Privacy Policy

Policy Statement

Privacy is acknowledged as a fundamental human right. Our Service has an ethical and legal responsibility to protect the privacy and confidentiality of children, individuals and families as outlined in Early Childhood Code of Ethics, National Education and Care Regulations and the Privacy Act 1988 (Cth). The right to privacy of all children, their families, and educators and staff of the Service will be upheld and respected, whilst ensuring that all children have access to high quality early years care and education. All staff members will maintain confidentiality of personal and sensitive information to foster positive trusting relationships with families.

To ensure that the confidentiality of information and files relating to the children, families, staff, and visitors using the Service is upheld at all times. We aim to protect the privacy and confidentiality of all information and records about individual children, families, educators, staff and management by ensuring continuous review and improvement on our current systems, storage, and methods of disposal of records. We will ensure that all records and information are held in a secure place and are only retrieved by or released to people who have a legal right to access this information.

Under National Law, Section 263, Early Childhood Services are required to comply with Australian privacy law which includes the Privacy Act 1988 (the Act) aimed at protecting the privacy of individuals. Schedule 1 of the Privacy Act (1988) includes 13 Australian Privacy Principles (APPs) which all services are required to apply. The APPs set out the standards, rights and legal obligations in relation to collecting, handling, holding and accessing personal information.

The Notifiable Data Breaches (NDB) scheme requires Early Childhood Services, Family Day Care Services, and Out of School Hours Care Services to provide notice to the Office of the Australian Information Commissioner (formerly known as the Privacy Commissioner) and affected individuals of any data breaches that are 'likely' to result in 'serious harm'.

Businesses that suspect an eligible data breach may have occurred, must undertake a reasonable and expeditious assessment to determine if the data breach is likely to result in serious harm to any individual affected. A breach of an Australian Privacy Principle is viewed as an 'interference with the privacy of an individual' and can lead to regulatory action and penalties.

source: OAIC Australian Privacy Principles

Australian Privacy Principles (APPs)

APP 1 – Open and transparent management of personal information

Ensures that APP entities manage personal information in an open and transparent way. This includes having a clearly expressed and up to date APP privacy policy.

APP 2 – Anonymity and Pseudonymity

Requires APP entities to give individuals the option of not identifying themselves, or of using a pseudonym. Limited exceptions apply.

APP 3 – Collection of solicited personal information

Outlines when an APP entity can collect personal information that is solicited. It applies higher standards to the collection of 'sensitive' information.

APP 4 – Dealing with unsolicited personal information

Outlines how APP entities must deal with unsolicited personal information.

APP 5 – Notification of the collection of personal information

Outlines when and in what circumstances an APP entity that collects personal information must notify an individual of certain matters.

APP 6 – Use or disclosure of personal information

Outlines the circumstances in which an APP entity may use or disclose personal information that it holds.

APP 7 – Direct marketing

An organisation may only use or disclose personal information for direct marketing purposes if certain conditions are met.

APP 8 – Cross-border disclosure of personal information

Outlines the steps an APP entity must take to protect personal information before it is disclosed overseas.

APP 9 – Adoption, use or disclosure of government related identifiers

Outlines the limited circumstances when an organisation may adopt a government related identifier of an individual as its own identifier, or use or disclose a government related identifier of an individual.

APP 10 – Quality of personal information

An APP entity must take reasonable steps to ensure the personal information it collects is accurate, up to date and complete. An entity must also take reasonable steps to ensure the personal information it uses or discloses is accurate, up to date, complete and relevant, having regard to the purpose of the use or disclosure.

APP 11 – Security of personal information

An APP entity must take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. An entity has obligations to destroy or de-identify personal information in certain circumstances.

APP 12 – Access to personal information

Outlines an APP entity's obligations when an individual requests to be given access to personal information held about them by the entity. This includes a requirement to provide access unless a specific exception applies.

APP 13 – Correction of personal information

Outlines an APP entity's obligations in relation to correcting the personal information it holds about individuals.

Policy Guidelines

Personal Information

The personal information that the service collects are:

  • Contact details of children, families, staff, students, volunteers and management
  • Children, families, staff, students, volunteers, emergency contacts contact details
  • Children's health status, immunisation and developmental records and plans, external agency information, custodial arrangements, incident records, and medication records
  • Staff documentation relating to recruitment and selection, performance reviews, qualifications, work history, child protection checks, health status, immunisation records and workers' compensation claims
  • Student and volunteer work history, child protection checks
  • Information relating to families' Child Care Benefit (CCB) status and any other additional funding arrangements

Our service

  • Will provide lockable storage facilities, such as filing cabinets to ensure that all confidential documents are securely maintained
  • Will adopt the following principles for handling personal information based on the Privacy Act (1988):
    • Collection of information will be lawful and fair
    • People will be told why information is collected
    • Personal information collected will be of good quality and not too intrusive
    • Personal information will be properly secure
    • People will have access to their own records
    • It will be ensured that personal information is of good quality and people will be allowed to have it changed where it is not
    • It will be ensured that personal information is of good quality before use
    • Use of personal information will be relevant
    • The use of personal information will be limited
    • The disclosure of personal information outside the agency will not be allowed
  • Will ensure every employee understands that information stored in the children's rooms is treated as confidential and is controlled under the guidelines of the policy and the Australian Privacy Act 1988 as below:
    • What information is to be kept confidential:
      • Child contact information
      • Enrolment summaries and information
      • Individual child programs
      • Medication, illness and incident forms
      • Parent meeting minutes
      • Behaviour management plans
    • The Director may forward confidential information to staff in order for them to fulfil their responsibility. This information may include:
      • Children's date of birth
      • Emergency contact phone numbers
      • Children's additional needs information
      • Children's allergy information
      • Children's dietary information
    • Who has a legal right to know what information:
      • Information regarding medication, illness and/or incident forms as well as the child's involvement in daily activities and experiences may be shared with any authorised person collecting the child
      • Any other information may only be communicated directly to the child's parent/guardian
    • Where and how the confidential information should be stored:
      • Any information regarding a child's education, such as observations and goals, will be stored in the child's online individual portfolio, accessed only by staff and the child's parents
      • Any information regarding a child's medication, illness or accidents will be stored in the room's medication folder, kept at reception
      • Any information regarding a child's enrolment, such as contact phone numbers and additional needs, will be stored in the room's planning folder, kept in the child's room
    • Confidential conversations that staff have with parents, or the Director has with staff members, will be conducted in a quiet area away from other children, parents and staff. Such conversations are to be minuted and stored in a confidential folder.
    • Personal forms and information will be stored securely.
    • No member of staff may give information or evidence on matters relating to children and/or their families to anyone other than the custodial parent/guardian, unless prior written approval by the custodial parent/guardian is obtained. Exceptions may apply regarding information about children when subpoenaed to appear before a court of law. Notwithstanding these requirements, confidential information may be exchanged in the normal course of work with other staff members at the centre and may be given to the Operator, when this is reasonably needed for the proper operation of the centre and the wellbeing of users and staff.
  • Provide Staff and Educators with relevant changes
  • Make sure all relevant staff understand the requirements under Australia's privacy law
  • Keep up to date with the Australian Privacy Principles (this may include delegating a staff member to oversee all privacy-related activities to ensure compliance).
  • Ensure personal information is protected in accordance with our obligations under the Privacy Act 1988 and Privacy amendments (Enhancing Privacy Protection) Act 2012.

Staff

  • Will protect the privacy and confidentiality of other staff members by not relating personal information about another staff member to anyone either within or outside the centre
  • Will protect the privacy and confidentiality of children and families by not relating personal information to anyone either within or outside the centre without prior authorisation
  • Students, people on work experience and volunteers will not make staff, children or families and the centre an object for discussion outside of the centre (e.g. college, school, home etc.), nor will they at any time use family names in recorded or tutorial information
  • Will not discuss other staff members, children or families via internet social networking sites such as Facebook, Myspace, Twitter or any other social network site
  • Will not use social networking systems such as Facebook to discuss disagreements with staff, families or management
  • Will not seek or accept friend requests from family members or students at the centre

Families

  • Will refrain from using the centre's name or child's room name to create web pages intended to increase their contact with other families via social networking systems such as Facebook
  • Will refrain from using internet social networking systems, such as Facebook, to seek out staff to further discuss problems or disagreements with the centre
  • Every enrolling parent/guardian is provided with clear information about:
    • What personal information is kept, and why
    • Any legal authority to collect personal information
    • Third parties to whom the service discloses such information as a usual practice
  • All matters discussed at Family Committee meetings will be treated as confidential

Records Archived at the centre

In accordance with the Education and Care Services National Regulations 2013, the following records must be kept:

  1. If the record relates to an incident, illness, injury or trauma suffered by a child while being educated and cared for by the centre, until the child is aged 25 years
  2. If the record relates to an incident, illness, injury or trauma suffered by a child that may have occurred following an incident while being educated and cared for by the centre, until the child is aged 25 years
  3. If the record relates to the death of a child while being educated and cared for by the centre, or that may have occurred as a result of an incident while being educated and cared for, until the end of 7 years after the death
  4. In the case of any other record relating to a child enrolled at the centre, until the end of 3 years after the last date on which the child was educated and cared for by the service
  5. If the record relates to the approved provider, until the end of 3 years after the last date on which the approved provider operated the centre
  6. If the record relates to the nominated supervisor or staff member of the centre, until the end of 3 years after the last date on which the nominated supervisor or staff member provided education and care on behalf of the centre
  7. In the case of any other record, until the end of 3 years after the date on which the record was made

Records stored at the centre will be kept in both hard and soft copy formats. This means that what can be stored on computer disc (soft copy) will be done so to save space. Otherwise original forms and documents will be stored in their paper form (hard copy).

These records will be stored in an area located on the centre property that is inaccessible to all children, families and unauthorised staff members.

Once records have been stored for their required amount of time, they will be destroyed in a manner that defies duplication. Computer discs will be erased and destroyed, and all paper documents and forms will be shredded.

How our online platform handles your information

This section explains how our online platform handles information collected through the public enquiry and booking website, the Family Hub, and the staff customer relationship management system. It sits alongside the centre-level practices above and is consistent with the Australian Privacy Principles.

Data we collect and create

  • Guardian and family details: names, email addresses, phone numbers, relationship to each child, Family Hub account details, contact preferences and communication consent or unsubscribe records.
  • Child details: names, dates of birth, centre preferences, requested days, target start dates, enrolment details and, where families provide it, sensitive information such as medical, allergy, dietary, additional-needs, funding or custody-related records.
  • Enrolment journey records: enquiries, centres of interest, waitlist entries, tours, offers, orientation bookings, enrolment-change requests, support cases, tasks, feedback and status history.
  • Payment and bond records: bond amount, payment status, Stripe checkout or payment identifiers, and refund status. We do not store card numbers or bank account details in the platform.
  • Communication records: transactional emails and SMS, case replies, call metadata and notes, delivery events, unsubscribe records and Family Hub messages.
  • Technical and security records: session cookies, signed Family Hub link events, webhook delivery records, audit logs, error events and limited device/browser information needed to keep the service secure.

Why we collect it

We collect and use this information to manage the enrolment journey, operate waitlists, book tours and orientations, issue and manage offers, process bond payments, respond to support cases, keep records required for childcare operations, and communicate with families about their child's place. We also use operational records to improve the reliability and safety of the service. The Family Hub and staff CRM are not used for third-party advertising.

Where information is stored and processed

PurposeSystem or processor
Platform database and operational recordsSupabase Postgres, hosted in the Sydney region, is the platform system of record.
Uploaded documents and attachmentsSupabase Storage private buckets with signed access links; centre marketing photos use the public centre-photo bucket.
Website and Family Hub hostingVercel serves the website, Family Hub and staff CRM.
Family authenticationClerk authenticates Family Hub users.
Staff authenticationMicrosoft Entra ID and NextAuth authenticate staff users and supply staff role information.
Transactional emailResend sends operational email such as Family Hub links, tour confirmations, offer notices, reminders, receipts and case messages.
SMS notificationsTwilio sends operational SMS where SMS is used.
Bond paymentsStripe processes bond payments. Stripe receives payment details directly; the platform stores only payment references and status needed to reconcile the offer.
Phone supportRingCentral supports call handling, caller identification and call logging for authorised staff.
Operational childcare systemKidsXap/XAP receives a limited family, guardian and child creation write when a placement is confirmed. XAP remains the operational childcare system for attendance, bookings and day-to-day childcare records.
Reporting and analyticsSnowflake receives a one-way reporting feed from the platform database for internal reporting. Data does not flow back from Snowflake into the operational platform.
Marketing email consentMarketing or lifecycle email is managed separately from this platform, through the relevant marketing email provider.

We only share the information each provider needs to deliver its service to us. Provider access, account configuration, hosting regions and any overseas processing are assessed as part of our privacy governance. Where a provider stores or processes information outside Australia, cross-border disclosure obligations under the Australian Privacy Principles apply.

Access control

Families can access their own Family Hub records after signing in. Staff access is restricted to authorised staff accounts and controlled by role-based access rules for job function. Administrative and configuration actions require stricter staff roles. Staff access to sensitive operational records is governed by role, audit logging, confidentiality obligations and the need to perform their work. The public marketing site does not expose family, guardian, child, offer, case or payment records.

Key status changes, account blocks, case actions and administrative actions are written to an audit log so that we can investigate questions, support breach assessment and maintain an accountable record of changes.

Retention, deletion and correction

The platform retains records while they are required for childcare operations, audit, recovery, legal, regulatory or child-safety reasons. Some records, including incident, illness, injury, trauma and child records, have minimum retention periods under the Education and Care Services National Regulations. The platform currently retains operational records, soft-deleted records and audit history indefinitely unless a lawful request, approved privacy decision or future retention schedule requires deletion or de-identification.

While records remain operationally or legally required, the platform generally soft-deletes records rather than immediately destroying them. This means a withdrawn, duplicate or closed record is hidden from ordinary workflows but retained for audit, recovery and record-keeping purposes. We will update this policy before introducing an automated destruction or anonymisation schedule.

You can ask to access or correct the personal information we hold about you, and ask questions about how it is handled, using the contact details below.

Child-safety alignment

The platform is a record system for enrolment, waitlist, communications and support workflows. It does not replace centre child-safety, incident, reportable-conduct, attendance or authorised-collection processes. Sensitive child information, including medical, dietary, additional-needs, custody and safeguarding context, is handled only where it is needed for care, enrolment or support, and is not used for marketing analytics or advertising.

Publication

This policy is published on the Explorers website at /privacy-policy, linked from the website footer and sitemap, and available to families using the same link from Family Hub resources.

National Quality Standard (NQS)

7.1 Governance

Governance supports the operation of a quality service.

7.1.1 Service philosophy and purposes

A statement of philosophy guides all aspects of the service's operations.

7.1.2 Management Systems

Systems are in place to manage risk and enable the effective management and operation of a quality service.

7.1.3 Roles and Responsibilities

Roles and responsibilities are clearly defined, and understood, and support effective decision making and operation of the service.

7.2 Leadership

Effective leadership builds and promotes a positive organisational culture and professional learning community.

Education and Care Services National Regulations

  • 168 – Education and care services must have policies and procedures
  • 181 – Confidentiality of records kept by approved provider
  • 181–184 – Confidentiality and storage of records

Sources

  • Australian Children's Education & Care Quality Authority
  • Guide to the Education and Care Services National Law and the Education and Care Services National Regulations
  • ECA Code of Ethics
  • Guide to the National Quality Standard
  • United Nations Convention on the Rights of the Child
  • Privacy Act 1988
  • Revised National Quality Standard
  • Australian Childcare Alliance – Changes to Australia's Privacy law
  • Office of the Australian Information Commissioner – Australian Privacy Principles

Notations of Amendment

  • October 2018 – Large variation to the policy statement and NQS references
  • January 2021 – Amendment to general typed errors

Contact us

If you have questions about this Privacy Policy or how we handle personal information, please contact us on 1300 000 335.