Nurture Privacy Policy
Effective date: 01/04/2026
Last reviewed: 01/04/2026
1. About this policy
This policy explains how NURTURE SOFTWARE LTD (“Nurture”, “we”, “us”) collects, uses, shares, and protects personal data when you interact with the Nurture platform — including the Nurture web portal at https://app.nurture-software.co.uk, the Nurture staff iOS app, and the underlying APIs.
Nurture is a software platform used by UK local authorities and independent fostering agencies to manage looked-after children’s care records, including foster families, foster parents (carers), placements, safeguarding, expenses and mileage, communications, and statutory reviews.
If you are a foster parent, child, or family member, the local authority or fostering agency that placed your child (or you, as a child in care) is the data controller for most of your personal data. Nurture operates as a data processor on their behalf under a written data processing agreement. Please refer to your authority’s own privacy notice for primary contact details and your rights as a data subject.
If you are a member of staff at an authority or agency using Nurture, your employer is the data controller. We process limited personal data about you to operate your account and audit usage.
2. Who to contact
- Data Protection Lead: Sam Beadle
- Email: [dpo@nurture-software.co.uk]
For data subject requests about records held within Nurture on behalf of a local authority, please contact that authority’s Data Protection Officer first; we will route requests to them.
3. Who this policy applies to
Nurture is used by people in several different roles. The data we hold, and how we use it, depends on your role:
| Role | Who it is | Data we hold |
|---|---|---|
| Super Administrator | Platform operator staff at Nurture | Name, work email, login activity, audit logs |
| Authority Administrator | Senior staff at a local authority / agency | Name, email, mobile number, job title, authority assignment, login activity, audit logs |
| Authority Staff (social workers, support staff) | Day-to-day operational staff | As above, plus records of professional actions (visits, diary entries, notes, follow-ups, approvals) |
| Foster Parent / Carer (“Family lane”) | Adult registered as a foster carer | Name, contact details, mobile number, login credentials, family composition, expenses and mileage claims, communications, diary entries you author |
| Looked-after Child | Child in the care of a local authority | Name, date of birth, demographic information, care plan information, placement history, risk assessments, safeguarding events, LAC review records, statutory reviews, incident and accident reports, communications about the child |
| Other people named in records | E.g. birth family members, significant adults, professionals | Name, role, relationship to the child, any contact arrangements recorded |
4. What personal data we process
4.1 Account and identity data
- Full name, email address, optional mobile number
- Job title and authority/agency affiliation (where applicable)
- Encrypted (hashed) password, password reset tokens, login timestamps
- Group / role memberships used for access control
4.2 Operational records (entered by authority staff or carers)
- Family records — name, address, contact details, household composition
- Foster parent records — names, contact details, professional history
- Child records — name, date of birth, demographic information, education, health flags, current and historical placements, RAG status, statutory and LAC review schedules, missing-from-care episodes, respite arrangements, significant people in their life, contact arrangements
- Safeguarding and incident data — accident reports, incident reports, follow-up notes, staff interaction notes, child risk reviews, fostering panel records
- Financial records — expenses (description, amount, attachments such as receipts), mileage claims (route, date, distance), approval status
- Documents — authority documents, family-linked documents, supporting attachments uploaded into the platform
- Communications — messages, comms thread participants, notification preferences
4.3 Technical data
- IP address, browser/user-agent string, device information
- Application logs and audit events (who did what, when)
- Push notification tokens for the staff iOS app
4.4 Special category and “sensitive” data
Because Nurture supports statutory fostering work, records will often contain special category and criminal-conviction-related personal data, including:
- Information about a child’s health (medical conditions, medication, mental health)
- Racial or ethnic origin, religious belief, where recorded for care planning
- Information about sexual orientation or sex life where disclosed for safeguarding
- Criminal allegations, investigations or convictions affecting a child or member of a household
We process this data only because, and to the extent that, the controlling authority is required or permitted to do so under UK law (see lawful bases below).
5. How we collect personal data
Personal data enters the platform in one of the following ways:
- Provided directly by you when you create an account, set a password, log in, log a diary entry, raise an expense, send a message, or upload a document.
- Provided about you by someone else — for example a social worker recording details about a child or a family.
- Collected automatically by our infrastructure when you use the platform — server logs, audit events, push-notification delivery.
- Imported from a controlling authority’s existing systems where a data migration has been agreed.
6. Why we process personal data, and our lawful basis
| Purpose | Lawful basis (UK GDPR Art. 6) | Special category basis where relevant (Art. 9) |
|---|---|---|
| Operating user accounts, authentication, role-based access | Legitimate interests / Contract / Legal obligation | n/a |
| Maintaining statutory care records for looked-after children on behalf of authorities | Legal obligation (Children Act 1989, Care Planning Regulations 2010) and Public task | Substantial public interest — safeguarding of children at risk; provision of social care services |
| Safeguarding triage, incident reporting, follow-up assignments | Legal obligation / Public task | Substantial public interest — safeguarding |
| Processing expenses and mileage for foster carers | Contract / Legitimate interests | n/a |
| Sending operational notifications, invites and password resets | Legitimate interests / Contract | n/a |
| Security monitoring, audit logging, fraud prevention | Legitimate interests / Legal obligation | n/a |
| Improving the platform (aggregate, non-identifying analysis) | Legitimate interests | n/a |
| Responding to data subject requests, complaints, regulator enquiries | Legal obligation | n/a |
For the controlling authority’s statutory processing of care records, the authority’s own legal basis applies and we act as their processor.
7. Who we share personal data with
We only share personal data where there is a clear, lawful reason. Recipients include:
- The controlling local authority or agency — we make care records available to authorised authority staff in line with the authority’s access controls.
- Other authorised users of the same authority — based on role (SuperAdmin, Admin, Staff, Family) and authority scope. Staff at one authority cannot see another authority’s records.
- Sub-processors who help us operate the service (see section 9).
- Regulators, courts, or law enforcement where we are legally required, including the Information Commissioner’s Office (ICO), Ofsted, the police, the courts, or a Safeguarding Adults / Children Board.
- Professional advisers (lawyers, auditors, insurers) bound by confidentiality.
- A successor organisation if our business is sold or merged, subject to equivalent protections.
We do not sell personal data, and we do not use personal data to train third-party AI models.
8. International transfers
The platform and its data are hosted in [Microsoft Azure UK South region]. Where a sub-processor is based outside the UK we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with additional safeguards where appropriate. A list of current cross-border transfers is available on request.
9. Sub-processors
We use a small number of carefully chosen sub-processors to operate Nurture. Current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting (web app, API, database, file storage) | UK |
| Microsoft 365 | Transactional email delivery (invites, password resets, notifications) | UL |
| OneSignal | iOS push notifications for staff app | UK |
| Microsoft Azure App Insights | Application error monitoring | UK |
| Azure DevOps | Source control and deployment pipelines (no production personal data) | UK / EU |
A full current list, with the data each sub-processor processes, is available on request.
10. How long we keep personal data
Retention is governed by the controlling authority’s own retention schedule and by UK statutory requirements for fostering and looked-after children records. By default:
- Looked-after child records — retained until the child’s 75th birthday, in line with IRMS guidance (or longer where required).
- Fostering household records — retained for the period required by the relevant fostering services regulations, typically a minimum of 10 years after the household ceases to foster.
- Staff account records — retained for the duration of the user’s role plus 6 years for audit purposes.
- Audit and access logs — retained for 12 months unless required longer for an active investigation.
- Backups — kept for 35 days and overwritten on a rolling basis.
When the retention period expires, records are securely deleted or anonymised so that they can no longer be associated with an individual.
11. Your rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Be informed about how your data is used (this notice).
- Access the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — limited in scope where we have a legal obligation to keep records, particularly for looked-after children’s records.
- Restriction of processing in certain circumstances.
- Object to processing based on legitimate interests.
- Portability — receive a copy of your data in a structured, machine-readable format where the processing is based on consent or contract.
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. Nurture does not make automated decisions of this kind.
To exercise a right relating to care records, contact your controlling authority’s DPO first. For requests about how Nurture itself uses your data (e.g. your staff account), contact us using section 2 above.
We aim to respond within one calendar month. We can extend this by up to two further months for complex requests and will tell you if we do.
12. How we keep personal data secure
We take a defence-in-depth approach. Measures include:
- Encryption in transit (TLS 1.2 or higher) for all traffic to and from the platform.
- Encryption at rest for the database and file storage.
- Strong authentication — passwords are hashed with a modern key-derivation function; reset tokens are single-use and time-limited.
- Role-based access control (RBAC) — every endpoint enforces role + authority scope, so users only see data for their own authority.
- Audit logging — privileged actions are recorded with the actor, target, timestamp and IP.
- Least privilege — staff at Nurture access personal data only when required to support the platform, under a binding confidentiality and DBS regime.
- Backups and disaster recovery — automated daily backups with periodic restore testing.
- Vulnerability management — dependency scanning, patching cadence, and periodic third-party penetration testing.
- Sub-processor due diligence — security and data-protection review before onboarding.
No system can guarantee absolute security; in the event of a personal data breach affecting your data we will follow our Incident Response Policy and notify the ICO within 72 hours where the threshold is met, and the relevant data subjects without undue delay if there is a high risk to their rights and freedoms.
13. Children’s data
Nurture exists to help authorities care for children. We process children’s data only on the controlling authority’s behalf and only to the extent the authority requires. Access is restricted by role and authority scope. Children’s records are retained for the long periods required by UK fostering and care record regulations.
We do not offer the service directly to children, and we do not use children’s data for any marketing, profiling, advertising, or AI-training purpose.
14. Cookies and similar technologies
The Nurture web app uses strictly necessary browser storage (localStorage and session cookies) to keep you signed in and remember your preferred settings. We do not use third-party advertising or analytics cookies that track you across other websites.
A separate cookie notice will be displayed in-app where required.
15. Changes to this policy
We may update this policy from time to time. The “Effective date” at the top will change when we do. For material changes (for example, adding a new category of data or a new sub-processor) we will notify controlling authorities in advance and, where appropriate, notify users in-app on next sign-in.
16. How to complain
If you are unhappy with how your personal data has been handled, please contact us first (section 2) so we have a chance to put things right. You also have the right to complain to the UK regulator at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
https://ico.org.uk/make-a-complaint/