Most data breaches in childcare software come from over-permissive APIs, URLs shared in emails that should never have been sent, or staff accounts left active after they leave. Every one of those is a rule the database enforces here, so no screen, export or API route can talk its way past it.
Below is a plain-English summary of how we protect your families’ data, with each claim mapped to the specific control that backs it. If you want the technical detail behind any of them, email security@parentlinkeducation.co.uk.
ParentLink’s access controls are enforced at the database, not the UI. That distinction matters: even if a logged-in staff member crafted a direct API request to read another nursery’s children, the database would return zero rows.
Payment integrations are the highest-stakes part of any nursery software. Forged webhook calls can mark unpaid invoices as paid, trigger refunds, or push fake bank-mandate confirmations. We’re paranoid about this layer.
ParentLink is a Supabase + Vercel application. We’re explicit about this because it’s how you should think about our security posture: the platform layer is best-in-class hyperscale infrastructure; the application layer is where our specific controls live.
In July 2026 we moved the entire production database from the EU to the UK region — every table, every stored file, every scheduled job — and brought it back up on the other side. The whole exercise took about four hours end to end; the database restore itself took seconds. Most of that time was checking, not waiting. It was a migration rather than a drill, but it is the same work a real recovery would need, and it is the reason we can describe our recovery process from experience instead of from a document.
ParentLink is operated by ParentLink Education Ltd, a company registered in Scotland under company number SC900539, and registered with the UK Information Commissioner’s Office under reference ZC232143. You can check both on the public registers rather than taking our word for it.
ParentLink Education Ltd acts as a data processor for nurseries that use the platform. Your nursery is the data controller. We do not sell, share, or repurpose customer data for any reason — and we do not train AI models on it. The full list of sub-processors is on our Privacy page; our data processing agreement is available on request.
Found something? We’d like to hear from you before you tell anyone else.