Privacy Notice
In effect since 22 September 2026 · Version 2
Who we are, and which of us holds your data
Little Bees is nursery management software and a public directory of Ofsted inspection records, operated by Swarm Labs.io ("Little Bees", "we"). Two different relationships sit behind that sentence, and which one applies decides who you should contact.
Your nursery is the controller of your family's data. Everything about a child — their record, observations, attendance, allergies, safeguarding notes — belongs to the nursery. It decides what is collected and why. We hold that data on the nursery's behalf and act on its instructions: we are the processor.
If you are a parent and you want to see, correct or delete what is held about your child, ask your nursery. It can answer, and it is the only party that can. We cannot make that decision for it.
Two things we control ourselves. First, the accounts and contact details of the people who sign up for Little Bees, subscribe, ask for a demo or write to us. Second, Nursery Intelligence: inspection and registration information about early years settings, gathered from Ofsted's public register and published reports. That information is about businesses and is already public; it contains nothing about any child. How we publish it, and how a setting can have its page corrected or object to it, is set out in our public listings policy.
What is held
For children and families, on a nursery's behalf: names, dates of birth, photographs, observations, attendance, allergies and medical conditions, dietary requirements, medication, safeguarding concerns and any referrals arising from them, court orders, guardians' contact details, invoices and payments, and consents.
For staff, on a nursery's behalf: employment records, DBS certificate numbers, appraisals and pay.
For people authorised to collect a child: their name, contact details, and the password word used at the door.
For account holders, in our own right: name, email address, the nursery you belong to, sign-in sessions, and — if you subscribe — the billing details our payment provider needs.
Much of what a nursery holds is special category data under the UK GDPR: health information, and anything touching safeguarding.
Why we process it, and on what basis
As a processor we act on the nursery's documented instructions; the nursery decides the purpose and the lawful basis, usually the performance of its contract with a family and its legal obligations under the Early Years Foundation Stage framework.
As a controller: we process account holders' details to provide the service you signed up for (performance of a contract); we keep financial records because the law requires it (legal obligation); we publish Nursery Intelligence in our legitimate interest in making Ofsted's public record easier to read, an interest we have weighed against settings' interests and answer to through the correction and objection process in the public listings policy; and we send service emails because the service cannot work without them. We do not send marketing email to anyone who has not asked for it.
Where it is kept, and how it is separated
Each nursery's data lives in its own database and its own file storage, reachable only by software holding the keys to that one pair. One nursery's system cannot name another's database. This is a structural separation, not a filter applied at read time.
Accounts and sign-in sessions are the exception: they are shared across the platform and separated by code rather than by structure, because signing in has to work before we know which nursery you belong to. We state that rather than describe the separation as absolute when it is not.
Encryption
Personal details, medical information, safeguarding records and credentials are encrypted field by field before they are stored, under four separate keys so that a key for one purpose cannot open another.
The keys are held as secrets in the platform, never in the database. Someone who obtained a copy of a nursery's database without those keys would find first names and little else: no surnames, addresses, dates of birth, contact details or medical notes. Today the same four keys serve every nursery, and Little Bees holds the copies needed to run and recover the service; we are moving each nursery onto keys of its own. Our administrative tools have no route into a nursery's records.
Some fields are deliberately not encrypted, and we would rather say so than imply otherwise. Children's and staff first names are searchable, as are the dates and statuses that staffing-ratio and funding calculations depend on. Encrypting a column makes it unsearchable, and a nursery that cannot search its own register cannot run a session.
Who else sees it
| Who | What they receive | Why |
|---|---|---|
| Cloudflare | Everything — they host the platform | The software runs on their infrastructure |
| Stripe | A payer's name, email address and card details; invoice amounts | Taking subscription payments, and fees a parent pays a nursery |
| Mailgun (EU region) | The recipient's address and the message | Password resets, portal invitations, report notices, alert digests |
| ElasticEmail | The same, only if Mailgun is unavailable | Fallback email sender |
| Google Analytics | Anonymous usage of the public website only — never anything from inside the app | Understanding which public pages are read; see the cookie policy |
A nursery using its own email server sends its mail through that server instead, and neither email provider sees anything of theirs.
We also look up postcodes to place nurseries on the Nursery Intelligence map. That service receives published nursery addresses only — never a family's address and never a member of staff's.
Cloudflare and Stripe operate worldwide. Where personal data leaves the United Kingdom it does so under safeguards the UK recognises — the UK International Data Transfer Agreement or Addendum, or an adequacy decision — and under each provider's own data processing terms.
How long it is kept
| When | Removed after |
|---|---|
| A trial ends without a subscription | 31 days |
| A subscription is cancelled | 365 days |
| Financial records | 6 years, as HMRC requires |
Deletion is real. When a nursery's retention period ends, the software, the database and the stored files are destroyed — it is not a flag set on a row that leaves the data in place. A nursery may ask for deletion sooner.
Account details we hold in our own right are deleted when the account is closed, apart from financial records. Nursery Intelligence is refreshed from Ofsted's register and kept while the setting is on it; a removed page stays removed.
Your rights
You can ask for a copy of what is held, ask for corrections, ask for deletion, object to processing, and ask for your data in a portable form.
For anything about a child, a family or a member of staff at a nursery, ask the nursery — it is the controller and the request is its to answer. We help it answer: every export a nursery runs is recorded, so "which exports included my child's data" can be answered rather than estimated.
For your own Little Bees account, or for a Nursery Intelligence page, write to us at the address below. We answer within one calendar month.
Two honest limits. Financial records must be kept for six years whatever else is requested. And a nursery may be legally required to retain safeguarding records — that obligation exists to protect children and it overrides a deletion request.
If you are not satisfied with how a request has been handled you can complain to the Information Commissioner's Office at ico.org.uk, the UK's data protection regulator.
Security incidents
If we become aware of a breach affecting a nursery's data we tell that nursery — the controller — without undue delay and in any case within 48 hours of becoming aware, with what we know, so that it can meet its own obligations to the ICO and to families. We cannot make that notification on its behalf. For data we control ourselves we notify the ICO where the law requires it, within 72 hours.
Contact
Data protection contact: [email protected]. Write "data protection" in the subject line and it reaches the right person. Postal enquiries can be sent to Swarm Labs.io, marked for the attention of Little Bees data protection.
Changes to this notice
Every published version of this notice is kept with the date it took effect, so what applied at any given time can be established rather than recalled. We tell subscribing nurseries before a material change takes effect.