Security & Privacy for Centres
How EarlyReady protects child data, and where responsibility sits between us and your service.
Last updated: September 2026
Who is responsible for what
EarlyReady is software sold to early childhood services. Under Australian privacy law, your service is the data controller responsible to families, and EarlyReady is the data processor that securely handles data on your behalf. This page explains that split clearly.
A note on data minimisation. EarlyReady is built to work with non-identifying references (e.g. "Child L" or initials) rather than full personal details. Wherever practical, we encourage using pseudonyms and entering only what's needed to do your work — less identifying data means less risk and simpler obligations for your service.
What EarlyReady handles (as your processor)
- Encrypted data storage (in transit and at rest) on secured infrastructure
- Per-user access controls — each educator only sees their own records by default
- Role-based access controls and secure authentication
- AI guardrails that prohibit fabricating observations or medical advice
- AI prompts are sent to our LLM sub-processor for generation only — not stored or republished by us
- No selling, advertising-sharing or on-selling of centre data
- Prompt breach notification to affected centres
- Full data export and deletion when a centre leaves the platform
What your service handles (as the controller)
The software gives you tools to help with these, but the legal duty to families sits with your service.
- Telling families what data is collected and why (collection notice)
- Obtaining and recording informed consent from parents
- Deciding what child data to enter (the app supports non-identifying references)
- Staff training on privacy and child-safe practice
- Retention schedules and timely deletion of old records
- Responding to family requests for access or correction
- Their own privacy policy and breach response to the OAIC
- Meeting state child-safe standards and mandatory reporting
Security safeguards
Encryption. All data is encrypted in transit (TLS) and at rest.
Access controls. Per-user row-level security means each educator only sees their own records by default. Centre-level tenant isolation is configurable for multi-staff services.
Roles. Admin and user roles control who can manage account settings and team members; all authenticated access is gated behind secure login.
Authentication. Secure login with optional OAuth (Google) and password reset flows.
Audit trail. Records are timestamped and attributed to the user who created or modified them.
Secure file storage. Uploaded documents (immunisation records, certificates) are stored as files with signed access URLs, not embedded in database fields.
Sub-processors
We engage the following third parties to process centre data on our behalf. Each is bound by contractual data-protection terms.
Our AI features are powered by Anthropic Claude Opus 4.8. Prompts are sent to Anthropic for generation only and are not stored or republished by us. We encourage your service to review Anthropic's privacy and data practices at anthropic.com as part of your own due diligence.
Data Processing Agreement
A Data Processing Agreement (DPA) is available to all centre customers. It sets out our obligations as your processor, breach notification timelines, sub-processor lists, and data return/deletion on termination. Request a copy before or during onboarding.
Data breach response
If a security incident affecting your centre's data occurs, EarlyReady will notify your service promptly so you can meet your own reporting obligations under the Notifiable Data Breaches scheme. Your service remains responsible for assessing and notifying the OAIC and affected families where required.
Important
This page describes the technical and organisational safeguards EarlyReady provides as a software vendor. It is general information, not legal advice or a compliance certification. Your service remains responsible for its own privacy obligations to families under the Privacy Act 1988, your state's ECEC law, and child-safe standards. For formal compliance guidance, consult your peak body (ECA, CELA) or a privacy professional.
Need a DPA or have security questions?
We're happy to provide a Data Processing Agreement and answer due-diligence questions during your evaluation.
© 2026 EarlyReady · This is general information, not legal advice.
