Safeguarding Statement
In effect since 26 September 2026 · Version 3
What this statement is, and what it is not
Little Bees holds safeguarding records on behalf of nurseries. This statement describes how the software protects those records, who can see them, and what we do if something goes wrong with it.
It is not a safeguarding policy for a nursery. Each setting has its own, written against its local safeguarding partnership's procedures, and nothing here replaces it or overrides it. We are not a referral route. If you are worried about a child, contact the nursery's Designated Safeguarding Lead, your local authority's children's services, or the police. In an emergency, call 999. The NSPCC helpline is 0808 800 5000.
Who can see a safeguarding record
Inside a nursery, safeguarding concerns are visible only to staff the nursery has designated — the Designated Safeguarding Lead and anyone they nominate. Being a manager or an owner is not sufficient on its own. This is enforced in the software, not by convention: staff without that designation cannot open the records at all.
Safeguarding notifications cannot be redirected to a general office address. Where a nursery can choose where other kinds of email are sent, safeguarding is deliberately excluded, because widening who receives a concern widens who can read it.
Our administrative tools have no route into a nursery's records. They run separately from each nursery's system and cannot open its database, so nobody using them can read a safeguarding record.
How the records are protected
Safeguarding data is encrypted under its own key, separate from the keys used for personal details, medical information and credentials. This is deliberate: someone obtaining the key that protects contact details still cannot open a safeguarding record.
Each nursery's records are encrypted with keys that belong to that nursery alone. Those keys are kept locked inside the nursery's own database, and the lock is opened only by a master key held as a secret in the platform, never stored alongside the data. A copy of a nursery's database on its own cannot be read, and a key taken from one nursery opens nothing in another.
The master key is generated inside the platform and never leaves it in the clear. Its only backup is an encrypted copy that can be opened solely with a private key the directors hold offline, on encrypted media kept in a safe. Every quarter a director proves that backup still restores.
Owners can refresh their nursery's keys at any time from Nursery settings, and we recommend doing so once a year. Every value is re-sealed under the new keys, and the old ones are retired.
We say this plainly because it matters: Little Bees writes and deploys the software that runs with those keys. The separation described here is how the platform is built and operated. It is not a claim that access by Little Bees is technically impossible.
If we ever have to act on a nursery's keys ourselves, to recover a nursery after a fault or to restore a backup, the action is taken by a director, written to the audit trail, and reported to both directors; a key refresh started by us is reported to the nursery's owner as well.
The audit trail
Every consequential action on a safeguarding record — designating a lead, reviewing a concern, changing a court-order flag — is written to a log that cannot be edited or deleted by anyone, including us and including anyone holding administrative credentials. That restriction is enforced by the database itself, not by a policy about who ought to behave well.
The purpose is narrow and it matters: the trail has to be trustworthy in exactly the circumstance it exists for, which is establishing what a privileged person actually did.
Court orders and who may collect a child
The software records who must not collect a child, and why. That is treated as safeguarding information rather than contact information and is protected under the safeguarding key.
People authorised to collect a child are recorded with a password word used at the door, held with the same protection as any other credential.
Retention
A nursery may be legally required to keep safeguarding records for a considerable period, and that obligation overrides a request to delete them. Where a nursery leaves the platform, safeguarding records are removed on the same schedule as everything else — 365 days after cancellation — unless the nursery tells us its retention obligations require otherwise, in which case it should export them before then; the export is recorded.
If something goes wrong
If we become aware of a breach affecting safeguarding data, we will notify the affected nursery — the controller — without undue delay and in any case within 48 hours of becoming aware, with what we know, so that it can meet its own obligations to the ICO, to its local safeguarding partnership and to families. We cannot make that notification on its behalf.
Our own people
Access to production systems is limited to the fewest people who need it, and requires two-factor authentication. The systems are built so that access to the platform's administrative tools does not confer access to a nursery's records.
Contact
[email protected], with "safeguarding" in the subject line. This address is for questions about how the software protects records. It is not monitored around the clock and it is not a way to report a concern about a child.