data — including children's data — processed through the Yenlio platform. These measures support our obligations under our Data Processing Agreement and are kept under review as the service and the threat landscape change.
Where a measure depends on the platform, database, storage or another provider, we have qualified it accordingly. We do not hold formal certifications such as ISO 27001 or SOC 2, and we do not present these measures as a blanket statement of "GDPR compliance" — they are the controls we have in place to protect data.
Tenant isolation and per-nursery scoping
Yenlio is multi-tenant. Every operational record is scoped to the setting (nursery, childminder or other provider) it belongs to, and queries are filtered by that setting so one customer's data is kept separate from another's. This per-setting scoping is a core design rule of the platform.
Role-based access control and least privilege
Access within a setting is governed by role-based access controls. Staff roles carry only the permissions appropriate to their function, and access is granted on a least-privilege basis. Sensitive actions are gated by the relevant role, and cross-setting administrative powers are separated from a person's ordinary role within their own setting.
Parent access scoped through the child relationship
Parents and guardians do not have open access to a setting's records. Their access is derived from their linked children through the child and contact relationship: a parent sees only the records that have been made available for the children they are linked to, and nothing for other children or other settings.
Authentication: multi-factor, passkeys and trusted devices
Where available, the platform supports multi-factor authentication, passkeys and trusted-device recognition to strengthen sign-in. Passwords are checked against known-breached-password datasets at the point they are set, and personal identification numbers (PINs) used for quick access meet a minimum length.
Encryption in transit and at rest
Personal data is encrypted in transit using current transport-layer security. Data at rest is encrypted where the underlying platform, database and storage services provide encryption. Public traffic is routed through a security and content-delivery layer that adds edge protection in front of the application.
Secrets management
Credentials, API keys, signing keys and similar secrets are held in a managed secrets store and loaded by the application at runtime. They are not committed to source code. Non-sensitive configuration is kept separate from sensitive secrets.
Audit logging
The platform records audit logs for sensitive actions. This includes audit trails for Direct Debit and payment activity, accident and incident reports, medication records, consent changes, and — where AI features are used — a record of AI usage. Audit entries capture who did what and when, supporting accountability and investigation.
Monitoring and observability
We use monitoring and observability tooling to detect and investigate issues, including AWS CloudWatch for logs and metrics, AWS CloudTrail for account-level activity, and Sentry for application error monitoring. Alerts surface anomalies and failures for review.
Backup and recovery
The platform takes regular backups to support recovery. Backups are retained for a limited period before being overwritten or deleted, consistent with our retention approach.
Vulnerability and dependency management; secure development
We follow secure development practices, including code review before changes are merged, automated testing, and dependency management to keep components current. We monitor for vulnerabilities and address them as part of routine maintenance. We maintain an incident-response approach so that suspected security events are assessed and handled, and affected customers and regulators are notified where required.
Staff and administrative access controls
Internal access to systems and data is granted on a need-to-know basis and is limited to what a person requires for their role. Staff and administrators are subject to confidentiality obligations. Emergency administrative access is controlled, time-limited and audited.
Data minimisation and use limits
We apply data minimisation, collecting and processing only what is needed for the relevant purpose. We do not sell personal data, and we do not carry out behavioural advertising to children.
Data residency
Yenlio's primary hosting and storage is in the United Kingdom and Ireland/EU. Where a specialist sub-processor is used, Yenlio requires appropriate contractual, security and transfer safeguards and maintains an up-to-date sub-processor list at /subprocessors.
AI and translation
AI features are assistive only — they draft, summarise or review content to save staff time and do not make automated decisions; staff review and approval are always required. Translation is convenience machine translation and is not certified human translation.
Sub-processor governance
Where we use sub-processors to help run the service, we require appropriate contractual, security and transfer safeguards. Our current sub-processors are listed on our sub-processors page.
Questions
For security or privacy questions, contact us at privacy@yenlio.app. These measures evolve over time as the service and the threat landscape change.
Related documents: Privacy notice · Data Processing Agreement · Sub-processors