OUR PROGRAM
General Data Protection Regulation Policy
OUR PROGRAM
Programs and
Schedules
General Data Protection Regulation Policy
General Data Protection Regulation Policy (Children, Parents and Visitors)
Statement
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act (2018) set out how personal information must be handled. Personal data must be processed lawfully, fairly, and transparently, collected for specific and legitimate purposes, and only used with the individual’s knowledge and, where required, explicit consent. These regulations apply to all personal data relating to identifiable individuals.
Toddlers Inn is committed to protecting the rights and freedoms of individuals with respect to the processing of children’s, parents, visitors, and staff personal data. The Data Protection Act gives individuals the right to know what information is held about them. It provides a framework to ensure that personal information is handled properly.
Toddlers Inn is registered with the ICO (Information Commissioners Office) under registration reference: ZA203890 Certificate is on display on the parents’ information board in the nursery.
Laura is Toddlers Inn Designated Data Protection Officer (DPO) and takes responsibility for data protection compliance; Nursery Deputy Manager takes the responsibility of Secondary Data Protection Officer.
GDPR includes 7 rights for individuals:
1)The right to be informed
Toddlers Inn is registered Childcare provider with Ofsted and as so, it is required to collect and manage certain data. We need to collect information regarding child and his parents in order to comply with Safeguarding, Health and Safety Policies as well as the Government and Local Authorities guidelines e.g. for parents claiming the free nursery entitlement we are requested to provide certain data to the Local Council; this information is sent to the Local Authority via a secure electronic file transfer system.
We are required to collect certain details of Nursery visitors. We need to know visitors’ names, telephone numbers, addresses and where appropriate company name.
Toddlers Inn uses Cookies on its website to collect data for Google Analytics; this data is anonymous.
2) The right of access
At any point an individual can make a request relating to their data and Toddlers Inn will need to provide a response without undue delay and within one month of receipt. Toddlers Inn can refuse a request, if we have a lawful obligation to retain data i.e. from Ofsted in relation to the EYFS, but we will inform the individual of the reasons for the rejection. The individual will have the right to complain to the ICO if they are not happy with the decision.
3) The right to erasure
An individual has the right to request the deletion of their data where there is no compelling reason for its continued use. However, Toddlers Inn has a legal duty to keep children’s and parent’s details for a reasonable time.
4) The right to restrict processing
Parents and visitors can object to Toddlers Inn processing their data. This means that records can be stored but must not be used in any way, for example reports or for communications.
5) The right to data portability
Toddlers Inn requires data to be transferred from one IT system to another, e.g. from Toddlers Inn to the Local Authority or to Eylog. These recipients use secure file transfer systems and have their own policies and procedures in place in relation to GDPR.
6) The right to object
Parents and visitors can object to their data being used for certain activities like marketing or research.
7) The right not to be subject to automated decision-making including profiling
Automated decisions and profiling are used for marketing-based organisations. Toddlers Inn does not use personal data for such purposes.
Complaints and individual requests
Any requests regarding personal data held by Toddlers Inn should be addressed in writing to the Nursery Manager (Secondary Data Protection Officer). It is the Manager’s responsibility to communicate those requests to Toddlers Inn Data Protection Officer.
Parents and visitors should ask for help from the Nursery Manager (Secondary Data Protection Officer) if they are unsure about data protection or if they wish to make a written complaint or notice any areas of data protection or security to be improved upon. Toddlers Inn Data Protection Officer is the person responsible of handling any complaints made by parents or visitors.
Storage and use of personal information
Toddlers Inn seeks parents’ consent to collect and process information about a child regarding:
Developmental records
- These include observations of children in the setting, photographs, video clips, summary developmental reports as well as photos and samples of their work that can be used as a part of displays in the nursery
Personal records
- These include registration and admission forms (including parents telephone numbers, collection passwords, emergency contact details, as well as parents’ emails; those will be used for contacting in case of emergency as well as for sending nursery newsletters, statements of charges, information about nursery events and nursery updates.
- Signed consent forms, child’s GP details,inoculation details, correspondence concerning the child or family, child’s health and medical details including any allergies, child’s daily routine, information regarding funding, reports or minutes from meetings concerning the child from other agencies, an on-going record of relevant contact with parents, and observations by staff on any confidential matter involving the child, such as developmental concerns or child protection matters but also information that may include racial or ethnic origin, religious or other beliefs.
Accident reports must be kept until the child is 21 years and 3 months (this is serious accidents reportable to OFSTED, e.g. head injuries, scalds and broken limbs, not your everyday trip and falls, lumps and bumps). Everyday accident records will be kept with the child’s other records for the general 7 years’ timeframe.
Safeguarding Records & Cause for Concern forms must be kept until the child/young person is 25 years old.
Insurance Certificates are required to be kept for 40 years. This data is archived securely and destroyed after the legal retention period.
In case of the nursery closing all the safeguarding records are given to the Local Safeguarding Children’s Board (LSCB) for safe keeping for the duration of the retention period.
All the electronic copies of children’s records are kept on the Office computer or Office iPad. Information regarding child’s developmental records like observations, snapshots, photos, and videos is also kept on Eylog tablets and iPads. Those are all password protected and will be erased after the retention period.
All paper copies of children’s records are kept in a lockable cabinet in the Office. Staff members can have access to these files, but information taken from the files about individual children is confidential and apart from archiving, these records should always remain on site. These records will be shredded after the retention period.
Information about individual children is used in certain documents, such as, a weekly register, medication forms, referrals to external agencies and disclosure forms. These documents include data such as children’s names, date of birth and sometimes address. These records will be password protected if stored electronically on an external hard drive or Google Drive; if in paper format these records will be kept in a lockable filing cabinet in the Manager’s Office or if archived in a lockable cabinet in the Nursery. These records will be permanently destroyed after the relevant retention period.
Toddlers Inn collects a large amount of personal data every year including names and addresses of those enquiring for nursery spaces. These records are permanently erased if the child does not attend or added to the child’s file and stored appropriately.
Upon a child leaving Toddlers Inn and moving on to school or moving settings, data held on the child may be shared with the receiving school. Such information will be sent via post service or via a secure file transfer system.
Toddlers Inn stores child’s personal data held visually in photographs or video clips unless written consent has been obtained by a child’s parent. No names are stored with images in photo albums, on the website or on Toddlers Inn social media sites.
Access to all Office computers and iPads, nursery PCs, laptops as well as Eylog, and tablets are password protected. When a member of staff leaves the company, these passwords are changed. Any portable data storage used to store personal data, e.g. USB memory stick, are password protected and/or stored in a lockable filing cabinet in the Manager’s Office.
If data has been accessed unlawfully, the relevant parties must be immediately informed, and the Information Commissioner’s Office needs to be notified within 72 hours. The information on how to notify ICO can be found on https://ico.org.uk or by calling ICO helpline on 0303 123 1113.
This Policy was adopted by the Toddlers Inn Nursery on the 10.07.2020
This Policy was reviewed by the Toddlers Inn Nursery on the 04.08.2025
Classes and Pre-School
Discover our diverse classes designed to cater to children of different age groups:

Butterfly Class
18 month - 24 month

Bumblebee Class
2 years - 2.6 years

Ladybirds Class
2.6 years - 3 years

Grasshoppers Class
3 years - 3.6 years

Dragonflies Class
3.6 years +
Engaging Activities for Every Child
Here are our dates for the ongoing Summer 2023 term at Toddler’s Inn Nursery and Pre-School.
Autumn term start: Wednesday, 6th of September 2023
Autumn term end: Friday, 15th of December 2023
Spring term start: Monday, 8th January 2024
Spring term end: Friday, 31st of March 2024
Summer term start: Tuesday, 18th of April 2024
Sumer term end: Friday, 14th of July 2024